Mobile body control device, mobile body control method, and storage medium

By introducing a tamper detection and response unit into the mobile control device, software tampering is identified and responded to, solving the interruption problem caused by false detection and improving the security and reliability of the system.

CN120716632APending Publication Date: 2025-09-30HONDA MOTOR CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510098123.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-27
Filing Date
2025-01-22
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

In a mobile control device, secure boot processing may lead to false detection of software tampering, resulting in interruption of use of the mobile device and affecting traffic safety and reliability.

Method used

The tamper detection and response units detect software tampering through secure boot processing and maintain the use of specified functions from the startup state until the standby state, preventing interruptions due to false detections.

Benefits of technology

It effectively suppresses the interruption of mobile use caused by false detection of software tampering, and improves traffic safety and system reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120716632A_ABST
    Figure CN120716632A_ABST
Patent Text Reader

Abstract

The invention provides a mobile body control apparatus, a mobile body control method, and a storage medium. The present application addresses the problem of suppressing interruption of use of a moving body due to erroneous detection of software tampering. A mobile body control device (1) is provided with: a tampering recognition unit (22) that recognizes tampering of software by executing security boot processing for verifying the presence or absence of tampering of software stored in a storage unit provided in a mobile body (100); and a tampering response unit (23) that, when the moving body (100) is in the activated state, executes a security boot process by the tampering recognition unit and recognizes tampering of software relating to a predetermined function of the moving body (100) by the tampering recognition unit (22). And a tamper response unit that executes a tamper response retention process for maintaining a state in which the predetermined function can be used until the moving body (100) is in a standby state, and disables the predetermined function after the moving body (100) is in the standby state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a mobile body control device, a mobile body control method and a storage medium. Background Art

[0002] Conventionally, a secure boot technology is known that verifies whether software such as firmware has been tampered with when starting an electronic device, and boots the device only if no tampering has been verified (for example, see Patent Document 1). Patent Document 1 discloses a technology that reduces boot time by collectively verifying that no tampering has occurred for multiple firmware files that are the subject of tampering verification.

[0003] Prior art literature

[0004] Patent Literature

[0005] Patent Document 1: Japanese Patent Application Laid-Open No. 2021-2168 Summary of the Invention

[0006] Problems to be solved by the invention

[0007] In a mobile control device, an example of an electronic device, a secure boot process is also performed to improve traffic safety. This process is performed in the background, not only during startup of the mobile device but also during operation. By performing the secure boot process during the mobile device's operation, software reliability can be improved. However, there is a concern that the increased frequency of secure boot processing may increase the likelihood of false tampering detections. Furthermore, if software tampering is detected during the secure boot process, the mobile device's operation is stopped. However, if a false detection is also detected, the mobile device's operation is also stopped, which can result in the user's use of the mobile device being interrupted. Therefore, the present application aims to prevent the interruption of mobile device use due to false detection of software tampering.

[0008] This application aims to solve the above-mentioned problems and improve safety. Furthermore, it further improves traffic safety and contributes to the development of sustainable transportation systems.

[0009] Means for solving problems

[0010] As a first method for achieving the above-mentioned purpose, a mobile body control device can be cited, which comprises: a tampering identification unit, which performs a secure boot process to verify whether the software stored in the storage unit of the mobile body has been tampered with to identify tampering of the software; and a tampering response unit, when the mobile body is in a startup state, the tampering identification unit performs the secure boot process and, when the tampering identification unit identifies tampering of the software related to a specified function of the mobile body, the tampering response unit performs a tampering response retention process to maintain a state in which the specified function can be used until the mobile body enters a standby state, and after the mobile body enters the standby state, the specified function is made unusable.

[0011] In the above-mentioned mobile body control device, it can also be configured that the tampering identification unit executes the secure boot process multiple times, and determines the identification of tampering of the software when tampering is continuously detected more than a specified number of times through the secure boot process, or when the ratio of the number of times tampering is detected in the multiple execution times of the secure boot process is more than a specified judgment ratio.

[0012] In the above-mentioned mobile body control device, it can also be constructed that the tampering identification unit sets the number of judgments when the mobile body is in the startup state to be greater than the number of judgments when the mobile body is in the standby state, and sets the judgment ratio when the mobile body is in the startup state to be greater than the judgment ratio when the mobile body is in the standby state.

[0013] In the above-mentioned mobile object control device, the tamper recognition unit may be configured to change the number of determinations and the determination ratio according to the predetermined function.

[0014] In the above-mentioned mobile body control device, it can also be constructed that when the mobile body is in the startup state, the tampering identification unit performs the secure boot processing and the tampering identification unit identifies tampering of the software related to the specified function of the mobile body, the tampering response unit decides whether to perform the tampering response retention processing according to the type of the specified function.

[0015] In the above-mentioned mobile body control device, it can also be constructed as follows: the mobile body is a vehicle, and the mobile body control device includes a mobile body position identification unit, which identifies the position of the mobile body. When the mobile body is in a startup state and the mobile body position identification unit identifies that the mobile body is outside the road, the tampering identification unit performs the secure boot processing and the tampering identification unit identifies tampering of the software related to the specified function of the mobile body, the tampering response unit does not perform the tampering response retention processing, and the specified function cannot be used.

[0016] The mobile control device may include a tampering notification unit configured to output warning information regarding the software tampering from a notification device used in the mobile body when the tampering recognition unit recognizes tampering of the software.

[0017] The mobile control device may include a tampering notification unit that transmits warning information regarding the software tampering to a user terminal used by a user of the mobile body when the tampering recognition unit recognizes tampering of the software.

[0018] As a second method for achieving the above-mentioned purpose, a mobile body control method can be cited, which is a mobile body control method executed by a computer, and the mobile body control method includes: a tampering identification step, performing a secure boot processing to verify whether the software stored in the storage unit of the mobile body has been tampered with to identify tampering of the software; and a tampering response step, when the mobile body is in a startup state, performing the secure boot processing by the tampering identification step, and when tampering of the software related to a specified function of the mobile body is identified by the tampering identification step, performing a tampering response retention processing to maintain a state in which the specified function can be used until the mobile body enters a standby state, and after the mobile body enters the standby state, making the specified function unusable.

[0019] As a third method for achieving the above-mentioned purpose, a storage medium can be cited, which stores a program that enables a computer to function as the following parts: a tampering identification unit that performs a secure boot process to verify whether the software stored in the storage unit of the mobile body has been tampered with, so as to identify tampering of the software; a tampering response unit that, when the mobile body is in the startup state, performs the secure boot process by the tampering identification unit, and when the tampering identification unit identifies tampering of the software related to the specified function of the mobile body, the tampering response unit performs a tampering response retention process to maintain the state in which the specified function can be used until the mobile body enters the standby state, and after the mobile body enters the standby state, the specified function of the mobile body is made unusable.

[0020] Effects of the Invention

[0021] According to the above-described mobile object control device, mobile object control method, and storage medium, it is possible to suppress interruption of use of the mobile object due to erroneous detection of software tampering. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 This is a structural diagram of a mobile body control device.

[0023] Figure 2 This is a first flowchart of the ECU software tampering monitoring process.

[0024] Figure 3 This is a second flowchart of the ECU software tampering monitoring process.

[0025] Description of Reference Numerals

[0026] 1…Mobile body control device; 2…SS switch; 3…Communication unit; 4…Navigation device; 5…Display; 10…Central ECU; 20…Processor; 21…Communication control unit; 22…Tampering identification unit; 23…Tampering response unit; 24…Mobile body position identification unit; 25…Tampering notification unit; 30…Memory; 31…Program; 50 (50a, 50b)…Gateway ECU; 51 (51a~51f)…Local ECU; 71~73…In-vehicle equipment; 90…User terminal; 100…Vehicle (mobile body); 200…Communication network; 210…Mobile body management server; U…User. DETAILED DESCRIPTION

[0027] [1. Structure of Mobile Object Control Device]

[0028] Reference Figure 1 , the structure of the mobile body control device 1 of the present embodiment will be described. The mobile body control device 1 is mounted on a vehicle 100 and controls the operation of the vehicle 100. The vehicle 100 is equivalent to the mobile body of the present disclosure. In addition to vehicles, the mobile body of the present disclosure may also be an aircraft, a ship, etc. The vehicle 100 includes an SS (start / stop) switch 2 for instructing the start and stop (power on and power off) of the vehicle 100, a communication unit 3, a navigation device 4, and a display 5. According to the start operation (start operation) of the SS switch 2, the vehicle 100 enters a start state in which it can travel, and according to the stop operation (stop operation) of the SS switch, the vehicle 100 enters a standby state in which it cannot travel.

[0029] The communication unit 3 communicates with the mobile management server 210 and the user terminal 90 used by the mobile user U via the communication network 200. Furthermore, the communication unit 3 performs short-range wireless communication with the user terminal 90 using Bluetooth (registered trademark), Wi-Fi (registered trademark), or the like. The navigation device 4 includes a GNSS (Global Navigation Satellite System) sensor for detecting the position of the vehicle 100 and provides route guidance to the destination.

[0030] The mobile control device 1 includes a central ECU (Electronic Control Unit) 10, gateway ECUs 50a and 50b, and local ECUs 51a to 51f. The central ECU 10 is connected to the gateway ECU 50a via a communication line 40a and is connected to the gateway ECU 50b via a communication line 40b.

[0031] The gateway ECU 50a is connected to multiple local ECUs 51a to 51c via a communication line 41a, and the gateway ECU 50b is connected to multiple local ECUs 51d to 51f via a communication line 41b. The local ECUs 51a to 51c control the operation of the onboard devices 71 to 73 of the vehicle 100. Examples of the onboard devices 71 to 73 include drive sources such as the engine and electric motor, driver control components such as the steering wheel, brake pedal, and accelerator pedal, headlights and other lighting components, auxiliary equipment such as wipers, powered sliding doors and power windows, and air conditioning systems. Furthermore, the local ECU 51d controls the operation of the communication unit 3, the local ECU 51e controls the operation of the navigation system 4, and the local ECU 51f controls the operation of the display 5.

[0032] Hereinafter, the gateway ECU 50a and the gateway ECU 50b are collectively referred to as the gateway ECU 50, and the local ECUs 51a to 51f are collectively referred to as the local ECU 51. Furthermore, devices connected to the local ECU 51 are collectively referred to as in-vehicle devices. The central ECU 10, the gateway ECU 50, and the local ECU 51 are control units equipped with processors, memory, interface circuits, and the like.

[0033] The plurality of local ECUs 51 connected to the gateway ECU 50 are grouped according to the functions and configuration locations of the in-vehicle devices connected to the local ECUs 51. Figure 1 In the figure, two gateway ECUs 50a and 50b are shown as an example, but three or more gateway ECUs 50 may be provided. In addition, the number of in-vehicle devices connected to the local ECU 51 may be two or more.

[0034] The central ECU 10 manages the mobile object 100 using OTA (Over The Air) downloading. It downloads a new version of the local ECU 51's software (update software) from the mobile object management server 210 to update the local ECU 51's software. Furthermore, the central ECU 10 monitors the software stored in the local ECU 51's memory for tampering. The following describes the processing performed by the central ECU 10 to identify tampering with the local ECU 51's software and the response to detecting such tampering.

[0035] The central ECU 10 includes a processor 20, a memory 30 (storage medium), and other components. The memory 30 stores a program 31 for controlling the central ECU 10. The processor 20 corresponds to the computer of the present disclosure. By reading and executing the program 31, the processor 20 functions as a communication control unit 21, a tamper detection unit 22, a tamper response unit 23, a mobile object position detection unit 24, and a tamper notification unit 25.

[0036] The processing executed by the tamper identification unit 22 corresponds to the tamper identification step in the mobile object control method of the present invention, and the processing executed by the tamper response unit 23 corresponds to the tamper response step in the mobile object control method of the present invention.

[0037] The communication control unit 21 controls communications with the mobile management server 210 and the user terminal 90 via the communication unit 3. The tamper detection unit 22 performs secure boot processing to verify whether the software stored in the memory of the local ECU 51 has been tampered with, thereby detecting software tampering. When the tamper detection unit 22 detects tampering with the software in the local ECU 51, the tamper response unit 23 disables the use of specified functions implemented by the software. Details of this processing will be described later.

[0038] The mobile object position recognition unit 24 communicates with the navigation device 4 to recognize the position of the vehicle 100 as detected by the GNSS sensor of the navigation device 4. When the tampering recognition unit 22 recognizes tampering of the local software, the tampering notification unit 25 transmits tampering notification information to the display 5 to notify that the local software has been tampered with, causing the display 5 to display a tampering notification screen indicating that the local software has been tampered with. Furthermore, when the tampering recognition unit 22 recognizes tampering of the local software, the tampering notification unit 25 transmits tampering notification information to the user terminal 90 to notify that the local software has been tampered with, causing the display unit of the user terminal 90 to display a tampering notification screen indicating that the local software has been tampered with.

[0039] [2. Software tampering monitoring process]

[0040] according to Figures 2 and 3 The flowchart shown in FIG. 1 illustrates the steps of the tampering monitoring process for the software of the local ECU 51 executed by the mobile body control device 1. When the vehicle 100 is in the startup state or in the standby state, the mobile body control device 1 executes the tampering monitoring process based on the software stored in the memory of the plurality of local ECUs 51 at a predetermined time. Figures 2 and 3 The execution time of the secure boot process is set, for example, when the vehicle 100 enters the standby state by the stop operation of the SS switch 2 or every time a predetermined time has passed.

[0041] exist Figure 2In step S1, the tamper detection unit 22 resets the counter variable CT, which counts the number of detected tampering (0→CT). In the following step S2, secure boot processing is performed on the software of the local ECU 51 (hereinafter referred to as the target software) that is the target of secure boot, to verify whether tampering has occurred. In the following step S3, the tamper detection unit 22 advances the process to step S10 if tampering with the target software is detected. If no tampering with the target software is detected, the process advances to step S4, concluding the current tampering monitoring process.

[0042] In step S10, the tamper detection unit 22 increments the counter variable CT (CT+1→CT). In the following step S11, the tamper detection unit 22 determines whether the vehicle 100 is in the startup state. If so, the process proceeds to step S20. If not (in the standby state), the process proceeds to step S12.

[0043] In step S12, the tampering identification unit 22 determines whether the counter variable CT is greater than the first determination number X1. If the counter variable CT is greater than the first determination number X1, the tampering identification unit 22 determines that the target software has been tampered with and proceeds to step S13. If the counter variable CT is less than the first determination number, the tampering identification unit 22 proceeds to step S2.

[0044] In step S13, as described above, the tamper notification unit 25 displays a tamper notification screen on the display 5 or the display unit of the user terminal 90. In the following step S14, the tamper response unit 23 prohibits the start of the vehicle 100 as a first guidance process for tampering. The user U visually recognizes the tamper notification screen, recognizes the tampering of the target software, and requests a road service company or the like to address the vehicle 100 failure.

[0045] By processing in steps S2 , S3 , and S10 to S14 , when tampering of the target software is detected continuously for a first determination number X1 or more, recognition of tampering of the target software is confirmed, thereby preventing the vehicle 100 from entering the start-up prohibited state due to erroneous detection of tampering.

[0046] In step S20, the tampering identification unit 22 determines whether the counter variable CT is greater than the second determination number X2. Then, when the counter variable CT is greater than the second determination number, the tampering identification unit 22 determines that the target software has been tampered with and enters the process. Figure 3 In step S21, when the counter variable CT is less than the second determination number X2, the process proceeds to step S2.

[0047] Here, the second determination count X2 corresponding to when vehicle 100 is in the active state is set to a greater number than the first determination count X1 corresponding to when vehicle 100 is in the standby state. Thus, when vehicle 100 is in the active state and user U is using vehicle 100, and the possibility of vehicle 100 being stolen is low, it is possible to prevent the activation process for vehicle 100 from being executed due to erroneous detection of tampering with the target software, thereby preventing the use of vehicle 100 from being interrupted.

[0048] exist Figure 3 In step S21, the tampering notification unit 25 displays the tampering notification screen on the display 5 or the display unit of the user terminal 90 as described above. In the following step S22, the tampering response unit 23 determines whether the control object of the software identified as tampered is a prescribed function. Here, the prescribed function is a function that does not hinder the driving of the vehicle 100 (for example, entertainment system functions such as displaying content on the display 5, communication functions using the communication unit 3, and connection functions with portable devices using interfaces such as air conditioning and USB (registered trademark)).

[0049] Then, the tamper response unit 23 enters the process into step S30 when the control target of the target software is the prescribed function, and enters the process into step S23 when the control target of the target software is not the prescribed function. In step S23, the tamper response unit 23 executes the second guidance process corresponding to the case where the vehicle 100 is in the start state, and enters the process into step S30. Figure 2 Step S4.

[0050] As a second guidance process, the tamper response unit 23 performs retreat control such as deceleration and guidance to stop on the shoulder of the road while the vehicle 100 is traveling, and after the vehicle 100 stops, when the vehicle 100 enters the standby state according to the operation of the SS switch 2, performs processing to prohibit the vehicle 100 from starting.

[0051] In step S30, the tamper response unit 23 determines whether the current position of the vehicle 100 identified by the mobile object position recognition unit 24 is off the road. The tamper response unit 23 then proceeds to step S22 if the current position of the vehicle 100 is off the road, and proceeds to step S31 if the current position of the vehicle 100 is on the road.

[0052] In step S31, when the vehicle 100 enters the standby state by the operation of the SS switch 2, the tamper response unit 23 advances the process to step S32. Figure 2 Similarly, in step S14, the first boot process corresponding to the standby state is executed, and the process enters Figure 2 The process of step S30 is equivalent to the tampering response retention process of the present disclosure.

[0053] [3. Other Implementation Methods]

[0054] In the above-described embodiment, the tampering identification unit 22 determines that tampering of the target software has been detected when tampering of the target software has been detected more than a predetermined number of times during the secure boot process. In another embodiment, the tampering identification unit 22 may perform the secure boot process multiple times and determine that tampering of the target software has been detected when the ratio of the number of times tampering of the target software has been detected during the multiple executions is greater than a predetermined determination ratio. In this case, the second determination ratio corresponding to the case where the vehicle 100 is in the startup state may be set to a ratio greater than the first determination ratio corresponding to the case where the vehicle 100 is in the standby state (first determination ratio < second determination ratio).

[0055] Furthermore, the first determination count, the second determination count, the first determination ratio, and the second determination ratio may be changed based on a predetermined function associated with the target software. For example, the first determination count and the second determination count for the target software of the vehicle 100's driving control system may be set to be smaller than the first determination count and the second determination count for target software related to controls other than the driving control system (such as those related to air conditioning, entertainment, etc.). For example, the first determination count and the second determination count for the target software of the vehicle 100's driving control system may be set to be smaller than the first determination count and the second determination count for target software related to controls other than the driving control system (such as those related to air conditioning, entertainment, etc.).

[0056] In the above embodiment, the tamper identification unit 22 sets the second determination count X2 corresponding to when the vehicle 100 is in the active state to a greater number than the first determination count X1 corresponding to when the vehicle 100 is in the standby state (X1 < X2). In other embodiments, the first determination count X1 and the second determination count X2 may be set to the same number. Furthermore, when tampering of the target software is detected during secure boot processing, the identification of tampering of the target software may be determined without determining the tampering detection count.

[0057] In the above embodiment, the mobile body position recognition unit 24 is provided, and the tamper response unit 23 is provided. Figure 3 In step S30, it is determined whether the current position of the vehicle 100 is off the road. The execution of the first guidance process in step S32 is suspended until the vehicle 100 enters the standby state in step S31. As another embodiment, the mobile object position recognition unit 24 may be omitted and the determination in step S30 may not be performed.

[0058] In the above embodiment, the tamper response unit 23 Figure 3In step S22, a determination is made as to whether to retain the execution of the first guidance process in step S32 until the vehicle 100 enters the standby state in step S31, based on the type of the control target of the target software. In another embodiment, the determination process in step S22 may be omitted, and the execution of the first guidance process in step S32 may be retained until the vehicle 100 enters the standby state in step S31, regardless of the type of the control target of the target software.

[0059] In the above embodiment, the tampering notification unit 25 is provided to notify software tampering, but the tampering notification unit 25 may be omitted.

[0060] in addition, Figure 1 This is a schematic diagram showing the structure of the mobile control device 1 according to the main processing contents for easy understanding of the present invention. The mobile control device 1 can also be configured by other divisions. In addition, the processing of each component can be executed by one hardware unit or by multiple hardware units. Figures 2 and 3 The processing of each component shown may be executed by one program or by a plurality of programs.

[0061] [4. Structures Supported by the Above-mentioned Embodiments]

[0062] The above-mentioned embodiment is a specific example of the following structure.

[0063] (Structure 1) A mobile body control device, comprising: a tampering identification unit, which performs a secure boot process for verifying whether software stored in a storage unit possessed by the mobile body has been tampered with, thereby identifying tampering with the software; and a tampering response unit, which, when the mobile body is in a startup state, performs the secure boot process by the tampering identification unit. When the tampering identification unit identifies tampering with the software related to a specified function of the mobile body, the tampering response unit performs a tampering response retention process for maintaining a state in which the specified function can be used until the mobile body enters a standby state, and after the mobile body enters the standby state, makes the specified function unusable.

[0064] According to the mobile body control device of structure 1, when software tampering is recognized when the mobile body is in the startup state, the state in which the specified functions related to the software can be used is maintained until the mobile body enters the standby state, thereby preventing the mobile body from being unable to be used due to false detection of software tampering.

[0065] (Structure 2) The mobile body control device described in Structure 1, wherein the tampering identification unit executes the secure boot process multiple times, and determines the identification of tampering of the software when tampering is continuously detected more than a specified number of times through the secure boot process, or when the ratio of the number of times tampering is detected in the multiple execution times of the secure boot process is more than a specified ratio.

[0066] According to the mobile object control device of the second configuration, the possibility of erroneous recognition of software tampering can be reduced by executing the secure boot process multiple times to confirm the recognition of software tampering.

[0067] (Structure 3) The mobile body control device described in Structure 2, wherein the tampering identification unit sets the number of judgments when the mobile body is in the startup state to be greater than the number of judgments when the mobile body is in the standby state, and sets the judgment ratio when the mobile body is in the startup state to be greater than the judgment ratio when the mobile body is in the standby state.

[0068] According to the mobile body control device of structure 3, in a case where the risk of theft of the mobile body is assumed to be low because the mobile body is in the startup state and the user is using the mobile body, the possibility of erroneously identifying tampering of the software can be reduced by setting the number of judgments to be greater than when the mobile body is in the standby state, or by setting the judgment ratio to be greater than when the mobile body is in the standby state.

[0069] (Structure 4) The mobile body control device according to Structure 2 or Structure 3, wherein the tamper recognition unit changes the number of determinations and the determination ratio according to the predetermined function.

[0070] According to the mobile object control device of the fourth configuration, the possibility of erroneously recognizing software tampering can be reduced by changing the appropriate number of determinations and the determination ratio according to a predetermined function related to the software.

[0071] (Structure 5) A mobile body control device according to any one of Structures 1 to 4, wherein, when the mobile body is in an activated state, the secure boot processing is performed by the tampering identification unit and tampering of the software related to the prescribed function of the mobile body is identified by the tampering identification unit, the tampering response unit determines whether to perform the tampering response retention processing based on the type of the prescribed function.

[0072] According to the mobile object control device of the fifth configuration, whether or not to execute the tampering response holding process can be determined based on, for example, whether the type of predetermined function related to the software contributes to the control of the movement of the mobile object.

[0073] (Structure 6) A mobile body control device according to any one of Structures 1 to 5, wherein the mobile body is a vehicle, and the mobile body control device includes a mobile body position identification unit that identifies the position of the mobile body, and when the mobile body is in an activated state and the mobile body position identification unit identifies that the mobile body is outside a road, the tampering identification unit performs the secure boot processing and the tampering identification unit identifies tampering of the software related to the prescribed function of the mobile body, the tampering response unit does not perform the tampering response retention processing, and the prescribed function cannot be used.

[0074] According to the mobile body control device of structure 6, even if the vehicle is parked in a parking space outside the road, etc. and the prescribed functions related to the software that has been identified as tampered cannot be used, it is possible to immediately disable the prescribed functions and perform tampering response processing if it is assumed that the user will suffer less adverse conditions.

[0075] (Structure 7) A mobile body control device according to any one of Structures 1 to 6, wherein the mobile body control device includes a tampering notification unit, and when tampering of the software is identified by the tampering identification unit, the tampering notification unit outputs warning information about tampering of the software from a notification device used in the mobile body.

[0076] According to the mobile object control device of the seventh configuration, it is possible to notify the user that tampering with the software has been recognized, thereby prompting the user to take measures to address the tampering.

[0077] (Structure 8) A mobile body control device according to any one of Structures 1 to 7, wherein the mobile body control device has a tampering notification unit, and when tampering of the software is identified by the tampering identification unit, the tampering notification unit sends a warning message about the tampering of the software to a user terminal used by a user of the mobile body.

[0078] According to the mobile object control device of the eighth configuration, it is possible to notify the user that software tampering has been recognized, thereby prompting the user to take measures to address the tampering.

[0079] (Structure 9) A mobile body control method, which is a mobile body control method executed by a computer, wherein the mobile body control method includes: a tampering identification step, executing a secure boot process to verify whether software stored in a storage unit possessed by the mobile body has been tampered with to identify tampering of the software; and a tampering response step, when the mobile body is in a startup state, executing the secure boot process by the tampering identification step, and when tampering of the software related to a specified function of the mobile body is identified by the tampering identification step, executing a tampering response retention process to maintain a state in which the specified function can be used until the mobile body enters a standby state, and after the mobile body enters the standby state, making the specified function unusable.

[0080] By executing the movable body control method of Configuration 9 on a computer, the same operational effects as those of the movable body control device of Configuration 1 can be obtained.

[0081] (Structure 10) A storage medium storing a program that causes a computer to function as: a tampering identification unit that performs a secure boot process for verifying whether software stored in a storage unit possessed by a mobile body has been tampered with, thereby identifying tampering with the software; a tampering response unit that, when the mobile body is in a startup state, performs the secure boot process by the tampering identification unit and, when the tampering identification unit identifies tampering with the software related to a specified function of the mobile body, performs a tampering response retention process for maintaining a state in which the specified function can be used until the mobile body enters a standby state, and after the mobile body enters the standby state, renders the specified function of the mobile body unusable.

[0082] The configuration of the mobile object control device of configuration 1 can be realized by executing the program of configuration 10 on a computer.

Claims

1. A mobile object control device comprising: a tampering identification unit that performs a secure boot process for verifying whether software stored in a storage unit included in the mobile object has been tampered with, thereby identifying tampering with the software; and The tamper response unit, when the mobile body is in the startup state, performs the secure boot processing by the tamper identification unit and, in the case where the tamper identification unit identifies tampering of the software related to the specified function of the mobile body, the tamper response unit performs tamper response retention processing to maintain the state in which the specified function can be used until the mobile body enters the standby state, and after the mobile body enters the standby state, the specified function cannot be used.

2. The mobile body control device according to claim 1, wherein: The tampering identification unit executes the secure boot process multiple times, and determines the identification of tampering of the software when tampering is continuously detected more than a specified number of times through the secure boot process, or when the ratio of the number of times tampering is detected in the multiple execution times of the secure boot process is more than a specified judgment ratio.

3. The mobile body control device according to claim 2, wherein The tamper recognition unit sets the number of determinations when the mobile body is in an active state to be greater than the number of determinations when the mobile body is in a standby state. The determination ratio when the moving object is in the active state is set to be larger than the determination ratio when the moving object is in the standby state.

4. The mobile body control device according to claim 2 or 3, wherein: The tamper recognition unit changes the number of determinations and the determination ratio according to the predetermined function.

5. The mobile body control device according to any one of claims 1 to 3, wherein: When the mobile body is in the startup state, the tampering identification unit performs the secure boot processing and the tampering identification unit identifies tampering of the software related to the specified function of the mobile body, the tampering response unit decides whether to perform the tampering response retention processing according to the type of the specified function.

6. The mobile body control device according to any one of claims 1 to 3, wherein: The mobile object is a vehicle, The mobile object control device includes a mobile object position recognition unit that recognizes the position of the mobile object. When the mobile body is in the startup state and the mobile body position identification unit identifies that the mobile body is outside the road, the tampering identification unit performs the secure boot processing and the tampering identification unit identifies tampering of the software related to the specified function of the mobile body, the tampering response unit does not perform the tampering response retention processing, so that the specified function cannot be used.

7. The mobile body control device according to any one of claims 1 to 3, wherein: The mobile body control device includes a tampering notification unit configured to output warning information regarding the software tampering from a notification device used in the mobile body when the tampering recognition unit recognizes tampering of the software.

8. The mobile body control device according to any one of claims 1 to 3, wherein: The mobile body control device includes a tampering notification unit that transmits warning information regarding the software tampering to a user terminal used by a user of the mobile body when the tampering recognition unit recognizes tampering of the software.

9. A mobile object control method, which is a mobile object control method executed by a computer, wherein: The mobile object control method comprises: a tampering identification step of performing a secure boot process for verifying whether software stored in a storage unit provided in the mobile object has been tampered with, thereby identifying tampering with the software; and A tampering response step, when the mobile body is in the startup state, performs the secure boot processing through the tampering identification step, and in the case where tampering of the software related to the specified function of the mobile body is identified through the tampering identification step, performs a tampering response retention processing for maintaining the state in which the specified function can be used until the mobile body enters the standby state, and after the mobile body enters the standby state, makes the specified function unusable.

10. A storage medium storing a program for causing a computer to function as: a tampering identification unit that performs a secure boot process to verify whether software stored in a storage unit provided in the mobile object has been tampered with, thereby identifying tampering with the software; The tamper response unit, when the mobile body is in the startup state, performs the secure boot processing by the tamper identification unit and, in the case where the tamper identification unit identifies tampering of the software related to the specified function of the mobile body, the tamper response unit performs tamper response retention processing to maintain the state in which the specified function can be used until the mobile body enters the standby state, and after the mobile body enters the standby state, the specified function of the mobile body cannot be used.

Citation Information

Patent Citations

  • Information processing device, and information processing method

    JP2021002168A