Authentication method, authentication system, and authentication device
By generating a third certificate through device authentication between the vehicle and the external device, the problem of inaccurate judgment of the autonomous driving level after the external device is installed on the vehicle is solved, ensuring system safety and liability attribution, and realizing the safe state of the autonomous driving system.
Patent Information
- Application Number
- CN202511174285.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2019-08-30
- Filing Date
- 2020-08-21
- Publication Date
- 2025-11-07
AI Technical Summary
After installing external devices on a vehicle, it becomes difficult to properly determine the overall level of autonomous driving of the system, leading to unclear liability and affecting system safety.
By certifying devices between vehicles and external devices, a third certificate is generated using the vehicle's first certificate and the external device's second certificate. Based on the certification results, the combination status of the vehicle and external devices is effectively determined, ensuring the overall autonomous driving level of the autonomous driving system.
It enables accurate judgment of the overall autonomous driving level of the autonomous driving system, ensures system safety, prevents the installation of improper external devices, and maintains a safe state.
Smart Images

Figure CN120902769A_ABST
Abstract
Description
[0001] This application is a divisional application of the Chinese Patent Application No. 202080007417.4, filed on August 21, 2020, with the title of “Authentication method, authentication system, and authentication device”. TECHNICAL FIELD
[0002] The present disclosure relates to an authentication method, an authentication system, and an authentication device in an automatic driving system. BACKGROUND
[0003] In recent years, automobile driving is gradually shifting from the past where it is driven by people to driving using an automatic driving system. In an automatic driving system (hereinafter referred to as an automatic driving system), all of a steering device, a brake, and an accelerator are operated by an electronic control unit (hereinafter referred to as an ECU: Electronic Control Unit) in accordance with values of various sensors. As a result, it is expected that the number of traffic accidents based on human errors will decrease, and environmental pollution caused by exhaust gas and the like will be suppressed.
[0004] Generally, an automatic driving system is roughly divided into three components. The three components refer to a cognition unit that obtains information on traffic conditions and the like through sensors for measuring the surrounding environment or communication, a judgment unit that determines the optimal travel path and travel speed and the like based on information from the cognition unit, and a control unit that operates an accelerator, a brake, a steering device, and the like based on the judgment result of the judgment unit. Among them, especially in the technical field of the cognition unit and the judgment unit, research and development are continuously conducted in order to achieve a higher level of automatic driving, and significant technical progress has been made. Since the development of vehicles is inevitably long-term and takes several years, a method of implementing the cognition unit and the judgment unit as an external device separate from the vehicle has been proposed. By connecting a vehicle already equipped with an automatic driving system to an external device separate from the vehicle, the external device is equipped with components that can achieve a higher level of automatic driving system, and thus the latest automatic driving system can be implemented at all times.
[0005] However, in the process of achieving full automation of the automatic driving system, it is assumed that the steering performed by the driver and the steering performed by the ECU will be mixed together, and there are many discussions on where the responsibility lies. For example, in Non-Patent Literature 1, the automatic driving level is defined as six levels of 0-5, and the responsibility is defined for each level.
[0006] (Prior Art Documents)
[0007] (Non-Patent Literature)
[0008] Non-Patent Literature 1: SAE-J3016_201806: Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicle
[0009] In correspondence with such an automatic driving level, it becomes important which automatic driving level the current vehicle is in. However, with the automatic driving system having the split external device, by installing the external device, a more highly automatic driving system can be realized, and the automatic driving level can be changed in accordance with the installed external device. That is, it is necessary to appropriately judge the automatic driving level when the external device is installed on the vehicle. SUMMARY
[0010] Therefore, the present disclosure aims to provide a certification method and the like that can appropriately judge the automatic driving level of the entire automatic driving system when an external device is installed on a vehicle.
[0011] To achieve the above object, one aspect of the present disclosure relates to a certification method in an automatic driving system including a vehicle and an external device that communicates with the vehicle and provides a function for the vehicle to automatically travel, in which the vehicle holds a first certificate for proving the legitimacy of the vehicle, the external device holds a second certificate for proving the legitimacy of the external device, and in the certification method, a third certificate for proving the legitimacy of the combination of the vehicle and the external device is made valid in accordance with the result of device certification of the vehicle and the external device using the first certificate and the second certificate.
[0012] With the present disclosure, the automatic driving level of the entire automatic driving system when an external device is installed on a vehicle can be appropriately judged. As a result, a safer automatic driving system can be provided. BRIEF DESCRIPTION OF DRAWINGS
[0013] Figure 1 is a diagram showing an example of the overall configuration of the automatic driving system in Embodiment 1.
[0014] Figure 2 is a diagram showing an example of the configuration of the ECU in Embodiment 1.
[0015] Figure 3 is a diagram showing an example of the configuration of the automatic driving ECU in Embodiment 1.
[0016] Figure 4FIG. 1 is a diagram showing an example of the configuration of a communication ECU on the vehicle side in Embodiment 1.
[0017] Figure 5 FIG. 2 is a diagram showing an example of the format of a public key certificate.
[0018] Figure 6 FIG. 3 is a diagram showing an example of the format of a certificate table in Embodiment 1.
[0019] Figure 7 FIG. 4 is a diagram showing an example of the configuration of a communication ECU on the external device side in Embodiment 1.
[0020] Figure 8 FIG. 5 is a sequence chart showing an example of the action of authentication of the vehicle and the external device in Embodiment 1.
[0021] Figure 9 FIG. 6 is a flowchart showing an example of the action of making a public key certificate valid in Embodiment 1.
[0022] Figure 10 FIG. 7 is a flowchart showing an example of the action of making a public key certificate invalid in Embodiment 1.
[0023] Figure 11 FIG. 8 is a flowchart showing an example of the action of making a public key certificate valid in a modification example of Embodiment 1.
[0024] Figure 12 FIG. 9 is a flowchart showing an example of the action of making a public key certificate invalid in a modification example of Embodiment 1.
[0025] Figure 13 FIG. 10 is a diagram showing an example of the overall configuration of an automatic driving system in Embodiment 2.
[0026] Figure 14 FIG. 11 is a diagram showing an example of the configuration of a communication ECU on the vehicle side in Embodiment 2.
[0027] Figure 15 FIG. 12 is a diagram showing an example of the configuration of a V2X communication ECU in Embodiment 2.
[0028] Figure 16 FIG. 13 is a diagram showing an example of the configuration of a server in Embodiment 2.
[0029] Figure 17 FIG. 14 is a diagram showing an example of the format of a certificate table in Embodiment 2.
[0030] Figure 18 FIG. 15 is a sequence chart showing an example of the action of issuing a public key certificate in Embodiment 2.
[0031] Figure 19is a sequence diagram showing an example of the action of invalidating a public key certificate in Embodiment 2.
[0032] Figure 20 is a sequence diagram showing an example of the action of issuing a public key certificate in a modification example of Embodiment 2.
[0033] Figure 21 is a sequence diagram showing an example of the action of invalidating a public key certificate in a modification example of Embodiment 2.
[0034] Figure 22 is a diagram showing an example of the overall configuration of an automatic driving system in Embodiment 3.
[0035] Figure 23 is a diagram showing an example of the configuration of a communication ECU on the vehicle side in Embodiment 3.
[0036] Figure 24 is a diagram showing an example of the configuration of a communication ECU on the external device side in Embodiment 3.
[0037] Figure 25 is a sequence diagram showing an example of the action of issuing a public key certificate in Embodiment 3.
[0038] Figure 26 is a sequence diagram showing an example of the action of invalidating a public key certificate in Embodiment 3.
[0039] Figure 27 is a sequence diagram showing an example of the action of issuing a public key certificate in a modification example of Embodiment 3.
[0040] Figure 28 is a sequence diagram showing an example of the action of invalidating a public key certificate in a modification example of Embodiment 3. DETAILED DESCRIPTION
[0041] To solve the problem, an authentication method according to one embodiment of the present disclosure is an authentication method in an automatic driving system including a vehicle and an external device that communicates with the vehicle and provides a function for the vehicle to automatically travel, in which the vehicle holds a first certificate for proving the legitimacy of the vehicle, the external device holds a second certificate for proving the legitimacy of the external device, and in the authentication method, a third certificate for proving the legitimacy of a combination of the vehicle and the external device is made valid in accordance with the result of device authentication of the vehicle and the external device performed using the first certificate and the second certificate.
[0042] In the automated driving system, in a case where the external device is mounted on the vehicle, the vehicle and the external device perform device authentication, and in a case where the device authentication is successful, the automated driving system, as a result of the device authentication, is able to recognize a combination of a proper vehicle and a proper external device included in the automated driving system. For example, the automated driving system holds a third certificate each time the vehicle and the external device are combined, and each of the third certificates corresponds to an automated driving level of the entire automated driving system for each combination. Thus, the automated driving system makes the third certificate corresponding to the recognized combination valid, is able to recognize the automated driving level corresponding to the valid third certificate, that is, is able to recognize the automated driving level of the entire automated driving system when the vehicle and the external device are combined. In this way, the automated driving level of the entire automated driving system when the vehicle is mounted with the external device can be properly judged, and as the entire system, a safe state can be maintained.
[0043] Further, in the authentication method, information on the automated driving level of the entire automated driving system when the vehicle and the external device are combined can be further outputted in correspondence with the valid third certificate.
[0044] Thus, the automated driving level of the entire automated driving system can be notified to an occupant or a manager of the vehicle, or the like, or the automated driving corresponding to the automated driving level of the entire automated driving system can be performed.
[0045] Further, in the validity of the third certificate, the third certificate corresponding to at least one of a vehicle ID of the vehicle and a device ID of the external device obtained as a result of the device authentication can be made valid.
[0046] In this way, by obtaining the vehicle ID of the proper vehicle or the device ID of the proper external device, the third certificate corresponding to the vehicle ID or the device ID can be made valid.
[0047] Further, the third certificate can be issued at the time of manufacturing the vehicle and pre-held in the vehicle.
[0048] Thus, an external communication device or the like is omitted, and the certificate can be made valid on the vehicle quickly. Further, the third certificate is pre-issued only for a specific combination of a specific vehicle and a specific external device, and thus for combinations other than the specific combination, the validity of the third certificate can be limited, and as the entire system, a safer state can be maintained.
[0049] Further, the automatic driving system can further include a server, and the third certificate can be transmitted from the server to the vehicle or the external device at the time of the device authentication.
[0050] Thus, it is not necessary to provide a storage area for holding a pre-issued certificate in the vehicle or the like, and it is possible to save the storage area. Further, it is possible to easily add a third certificate for a new combination of the vehicle and the external device.
[0051] Further, the third certificate can be valid in a case where a specific condition is satisfied with respect to a driving state of the vehicle.
[0052] Thus, the third certificate is valid in a case where the driving state of the vehicle satisfies a specific condition. For example, the third certificate is valid at a timing where the driving state of the vehicle has no influence on the driver, and it is possible to not degrade convenience.
[0053] Further, the driving state of the vehicle in which the specific condition is satisfied can be a state where the vehicle is parked.
[0054] Generally, an external device is not installed on a vehicle that is running, and thus it is indicated that there is a possibility that some abnormality occurs with respect to the installation of the external device on the vehicle while the vehicle is running, in other words, the device authentication is performed while the vehicle is running. Therefore, by making the third certificate valid only in a case where the vehicle is parked, it is possible to suppress the third certificate from being valid in a state where an abnormality is likely to occur. Further, it is possible to suppress an erroneous operation such as making the third certificate valid while the vehicle is running.
[0055] Further, the state of the vehicle and the external device can be further monitored, and the third certificate can be invalidated in accordance with a change in the state.
[0056] Depending on the state of the vehicle and the external device, it is sometimes better to restore the automatic driving level from the entire automatic driving system to the vehicle alone, and thus it is possible to invalidate the third certificate in accordance with the state of the vehicle and the external device, and appropriately set the automatic driving level.
[0057] Further, the state can be a communication state between the vehicle and the external device, and the third certificate can be invalidated in a case where the communication state becomes abnormal in the invalidation of the third certificate.
[0058] In a case where a communication abnormality occurs between the vehicle and the external device, the automatic driving system including the vehicle and the external device cannot function properly, and thus the third certificate is invalidated in accordance with the communication state of the vehicle and the external device that has an influence on the automatic driving level, and it is possible to appropriately set the automatic driving level.
[0059] Further, in the monitoring of the state, the state can be monitored in a case where a traveling state of the vehicle satisfies a specific condition.
[0060] Thus, when the traveling state of the vehicle changes, the necessity of the invalidation processing of the third certificate is confirmed, and thus the safety of the driver can be ensured.
[0061] Further, the traveling state of the vehicle that satisfies the specific condition can be a state where the vehicle is parked.
[0062] Thus, the invalidation processing of the third certificate is limited only to the case where the vehicle is parked, and thus the processing load can be reduced.
[0063] Further, the authentication system in one embodiment of the present disclosure is an authentication system in an automatic driving system that includes a vehicle and an external device that communicates with the vehicle and provides a function for the vehicle to automatically travel, in which the vehicle holds a first certificate that proves the legitimacy of the vehicle, the external device holds a second certificate that proves the legitimacy of the external device, and the authentication system includes a management unit that makes a third certificate that proves the legitimacy of the combination of the vehicle and the external device valid based on the result of device authentication of the vehicle and the external device using the first certificate and the second certificate.
[0064] Thus, an authentication system that can appropriately determine the automatic driving level of the entire automatic driving system when the external device is installed on the vehicle can be provided.
[0065] Further, the authentication device in one embodiment of the present disclosure is an authentication device included in a vehicle in an automatic driving system that includes the vehicle and an external device that communicates with the vehicle and provides a function for the vehicle to automatically travel, in which the authentication device includes a holding unit that holds a first certificate that proves the legitimacy of the vehicle, an authentication unit that authenticates the external device using a second certificate that proves the legitimacy of the external device, and a management unit that makes a third certificate that proves the legitimacy of the combination of the vehicle and the external device valid based on the result of the authentication.
[0066] Thus, an authentication device that can appropriately determine the automatic driving level of the entire automatic driving system when the external device is installed on the vehicle can be provided. Further, the installation of an illegitimate external device on the vehicle can be prevented, the automatic driving level can not be erroneously increased, and a safe state can be maintained.
[0067] Further, the authentication device in an embodiment of the present disclosure is an authentication device provided in an external device in an autonomous driving system including a vehicle and the external device, the external device communicating with the vehicle and providing a function for the vehicle to autonomously travel, the authentication device including a holding unit that holds a second certificate for proving legitimacy of the external device, an authentication unit that authenticates the vehicle using a first certificate for proving legitimacy of the vehicle, and a management unit that makes a third certificate for proving legitimacy of a combination of the vehicle and the external device valid using a result of the authentication.
[0068] Thus, an authentication device that can appropriately determine an autonomous driving level of an autonomous driving system as a whole when an external device is installed on a vehicle can be provided. Further, installation of an external device on an illegitimate vehicle can be prevented, an autonomous driving level can not be erroneously increased, and a safe state can be maintained.
[0069] An authentication method and the like related to an embodiment of the present disclosure will be described below with reference to the drawings. Note that the following embodiments are merely one specific example illustrating a preferred embodiment of the present disclosure. In other words, the numerical values, constituent elements, arrangement and connection forms of the constituent elements, steps, and order of the steps, and the like shown in the following embodiments are merely one example of the present disclosure, and the gist of the present disclosure is not limited to the present disclosure. The present disclosure is determined based on the description of the technical solution. Further, in the constituent elements in the following embodiments, the constituent elements not described with respect to the independent technical solution showing the highest concept of the present disclosure are not necessarily constituent elements for achieving the object of the present disclosure, and can be described as constituent elements for a better configuration.
[0070] (Embodiment 1)
[0071] [1. System Configuration]
[0072] Here, as an embodiment of the present disclosure, an autonomous driving system 1000 will be described with reference to the drawings.
[0073] [1.1 Overall Configuration of Autonomous Driving System 1000]
[0074] Figure 1 is a drawing illustrating an example of the overall configuration of the autonomous driving system 1000 in Embodiment 1.
[0075] The autonomous driving system 1000 is configured of a vehicle 1001 and an external device 1002 connected to the vehicle 1001 and operating in conjunction with the vehicle 1001.
[0076] For example, the vehicle 1001 is configured of the ECUs 1100a, 1100b, 1100c, and 1100d connected to various in-vehicle networks, the respective control targets of the ECUs, that is, the camera 1010, the brake 1011, the steering wheel 1012, and the accelerator 1013, the automatic driving ECU 1200 that performs control relating to automatic driving by communicating with the respective ECUs 1100a to 1100d, and the communication ECU 1300 that communicates with the automatic driving ECU 1200 via the in-vehicle network.
[0077] The ECUs 1100a to 1100d transmit and receive communication packets to and from each other via the in-vehicle network, thereby implementing control of the vehicle. As the in-vehicle network, Ethernet (registered trademark) or CAN (registered trademark) (Controller Area Network), or the like is used.
[0078] The automatic driving ECU 1200 communicates with the other ECUs via the in-vehicle network and performs judgment and control instruction necessary for automatic driving.
[0079] The communication ECU 1300 communicates with the external device 1002 and transmits and receives packets between the external device 1002 and the other ECUs in the vehicle 1001.
[0080] The external device 1002 is a device that communicates with the vehicle 1001 and provides one or more functions for automatic travel (for example, steering and acceleration / deceleration instruction, and the like) of the vehicle 1001. For example, the external device 1002 is configured of the ECU 1100e, the control target of the ECU 1100e, that is, the Lidar 1014, and the communication ECU 1400 that communicates with the ECU 1100e via the in-vehicle network.
[0081] The ECU 1100e, like the ECU 1100a, exchanges communication packets via the in-vehicle network. As the in-vehicle network, Ethernet, or the like is used.
[0082] The communication ECU 1400 communicates with the vehicle 1001 and transmits and receives packets between the vehicle 1001 and the other ECUs in the external device 1002.
[0083] [1.2 Configuration Diagram of ECU 1100a]
[0084] Figure 2 is a diagram illustrating an example of the configuration of the ECU 1100a in Embodiment 1.
[0085] For example, the ECU 1100a is constituted by a communication section 1101 and a message conversion section 1102. Also, the same constitution applies to the ECU 1100b, the ECU 1100c, the ECU 1100d, and the ECU 1100e, and the description thereof is omitted here.
[0086] The communication section 1101 communicates with external ECUs or various sensors via the in-vehicle network. The communication section 1101 notifies the message conversion section 1102 of a received message or a sensor value. Further, the communication section 1101 transmits a message notified by the message conversion section 1102 to other ECUs or various sensors.
[0087] The message conversion section 1102 converts a sensor value of various sensors notified by the communication section 1101 in accordance with the format of the in-vehicle network, and transmits the sensor value to other ECUs via the communication section 1101. Further, the message conversion section 1102 converts a communication message received by the communication section 1101 into a sensor value or setting information, and transmits the sensor value or the setting information to various sensors via the communication section 1101.
[0088] [1.3 Configuration diagram of autonomous driving ECU 1200]
[0089] Figure 3 is a diagram illustrating an example of the configuration of the autonomous driving ECU 1200 in Embodiment 1.
[0090] For example, the autonomous driving ECU 1200 is constituted by a communication section 1201, a determination section 1202, and an autonomous driving level management section 1203.
[0091] The communication section 1201 communicates with other ECUs via the in-vehicle network, and notifies the determination section 1202 and the autonomous driving level management section 1203 of a received message. Further, the communication section 1201 transmits a message notified by the determination section 1202 to other ECUs.
[0092] The determination section 1202 obtains various sensor values from a received message notified by the communication section 1201, and transmits a necessary control instruction to other ECUs via the communication section 1201.
[0093] The autonomous driving level management section 1203 obtains information of a current certificate from a message notified by the communication section 1201, and thereby manages a current autonomous driving level, and notifies the determination section 1202. The determination section 1202 can perform an action corresponding to the current autonomous driving level. For example, the kind of a sensor used or the amount of data, or the like can be changed in correspondence with the current autonomous driving level.
[0094] [1.4 Configuration diagram of communication ECU 1300 on the vehicle 1001 side]
[0095] Figure 4 FIG. 1 is a diagram showing an example of the configuration of the communication ECU 1300 on the vehicle 1001 side in Embodiment 1.
[0096] For example, the communication ECU 1300 is configured by a communication section 1301, an authentication processing section 1302, an authentication information holding section 1303, a certificate management section 1304, and a certificate holding section 1305. The communication ECU 1300 is an example of an authentication device possessed by the vehicle 1001 in the automated driving system 1000.
[0097] The communication section 1301 communicates with the external device 1002. For example, the communication section 1301 communicates with the external device 1002 by wire. In addition, the communication section 1301 communicates with the automated driving ECU 1200 in the vehicle 1001 via an in-vehicle network. In addition, the communication section 1301 can communicate with a server or the like. The communication section 1301 notifies the authentication processing section 1302 and the certificate management section 1304 of a communication message received by the external device 1002. In addition, the communication section 1301 receives a notification from the authentication processing section 1302 and transmits a communication message to the external device 1002. As will be described later in detail, the communication section 1301 is an example of an output section that outputs information on the automated driving level of the entire automated driving system 1000 when the vehicle 1001 and the external device 1002 are combined, which corresponds to the 3rd certificate that is valid.
[0098] The authentication processing section 1302 communicates with the external device 1002 via the communication section 1301 and performs authentication processing of the external device 1002. The authentication processing section 1302 is an example of an authentication section that authenticates the external device 1002 using the 2nd certificate for proving the legitimacy of the external device 1002. In addition, the authentication processing section 1302 obtains information necessary at the time of authentication processing from the authentication information holding section 1303. In addition, the authentication processing section 1302 notifies the certificate management section 1304 of the result of the authentication processing.
[0099] The authentication information holding section 1303 holds a key pair of a private key and a public key certificate. The authentication information holding section 1303 is an example of a holding section that holds the 1st certificate for proving the legitimacy of the vehicle 1001. The public key certificate held by the authentication information holding section 1303 is an example of the 1st certificate. The private key and the public key certificate are embedded in the authentication information holding section 1303 at the time of shipment of the vehicle 1001.
[0100] Figure 5 FIG. 2 is a diagram showing an example of the format of a public key certificate.
[0101] The public key certificate is constituted of a version, an issuer, a start and an end of a valid period, an autonomous driving level, a certificate ID, and a signature of a certification authority. The public key certificate can not include the autonomous driving level.
[0102] The certificate holding unit 1305 holds a public key certificate group and a certificate table. The public key certificate held by the certificate holding unit 1305 is an example of the 3rd certificate for proving the legitimacy of the combination of the vehicle 1001 and the external device 1002. The certificate holding unit 1305 holds the 3rd certificate for each of various combinations of the vehicle 1001 and the external device 1002 (that is, a 3rd certificate group). In Embodiment 1, the 3rd certificate group is issued at the time of the manufacture of the vehicle 1001 and is held in the vehicle 1001 in advance. For example, the 3rd certificate group is embedded in the certificate holding unit 1305 at the time of the shipment of the vehicle 1001. Each of the 3rd certificate group corresponds to the autonomous driving level of the autonomous driving system 1000 as a whole at the time when the external device 1002 is installed in the vehicle 1001.
[0103] Figure 6 Fig. 13 is a diagram showing an example of the format of the certificate table in Embodiment 1. Each row in the certificate table corresponds to each 3rd certificate. For example, each row of the certificate table is constituted of the certificate ID of the 3rd certificate, the autonomous driving level corresponding to the 3rd certificate, the device ID corresponding to the 3rd certificate, and the state of the 3rd certificate. In addition, the state of each 3rd certificate is rewritten to valid and invalid according to the current state.
[0104] The certificate management unit 1304 is an example of a management unit, and the certificate management unit 1304 makes the 3rd certificate valid using the result of the authentication by the authentication processing unit 1302. The certificate management unit 1304 notifies the authentication information holding unit 1303 of the 3rd certificate corresponding to the result of the authentication among the 3rd certificate group held in advance using the result of the authentication notified by the authentication processing unit 1302 and the certificate table held in the certificate holding unit 1305, and saves it in the authentication information holding unit 1303. Thus, the notified 3rd certificate is registered in the authentication information holding unit 1303, and the 3rd certificate is made valid. Further, the certificate management unit 1304 deletes the 3rd certificate saved in the authentication information holding unit 1303 according to the result of the communication processing from the communication unit 1301. Thus, the registration of the 3rd certificate in the authentication information holding unit 1303 is released, and the valid 3rd certificate becomes invalid. The processing of the validity and the invalidity of the 3rd certificate will be described later in detail.
[0105] [1.5 Configuration diagram of the communication ECU 1400 on the external device 1002 side]
[0106] Figure 7This is a diagram showing an example of the configuration of the communication ECU 1400 on the external device 1002 side in Embodiment 1.
[0107] The communication ECU 1400 consists of a communication unit 1401, an authentication processing unit 1402, and an authentication information retention unit 1403.
[0108] Communication unit 1401 communicates with vehicle 1001. For example, communication unit 1401 communicates with vehicle 1001 via a wired connection. Furthermore, communication unit 1401 communicates with ECU 1100e within external device 1002 via an in-vehicle network. Communication unit 1401 notifies authentication processing unit 1402 of communication messages received from vehicle 1001. Additionally, communication unit 1401 receives notifications from authentication processing unit 1402 and sends communication messages to vehicle 1001.
[0109] The authentication processing unit 1402 communicates with the vehicle 1001 via the communication unit 1401 to perform authentication processing on the vehicle 1001. The authentication processing unit 1402 is an example of an authentication unit; it authenticates the vehicle 1001 using a first certificate used to prove the legitimacy of the vehicle 1001. Furthermore, the authentication processing unit 1402 obtains the information required for the authentication process through the authentication information retention unit 1403.
[0110] The authentication information retention unit 1403 retains a key pair of a private key and a public key certificate. The authentication information retention unit 1403 is an example of a retention unit that retains a second certificate used to prove the legitimacy of the external device 1002. The public key certificate retained by the authentication information retention unit 1403 is an example of a second certificate. The private key and public key certificate are embedded in the authentication information retention unit 1403 when the external device 1002 is shipped. The format of the public key certificate (second certificate) is, for example, similar to... Figure 5 Similarly, the explanation is omitted here.
[0111] [1.6 An example of an authentication sequence]
[0112] Then use Figure 8 This describes the mutual authentication performed between the communication ECU 1300 on the vehicle 1001 side and the communication ECU 1400 on the external device 1002 side when the external device 1002 is installed on the vehicle 1001.
[0113] Figure 8 This is a sequence diagram illustrating an example of the authentication operation between the vehicle 1001 and the external device 1002 in Embodiment 1.
[0114] The external device 1002 transmits a connection request to the vehicle 1001 (S1101). At this time, the external device 1002 transmits the device ID of the external device 1002 and the public key certificate (i.e., the 2nd certificate) together.
[0115] The vehicle 1001 verifies the signature of the public key certificate received from the external device 1002 (S1102). The vehicle 1001, in a case where the verification is not successful (NO in S1102), notifies the external device 1002 of an error and ends the process.
[0116] The vehicle 1001, in a case where the verification is successful (YES in S1102), generates a random number, and transmits the generated random number to the external device 1002 together with the vehicle ID of the vehicle 1001 and the public key certificate (i.e., the 1st certificate) (S1103).
[0117] The external device 1002 receives the random number and the public key certificate, and verifies the signature of the public key certificate received from the vehicle 1001 (S1104). The external device 1002, in a case where the verification is not successful (NO in S1104), notifies the vehicle 1001 of an error and ends the process.
[0118] The external device 1002, in a case where the verification is successful (YES in S1104), generates a signature based on the random number received from the vehicle 1001 and the private key of the external device 1002 (S1105).
[0119] The external device 1002 generates a random number, and transmits the generated random number to the vehicle 1001 together with the signature generated in S1105 (S1106).
[0120] The vehicle 1001 receives the signature and the random number, and verifies the signature using the public key certificate received in S1101 (S1107). The vehicle 1001, in a case where the verification of the signature is not successful (NO in S1107), notifies the external device 1002 of an error and ends the process.
[0121] The vehicle 1001, in a case where the verification of the signature is successful (YES in S1107), generates a signature based on the random number received in S1107 and the private key of the vehicle 1001, and transmits the generated signature to the external device 1002 (S1108).
[0122] The external device 1002 receives the signature, and verifies the signature using the public key certificate received in S1104 (S1109). The external device 1002, in a case where the verification of the signature is not successful (NO in S1109), notifies the vehicle 1001 of an error and ends the process.
[0123] In a case where the verification is successful in S1109, the vehicle 1001 registers the device ID of the external device 1002 as a connection object, and the external device 1002 registers the vehicle ID of the vehicle 1001 as a connection object (S1110). In this way, as a result of the device authentication of the vehicle 1001 and the external device 1002, a legitimate vehicle ID of the vehicle 1001 and a legitimate device ID of the external device 1002 are obtained.
[0124] In addition, the device ID is an identifier for identifying the external device 1002, and the form thereof is not particularly limited and can be, for example, a MAC (Media Access Control) address or the like, or an identifier set by each manufacturer. Further, the vehicle ID is an identifier for identifying the vehicle 1001, and the form thereof is not particularly limited and can be, for example, a MAC address or the like, or an identifier set by each manufacturer.
[0125] [1.7 Example of flowchart at the time of making certificate valid]
[0126] Next, the use of the device ID and the vehicle ID will be described. Figure 9 The making of the third certificate corresponding to the automatic driving level valid, which is held in the vehicle 1001, will be described.
[0127] Figure 9 is a flowchart showing an example of the action of making the public key certificate (third certificate) valid in Embodiment 1.
[0128] The certificate management unit 1304 determines whether the registered device ID can be obtained (S1201). The certificate management unit 1304 determines that an error has occurred and ends the process in a case where the device ID has not been registered (NO in S1201). Figure 8 The authentication process of the certificate management unit 1304 ends, and the device ID has been registered.
[0129] The certificate management unit 1304 determines whether the obtained device ID exists in the certificate table (S1202) in a case where the device ID has been obtained (YES in S1201). The certificate management unit 1304 determines that an error has occurred and ends the process in a case where the obtained device ID does not exist in the certificate table (NO in S1202).
[0130] The certificate management unit 1304 changes the third certificate of the certificate ID corresponding to the obtained device ID to "valid" (S1203) in a case where the obtained device ID exists in the certificate table (Yes in S1202). Specifically, the certificate management unit 1304 collates the obtained device ID with the certificate table, notifies the authentication information holding unit 1403 of the third certificate of the certificate ID of the row corresponding to the device ID, and changes the state of the row corresponding to the device ID to "valid". For example, in a case where the external device 1002 having the device ID "XXX" is installed in the vehicle 1001 and the device authentication ends, the certificate management unit 1304 obtains the device ID "XXX", collates the device ID "XXX" with the certificate table, notifies the authentication information holding unit 1403 of the third certificate of the certificate ID "1" of the row corresponding to the device ID "XXX", and changes the state of the row corresponding to the device ID "XXX" to "valid" as shown in FIG. 30. Figure 6
[0131] In this way, the third certificate corresponding to at least one of the vehicle ID of the vehicle 1001 and the device ID of the external device 1002, which are obtained as a result of the device authentication of the vehicle 1001 and the external device 1002, is made valid. Here, the third certificate corresponding to the device ID of the external device 1002 is made valid in the vehicle 1001, and the vehicle ID of the vehicle 1001 itself is fixed, so the third certificate corresponding to the device ID of the external device 1002 is made valid.
[0132] Further, the communication unit 1301 outputs information on the automatic driving level of the entire automatic driving system 1000 corresponding to the third certificate that is made valid (S1204). The automatic driving level of the entire automatic driving system 1000 is the automatic driving level of the automatic driving system 1000 when the vehicle 1001 and the external device 1002 are combined. The information on the automatic driving level of the entire automatic driving system 1000 can be information for displaying the automatic driving level on a display provided in the vehicle 1001 or a monitoring room or the like that monitors the vehicle 1001, or information for displaying that manual driving is not required. Furthermore, the information on the automatic driving level of the entire automatic driving system 1000 can be information for causing the automatic driving ECU 1200 to perform automatic driving corresponding to the automatic driving level of the entire automatic driving system 1000.
[0133] [1.8 Example of Flowchart When Certificate is Made Invalid]
[0134] Next, invalidation of the third certificate corresponding to the automatic driving level, which is held in the vehicle 1001, will be described. Figure 10
[0135] Figure 10 is a flowchart showing an example of the action of invalidating the public key certificate (the 3rd certificate) in Embodiment 1.
[0136] The certificate management unit 1304 monitors the communication state between the vehicle 1001 and the external device 1002 via the communication unit 1301 (S1301).
[0137] The certificate management unit 1304 determines whether or not the communication state between the vehicle 1001 and the external device 1002 has become abnormal (S1302). The certificate management unit 1304 ends the process in the case where no communication abnormality has occurred (NO in S1302).
[0138] The certificate management unit 1304 increments the error counter by 1 in the case where a communication abnormality has occurred (YES in S1302) (S1303).
[0139] The certificate management unit 1304 determines whether or not the error counter is equal to or greater than a threshold value (S1304). In the case where the error counter is less than the threshold value (NO in S1304), the process returns to S1302. The threshold value is not particularly limited and can be appropriately set.
[0140] The certificate management unit 1304 invalidates the valid 3rd certificate in the case where the error counter is equal to or greater than the threshold value (YES in S1304) (S1305). In other words, the certificate management unit 1304 invalidates the 3rd certificate that is valid in the case where the communication abnormality between the vehicle 1001 and the external device 1002 continues for a certain period of time or more. For example, the certificate management unit 1304 invalidates the 3rd certificate by deleting the 3rd certificate stored in the authentication information holding unit 1303. At this time, the certificate management unit 1304 changes the state of the 3rd certificate in the certificate table to "invalid".
[0141] The certificate management unit 1304 resets the error counter (S1306).
[0142] The certificate management unit 1304 deletes the device ID of the connection target (S1307).
[0143] In this way, the certificate management unit 1304 monitors the states of the vehicle 1001 and the external device 1002 and invalidates the 3rd certificate in accordance with a change in the states. Specifically, the states of the vehicle 1001 and the external device 1002 are the communication state between the vehicle 1001 and the external device 1002, and the certificate management unit 1304 invalidates the 3rd certificate in the case where the communication state becomes abnormal.
[0144] [1.9 Effects of Embodiment 1]
[0145] In the autonomous driving system 1000 shown in Embodiment 1, in addition to the 1st certificate of the vehicle 1001 and the 2nd certificate of the external device 1002, a 3rd certificate is installed in advance, and the validity and invalidity of the 3rd certificate are switched according to the communication result of the vehicle 1001 and the external device 1002, so that the appropriate autonomous driving level when the vehicle 1001 and the external device 1002 become one to act can be determined, and the safety can be ensured.
[0146] (Modified example of Embodiment 1)
[0147] In the autonomous driving system 1000 shown in Embodiment 1, the 3rd certificate can be made valid or invalid at any time, but the timing of validity or invalidity can be controlled according to the driving state. This is described in the modified example of Embodiment 1. In addition, the same parts as Embodiment 1 are omitted from the description.
[0148] [1.10 One example of a flowchart when the certificate is made valid]
[0149] Figure 11 is a flowchart showing one example of the operation of making the public key certificate (3rd certificate) valid in the modified example of Embodiment 1. In the modified example of Embodiment 1, the 3rd certificate is made valid when the driving state of the vehicle 1001 satisfies a certain condition. In addition, the same steps as Embodiment 1 are given the same numbers, and the description is omitted.
[0150] For example, the driving state of the vehicle 1001 that satisfies the certain condition is a state of stopping, and the certificate management unit 1304 determines whether the driving state of the vehicle 1001 is in stopping before making the 3rd certificate valid (S1205). The certificate management unit 1304 discontinues the validity processing of the 3rd certificate and ends when the vehicle 1001 is not in stopping (No in S1205), and makes the 3rd certificate valid (S1203) when the vehicle 1001 is in stopping (Yes in S1205).
[0151] [1.11 One example of a flowchart when the certificate is made invalid]
[0152] Figure 12 is a flowchart showing one example of the operation of making the public key certificate (3rd certificate) invalid in the modified example of Embodiment 1. In the modified example of Embodiment 1, when the driving state of the vehicle 1001 satisfies a certain condition, the state of the vehicle 1001 and the external device 1002 (for example, the communication state of the vehicle 1001 and the external device 1002) is monitored, and the 3rd certificate is invalidated according to the communication state. In addition, the same steps as Embodiment 1 are given the same numbers, and the description is omitted.
[0153] The certificate management unit 1304 determines whether the running state of the vehicle 1001 is a parked state (S1308). The certificate management unit 1304 discontinues the invalidation processing of the third certificate and ends in the case where the vehicle 1001 is not in the parked state (NO in S1308), and monitors the communication state (S1301) and continues the invalidation processing in the case where the vehicle 1001 is in the parked state (YES in S1308).
[0154] [1.12 Effects of the Modification of Embodiment 1]
[0155] In the automatic driving system 1000 illustrated in the modification of Embodiment 1, the third certificate is installed in advance in addition to the first certificate of the vehicle 1001 and the second certificate of the external device 1002, and the validity and invalidity of the third certificate are switched in accordance with the running state of the vehicle 1001 in addition to the communication result between the vehicle 1001 and the external device 1002, so that an appropriate automatic driving level when the vehicle 1001 and the external device 1002 act as one can be determined, and safety can be ensured.
[0156] In addition, the functions of the communication ECU 1300 of the vehicle 1001 can be possessed by the external device 1002. That is, the third certificate group can be installed in advance in the external device 1002, and the validity and invalidity of the third certificate can be switched by the external device 1002. In this case, the third certificate is valid in the external device 1002, and the device ID of the external device 1002 itself is fixed, so the third certificate corresponding to the vehicle ID of the vehicle 1001 is valid. The same effects can be obtained in this case as well.
[0157] (Embodiment 2)
[0158] [2. Configuration of System]
[0159] Next, as Embodiment 2 of the present disclosure, an automatic driving system 2000 is described with reference to the drawings.
[0160] [2.1 Overall Configuration of Automatic Driving System 2000]
[0161] Figure 13 is a drawing illustrating an example of the overall configuration of the automatic driving system 2000 in Embodiment 2.
[0162] The automatic driving system 2000 is configured of a vehicle 2001, an external device 1002 connected to the vehicle 2001 to act, and a server 2600 that performs V2X communication with the vehicle 2001.
[0163] In addition, the same components as in Embodiment 1 are given the same numbers, and the description is omitted.
[0164] For example, the vehicle 2001 is constituted by the ECUs 1100a, 1100b, 1100c, and 1100d connected to various in-vehicle networks, the respective control targets of the ECUs, that is, the camera 1010, the brake 1011, the steering wheel 1012, and the accelerator 1013, the automatic driving ECU 1200 that performs control relating to automatic driving in communication with the respective ECUs 1100a to 1100d, the communication ECU 2300 that performs communication with the automatic driving ECU 1200 and the V2X communication ECU 2500 via the in-vehicle network, the V2X communication ECU 2500 that performs V2X communication with the server 2600.
[0165] The communication ECU 2300 performs transmission and reception of messages between the external device 1002 and other ECUs in the vehicle 2001. Further, the communication ECU 2300 performs transmission and reception of messages required when the public key certificate (the third certificate) corresponding to the new automatic driving level when the external device 1002 is installed on the vehicle 2001 is made valid, in communication with the server 2600 via the V2X communication ECU 2500.
[0166] The V2X communication ECU 2500 performs transmission and reception of messages between the server 2600 and the ECU 2300 in the vehicle 2001.
[0167] The server 2600 performs communication with the vehicle 2001, and issues the public key certificate (the third certificate) corresponding to the new automatic driving level when the external device 1002 is installed on the vehicle 2001, in accordance with the authentication result of the vehicle 2001 and the external device 1002.
[0168] [2.2 Configuration diagram of the communication ECU 2300 on the vehicle 2001 side]
[0169] Figure 14 is a diagram illustrating an example of the configuration of the communication ECU 2300 on the vehicle 2001 side in Embodiment 2.
[0170] For example, the communication ECU 2300 is constituted by the communication section 2301, the authentication processing section 1302, the authentication information holding section 1303, and the certificate management section 2304. The communication ECU 2300 is an example of the authentication device possessed by the vehicle 2001 in the automatic driving system 2000. The same configuration as in Embodiment 1 is given the same number, and the following description is omitted.
[0171] The communication section 2301 communicates with the external device 1002. For example, the communication section 2301 communicates with the external device 1002 by wire. In addition, the communication section 2301 communicates with the automatic driving ECU 1200 and the V2X communication ECU 2500 in the vehicle 2001 via an in-vehicle network. The communication section 2301 notifies the authentication processing section 1302 and the certificate management section 2304 of a communication packet received from the external device 1002 and the server 2600. In addition, the communication section 2301 receives a notification from the authentication processing section 1302 and the certificate management section 2304 and transmits a communication packet to the external device 1002 and the server 2600.
[0172] The certificate management section 2304 is an example of a management section that makes a third certificate valid using the result of authentication by the authentication processing section 1302. The certificate management section 2304 obtains, from the server 2600 via the communication section 2301, a public key certificate (third certificate) corresponding to a new automatic driving level, which is issued from the server 2600 using the authentication result notified from the authentication processing section 1302, and saves it in the authentication information holding section 1303. Thus, the third certificate is registered in the authentication information holding section 1303, and the third certificate is made valid on the vehicle 2001 side. In addition, the certificate management section 2304 deletes the third certificate of the authentication information holding section 1303 according to the communication processing result from the communication section 2301. Thus, the registration of the third certificate to the authentication information holding section 1303 is released, and the third certificate that is made valid on the vehicle 2001 side is invalidated.
[0173] [2.3 Configuration Diagram of V2X Communication ECU 2500]
[0174] Figure 15 is a diagram illustrating an example of the configuration of the V2X communication ECU 2500 in Embodiment 2. The V2X communication ECU 2500 is configured by a communication section 2501 and a packet conversion section 2502.
[0175] The communication section 2501 communicates with the communication ECU 2300 via an in-vehicle network. In addition, the communication section 2501 communicates with the server 2600 by V2X communication by wire. The communication section 2501 notifies the packet conversion section 2502 of a received packet. In addition, the communication section 2501 transmits a packet notified from the packet conversion section 2502 to the communication ECU 2300 or the server 2600.
[0176] The message conversion section 2502 converts a message received from the server 2600 via the communication section 2501 in accordance with the format of the in-vehicle network and transmits the message to the communication ECU 2300 via the communication section 2501. In addition, the message conversion section 2502 transmits a communication message received from the communication ECU 2300 via the communication section 2501 to the server 2600 via the communication section 2501.
[0177] [2.4 Configuration of the Server 2600]
[0178] Figure 16 is a diagram illustrating an example of the configuration of the server 2600 in Embodiment 2.
[0179] The server 2600 is configured of a communication section 2601, an authentication processing section 2602, an authentication information holding section 2603, a certificate management section 2604, and a certificate holding section 2605. The server 2600 is an example of an authentication system in the automated driving system 2000.
[0180] The communication section 2601 performs V2X communication with the vehicle 2001. In addition, the communication section 2601 notifies the authentication processing section 2602 and the certificate management section 2604 of the public key certificate (the first certificate and the second certificate) accepted from the vehicle 2001. In addition, the communication section 2601 receives a notification from the authentication processing section 2602 and the certificate management section 2604 and transmits a communication message to the vehicle 2001. The communication section 2601 is an example of an output section that outputs information on the automated driving level of the entire automated driving system 2000 when the vehicle 2001 is combined with the external device 1002, which corresponds to the valid third certificate.
[0181] The authentication processing section 2602 performs communication with the vehicle 2001 via the communication section 2601 and performs signature verification processing on the public key certificate (the first certificate and the second certificate) notified from the vehicle 2001. In addition, the authentication processing section 2602 obtains information required in the signature verification processing from the authentication information holding section 2603. In addition, the authentication processing section 2602 notifies the certificate management section 2604 of the result of the signature verification processing.
[0182] The authentication information holding section 2603 holds a key pair of the private key and the public key certificate of the certification authority. An example of the configuration of the public key certificate is the same as that of the vehicle 2001. Figure 5 Therefore, the description is omitted here.
[0183] The certificate holding section 2605 holds a certificate table.
[0184] Figure 17This diagram illustrates an example of the certificate table format in Implementation Method 2. Each row in the certificate table corresponds to a specific third certificate. For example, each row of the certificate table is composed of the certificate ID of the third certificate, the corresponding autonomous driving level, a combination of the vehicle ID and device ID corresponding to the third certificate, and the status of the third certificate. Furthermore, the status of each third certificate is rewritten as valid or invalid according to its current status.
[0185] Certificate Management Department 2604 is an example of a management department. Based on the device authentication results of vehicle 2001 and external device 1002 using Certificate 1 and Certificate 2, Certificate Management Department 2604 validates Certificate 3. Using the authentication results notified by Authentication Processing Department 2602 and the certificate list held in Certificate Retention Department 2605, Certificate Management Department 2604 reissues Certificate 3 to prove the legitimacy of the combination of vehicle 2001 and external device 1002, notifies vehicle 2001 via Communication Department 2601, and stores it in Authentication Information Retention Department 2603. Thus, the notified Certificate 3 is registered in Authentication Information Retention Department 2603, and the Certificate 3 is validated on server 2600 side. Furthermore, based on an invalidation instruction from Communication Department 2301, Certificate Management Department 2604 deletes Certificate 3 stored in Authentication Information Retention Department 2603. Thus, the registration of Certificate 3 with Authentication Information Retention Department 2603 is deactivated, and Certificate 3, which was valid on server 2600 side, is invalidated.
[0186] [2.5 An example of the sequence when issuing a certificate]
[0187] Then use Figure 18 This describes the issuance of a third certificate by server 2600 after mutual authentication between vehicle 2001 and external device 1002. This third certificate corresponds to the level of autonomous driving. The third certificate issued by server 2600 is retained within vehicle 2001 and is valid.
[0188] Figure 18 This is a sequence diagram illustrating an example of the action of issuing a public key certificate (third certificate) in Implementation 2.
[0189] Vehicle 2001 determines whether it can obtain the registered device ID (S2201). If the device ID has not been registered, vehicle 2001 cannot obtain the device ID (No in S2201), and the authentication process is considered incomplete, so the process ends. This is considered... Figure 8 The authentication process is complete, and the device ID is registered.
[0190] The vehicle 2001, in a case where the device ID of the external device 1002 is obtained (Yes in S2201), transmits the obtained device ID to the server 2600 together with the vehicle ID of the vehicle 2001, the public key certificate (1st certificate) of the vehicle 2001, and the public key certificate (2nd certificate) of the external device 1002.
[0191] The server 2600, receiving the device ID of the external device 1002, the vehicle ID of the vehicle 2001, and the two public key certificates, verifies the signatures of the two public key certificates received (S2202). The server 2600, in a case where the verification is not successful (No in S2202), notifies the vehicle 2001 of an error and ends the processing.
[0192] The server 2600, in a case where the verification is successful (Yes in S2202), confirms whether or not the combination of the device ID and the vehicle ID received in S2202 exists in the certificate table (S2203). The server 2600, in a case where the combination of the device ID and the vehicle ID received does not exist in the certificate table (No in S2203), notifies the vehicle 2001 of the matter and ends the processing as an error.
[0193] The server 2600, in a case where the combination of the device ID and the vehicle ID received exists in the certificate table (Yes in S220), issues the 3rd certificate corresponding to the obtained combination and transmits it to the vehicle 2001 (S2204). Specifically, the certificate management section 2604 of the server 2600 collates the combination of the device ID and the vehicle ID obtained with the certificate table, notifies the authentication information holding section 2603 of the 3rd certificate of the certificate ID of the row corresponding to the combination, and changes the state of the row corresponding to the combination to "valid". For example, in a case where the external device 1002 of the device ID "XXX" is installed in the vehicle 2001 of the vehicle ID "AAA" and the device authentication is completed, the certificate management section 2604 obtains the device ID "XXX" and the vehicle ID "AAA", collates the combination of the device ID "XXX" and the vehicle ID "AAA" with the certificate table, as shown in Figure 17 , notifies the authentication information holding section 2603 of the 3rd certificate of the certificate ID "1" of the row corresponding to the device ID "XXX" and the vehicle ID "AAA", and changes the state of the row corresponding to the device ID "XXX" and the vehicle ID "AAA" to "valid". In this way, the 3rd certificate corresponding to the vehicle ID of the vehicle 2001 and the device ID of the external device 1002 obtained as a result of the device authentication of the vehicle 2001 and the external device 1002 is made valid. Further, the 3rd certificate made valid on the server 2600 side is transmitted to the vehicle 2001.
[0194] The vehicle 2001 holds the 3rd certificate issued by the server 2600 (S2205). For example, the authentication information holding section 1303 in the communication ECU 2300 of the vehicle 2001 holds the 3rd certificate, and thus the 3rd certificate also becomes valid on the vehicle 2001 side.
[0195] Further, although not illustrated, the server 2600 outputs information on the automatic driving level of the automatic driving system 2000 as a whole when the vehicle 2001 and the external device 1002 are combined, which corresponds to the 3rd certificate that is valid. Alternatively, the vehicle 2001 (for example, the communication section 2301) can output information on the automatic driving level of the automatic driving system 2000 as a whole when the vehicle 2001 and the external device 1002 are combined, which corresponds to the 3rd certificate that is valid.
[0196] [2.6 Example of sequence when invalidating certificate]
[0197] Next, the use of the 3rd certificate held by the vehicle 2001 and the server 2600 will be described. Figure 19 The invalidation of the 3rd certificate held by the vehicle 2001 and the server 2600 in correspondence with the automatic driving level will be described. In addition, the same numbers are assigned to the same steps as in Embodiment 1, and the description will be omitted.
[0198] Figure 19 is a sequence diagram illustrating an example of the action of invalidating the public key certificate (3rd certificate) in Embodiment 2.
[0199] The vehicle 2001 determines whether the error counter is equal to or greater than the threshold value (S2304), and in the case where the error counter is equal to or greater than the threshold value (YES in S2304), notifies the server 2600 of the issued public key certificate (3rd certificate), and thus performs invalidation instruction for invalidating the 3rd certificate in the server 2600. In the case where the error counter does not exceed the threshold value (NO in S2304), the process returns to S1302.
[0200] In the case where the error counter is equal to or greater than the threshold value (YES in S2304), the vehicle 2001 and the server 2600 invalidate the 3rd certificate held by each of them (S2305). For example, the certificate management section 2304 in the communication ECU 2300 of the vehicle 2001 invalidates the 3rd certificate by deleting the 3rd certificate held in the authentication information holding section 1303. Further, the certificate management section 2604 of the server 2600 invalidates the 3rd certificate by deleting the 3rd certificate held in the authentication information holding section 2603. In addition, the certificate management section 2604 changes the state of the 3rd certificate in the certificate table to "invalid".
[0201] As described above, in Embodiment 2, the automated driving system 2000 includes the server 2600, and the 3rd certificate is transmitted from the server 2600 to the vehicle 2001 at the time of device authentication.
[0202] [2.7 Effects of Embodiment 2]
[0203] In the automated driving system 2000 shown in Embodiment 2, the 3rd certificate different from the 1st certificate of the vehicle 2001 and the 2nd certificate of the external device 1002 is issued by the server 2600, and the issued 3rd certificate is managed in the vehicle 2001. Also, the validity and invalidity of the 3rd certificate are switched according to the communication result of the vehicle 2001 and the external device 1002, so that the appropriate automated driving level at the time when the vehicle 2001 and the external device 1002 become integrated to act can be determined, and the safety can be ensured.
[0204] (Embodiment 2 Modification)
[0205] In the automated driving system 2000 shown in Embodiment 2, the validity or invalidity of the 3rd certificate can be performed at any time, but the timing of the validity or invalidity can be controlled according to the running state of the vehicle 2001. This is described as a modification of Embodiment 2. In addition, the same parts as Embodiment 2 are omitted from the description.
[0206] [2.8 Example of Sequence at the Time of Issuing a Certificate]
[0207] Figure 20 is a sequence diagram showing an example of the action of issuing a public key certificate (3rd certificate) in the modification of Embodiment 2. In the modification of Embodiment 2, the 3rd certificate is issued when the running state of the vehicle 2001 satisfies a specific condition. In addition, the same steps as Embodiment 2 are given the same numbers, and the description is omitted.
[0208] For example, the running state of the vehicle 2001 that satisfies the specific condition is a state of stopping, and the vehicle 2001 determines whether the running state of the vehicle 2001 is in stopping before starting the process of making the 3rd certificate valid (S2206). In the case where the vehicle 2001 is not in stopping (NO in S2206), the process of making the 3rd certificate valid is not started, and the process is ended. In the case where the vehicle 2001 is in stopping (YES in S2206), the process of making the 3rd certificate valid is started.
[0209] [2.9 Example of Sequence at the Time of Invalidating a Certificate]
[0210] Figure 21is a sequence chart showing an example of the action of invalidating the public key certificate (the 3rd certificate) in the modification of Embodiment 2. In the modification of Embodiment 2, in a case where the running state of the vehicle 2001 satisfies a specific condition, the state (for example, the communication state) of the vehicle 2001 and the external device 1002 is monitored, and the 3rd certificate is invalidated in accordance with the communication state. In addition, the same steps as in Embodiments 1 and 2 are given the same numbers, and the explanation is omitted.
[0211] The vehicle 2001 determines whether the running state of the vehicle 2001 is a state of being parked (S2308). In a case where the vehicle 2001 is not in the state of being parked (NO in S2308), the invalidation process of the 3rd certificate is interrupted and ended, and in a case where the vehicle 2001 is in the state of being parked (YES in S2308), the communication state is monitored (S1301), and the invalidation process is continued.
[0212] [2.10 Effects of the Modification of Embodiment 2]
[0213] In the automatic driving system 2000 shown in Embodiment 2, the 3rd certificate different from the 1st certificate of the vehicle 2001 and the 2nd certificate of the external device 1002 is issued by the server 2600, and the issued 3rd certificate is managed in the vehicle 2001. Moreover, in addition to the communication result between the vehicle 2001 and the external device 1002, the validity and invalidity of the 3rd certificate are switched in accordance with the running state of the vehicle 2001, so that the appropriate automatic driving level when the vehicle 2001 and the external device 1002 become the integrated action can be determined, and the safety can be ensured.
[0214] (Embodiment 3)
[0215] [3. Configuration of the System]
[0216] Next, as Embodiment 3 of the present disclosure, the automatic driving system 3000 is explained with reference to the drawings.
[0217] [3.1 Overall Configuration of the Automatic Driving System 3000]
[0218] Figure 22 is a diagram showing an example of the overall configuration of the automatic driving system 3000 in Embodiment 3.
[0219] The automatic driving system 3000 is configured of the vehicle 3001, the external device 3002 connected to the vehicle 3001 to act, and the server 2600 that performs V2X communication with the external device 3002.
[0220] In addition, the same configuration elements as in Embodiments 1 and 2 are given the same numbers, and the explanation is omitted.
[0221] For example, the vehicle 3001 is configured of the ECUs 1100a, 1100b, 1100c, and 1100d connected to various in-vehicle networks, the respective control targets of the ECUs, that is, the camera 1010, the brake 1011, the steering wheel 1012, and the accelerator 1013, the automatic driving ECU 1200 that performs control relating to automatic driving by communicating with the respective ECUs 1100a to 1100d, the communication ECU 3300 that communicates with the automatic driving ECU 1200 via the in-vehicle network.
[0222] The communication ECU 3300 communicates with the external device 3002 and transmits and receives messages between the external device 3002 and other ECUs in the vehicle 3001.
[0223] For example, the external device 3002 is configured of the ECU 1100e, the control target of the ECU 1100e, that is, the Lidar 1014, the communication ECU 3400 that communicates with the ECU 1100e and the V2X communication ECU 2500 via the in-vehicle network, and the V2X communication ECU 2500 that performs V2X communication with the server 2600.
[0224] The communication ECU 3400 communicates with the vehicle 3001 and transmits and receives messages between the vehicle 3001 and other ECUs in the external device 3002. Further, the communication ECU 3400 communicates with the server 2600 via the V2X communication ECU 2500 and transmits and receives messages necessary when the public key certificate (the third certificate) corresponding to the new automatic driving level is made valid, which is installed on the vehicle 3001 when the external device 1002 is installed.
[0225] [3.2 Configuration Diagram of the Communication ECU 3300 on the Vehicle 3001 Side]
[0226] Figure 23 is a diagram illustrating an example of the configuration of the communication ECU 3300 on the vehicle 3001 side in Embodiment 3.
[0227] For example, the communication ECU 3300 is configured of the communication section 3301, the authentication processing section 3302, and the authentication information holding section 1303. The same configuration as in Embodiment 1 is given the same number, and the description thereof will be omitted below.
[0228] The communication section 3301 communicates with the external device 3002. For example, the communication section 3301 communicates with the external device 3002 by wire. In addition, the communication section 3301 communicates with the automated driving ECU 1200 in the vehicle 3001 via an in-vehicle network. The communication section 3301 notifies the authentication processing section 3302 of a communication packet received from the external device 3002. In addition, the communication section 3301 receives a notification from the authentication processing section 3302 and transmits a communication packet to the external device 3002.
[0229] The authentication processing section 3302 performs an authentication process of the external device 3002 by communicating with the external device 3002 via the communication section 3301. In addition, the authentication processing section 3302 obtains information necessary at the time of the authentication process from the authentication information holding section 1303.
[0230] [3.3 Configuration Diagram of the Communication ECU 3400 on the External Device 3002 Side]
[0231] Figure 24 FIG. 3 is a diagram illustrating an example of a configuration of the communication ECU 3400 on the external device 3002 side in Embodiment 3.
[0232] The communication ECU 3400 is configured of a communication section 3401, an authentication processing section 3402, an authentication information holding section 1403, and a certificate management section 3404. The communication ECU 3400 is an example of an authentication device possessed by the external device 3002 in the automated driving system 3000. The same configuration as in Embodiment 1 is given the same number, and the description thereof will be omitted below.
[0233] The communication section 3401 communicates with the vehicle 3001. For example, the communication section 3401 communicates with the vehicle 3001 by wire. In addition, the communication section 3401 communicates with the ECU 1100e and the V2X communication ECU 2500 in the external device 3002 via an in-vehicle network. The communication section 3401 notifies the authentication processing section 3402 and the certificate management section 3404 of a communication packet received from the vehicle 3001 and the server 2600. In addition, the communication section 3401 receives a notification from the authentication processing section 3402 and the certificate management section 3404 and transmits a communication packet to the vehicle 3001 and the server 2600.
[0234] The authentication processing section 3402 performs communication with the vehicle 3001 via the communication section 3401, and performs authentication processing of the vehicle 3001. The authentication processing section 3402 is an example of an authentication section that authenticates the vehicle 3001 using the first certificate for proving the legitimacy of the vehicle 3001. Further, the authentication processing section 3402 obtains information necessary at the time of authentication processing from the authentication information holding section 1403. Further, the authentication processing section 3402 notifies the certificate management section 3404 of the result of the authentication processing.
[0235] The certificate management section 3404 is an example of a management section that makes the third certificate valid using the result of the authentication by the authentication processing section 3402. The certificate management section 3404 obtains the public key certificate (third certificate) corresponding to the new automated driving level issued by the server 2600 from the server 2600 via the communication section 3401 using the authentication result notified from the authentication processing section 3402, and saves it in the authentication information holding section 1403. Thus, the third certificate is registered in the authentication information holding section 1403, and the third certificate is made valid on the side of the external device 3002. Further, the certificate management section 3404 deletes the third certificate in the authentication information holding section 1403 according to the communication processing result from the communication section 3401. Thus, the registration of the third certificate to the authentication information holding section 1403 is released, and the third certificate valid on the side of the external device 3002 becomes invalid.
[0236] [3.4 Example of sequence at the time of issuance of certificate]
[0237] Next, issuance of the third certificate corresponding to the automated driving level by the server 2600 after the mutual authentication between the vehicle 3001 and the external device 3002 will be described using Figure 25
[0238] Figure 25 is a sequence diagram showing an example of the action of issuing the public key certificate (third certificate) in Embodiment 3.
[0239] The external device 3002 determines whether the registered vehicle ID can be obtained (S3201). The external device 3002, when the vehicle ID is not registered (NO in S3201), cannot obtain the vehicle ID, and considers that the authentication processing is not completed, so the processing is ended. Here, it is considered that the authentication processing of Figure 8 is completed, and the vehicle ID is registered.
[0240] The external device 3002 transmits the obtained vehicle ID to the server 2600 together with the device ID of the external device 3002, the public key certificate (1st certificate) of the vehicle 3001, and the public key certificate (2nd certificate) of the external device 3002, in a case where the vehicle ID of the vehicle 3001 is obtained (Yes in S3201).
[0241] The server 2600 receives the device ID of the external device 3002, the vehicle ID of the vehicle 3001, and the two public key certificates, and verifies the signatures of the two public key certificates received (S3202). The server 2600, in a case where the verification is not successful (No in S3202), notifies the external device 3002 of an error and ends the processing.
[0242] The server 2600, in a case where the verification is successful (Yes in S3202), confirms whether or not the combination of the device ID and the vehicle ID received in S3202 exists in the certificate table (S3203). The server 2600, in a case where the combination of the device ID and the vehicle ID received does not exist in the certificate table (No in S3203), notifies the external device 3002 of this fact, and ends the processing as an error.
[0243] The server 2600, in a case where the combination of the device ID and the vehicle ID received exists in the certificate table (Yes in S3203), issues a 3rd certificate corresponding to the obtained combination, and transmits it to the external device 3002 (S3204).
[0244] The external device 3002 stores the 3rd certificate issued by the server 2600 (S3205). For example, the authentication information holding section 1403 in the communication ECU 3400 of the external device 3002 stores the 3rd certificate, whereby the 3rd certificate is also valid on the external device 3002 side.
[0245] Further, although not illustrated, the server 2600 shows information on the automatic driving level of the automatic driving system 3000 as a whole when the vehicle 3001 and the external device 3002 are combined, corresponding to the valid 3rd certificate. In addition, it is also possible to output, by the external device 3002 (for example, the communication section 3401), information on the automatic driving level of the automatic driving system 3000 as a whole when the vehicle 3001 and the external device 3002 are combined, corresponding to the valid 3rd certificate.
[0246] [3.5 Example of sequence for invalidating certificate]
[0247] Next, invalidation of the 3rd certificate corresponding to the automatic driving level, which is held by the external device 3002 and the server 2600, will be described with reference to Figure 26
[0248] Figure 26 is a sequence diagram showing an example of the action of invalidating the public key certificate (the 3rd certificate) in Embodiment 3.
[0249] The external device 3002 monitors the communication state of the vehicle 3001 (S3301).
[0250] The external device 3002 determines whether or not the communication state of the vehicle 3001 has become abnormal (S3302). The external device 3002 ends the processing in the case where no communication abnormality has occurred (NO in S3302).
[0251] The external device 3002 increments the error counter in the case where a communication abnormality has occurred (YES in S3302) (S3303).
[0252] The external device 3002 determines whether or not the error counter is equal to or greater than the threshold value (S3304). The external device 3002 notifies the server 2600 of the issued public key certificate (the 3rd certificate) in the case where the error counter is equal to or greater than the threshold value (YES in S3304), thereby performing invalidation instruction to invalidate the 3rd certificate in the server 2600. The external device 3002 returns to S3302 in the case where the error counter does not exceed the threshold value (NO in S3304).
[0253] The external device 3002 and the server 2600 invalidate the 3rd certificate each of which is held in the case where the error counter is equal to or greater than the threshold value (YES in S3304) (S3305). For example, the certificate management section 3404 in the communication ECU 3400 of the external device 3002 invalidates the 3rd certificate by deleting the 3rd certificate held in the authentication information holding section 1403.
[0254] The external device 3002 resets the error counter (S3306).
[0255] The external device 3002 deletes the vehicle ID as a connection object (S3307).
[0256] As described above, in Embodiment 3, the external device 3002 includes the server 2600, and the 3rd certificate is transmitted from the server 2600 to the external device 3002 at the time of device authentication.
[0257] [3.6 Effects of Embodiment 3]
[0258] In the autonomous driving system 3000 shown in Embodiment 3, a different third certificate is issued by the server 2600 from the first certificate of the vehicle 3001 and the second certificate of the external device 3002, and the issued third certificate is managed in the external device 3002. Also, the validity of the third certificate is switched according to the communication result of the vehicle 3001 and the external device 3002, so that the appropriate autonomous driving level when the vehicle 3001 and the external device 3002 become integrated to act can be determined, and the safety can be ensured.
[0259] (Embodiment 3 Modification)
[0260] In the autonomous driving system 3000 shown in Embodiment 3, the validity or invalidity of the third certificate can be performed at any time, but the timing of the validity or invalidity can also be controlled according to the running state of the vehicle 3001. This is described as a modification of Embodiment 3. In addition, the same parts as Embodiment 3 are omitted from the description.
[0261] [3.7 Example of Sequence at the Time of Certificate Issuance]
[0262] Figure 27 is a sequence diagram showing an example of the action of issuing a public key certificate (third certificate) in the modification of Embodiment 3. In the modification of Embodiment 3, the third certificate is issued when the running state of the vehicle 3001 satisfies a specific condition. In addition, the same steps as Embodiment 3 are given the same numbers, and the description is omitted.
[0263] For example, the running state of the vehicle 3001 that satisfies the specific condition is a state of stopping, and the external device 3002 determines whether the running state of the vehicle 3001 is in stopping before starting the process of making the third certificate valid (S3206). The external device 3002 does not start the process for making the third certificate valid when the vehicle 3001 is not in stopping (No in S3206), and ends the process. The external device 3002 starts the process of making the third certificate valid when the vehicle 3001 is in stopping (Yes in S3206).
[0264] [3.8 Example of Sequence for Invalidating the Certificate]
[0265] Figure 28 is a sequence diagram showing an example of the action of invalidating a public key certificate (third certificate) in the modification of Embodiment 3. In the modification of Embodiment 3, the state (for example, the communication state) of the vehicle 3001 and the external device 3002 is monitored when the running state of the vehicle 3001 satisfies a specific condition, and the third certificate is invalidated according to the communication state. In addition, the same steps as Embodiment 3 are given the same numbers, and the description is omitted.
[0266] The external device 3002 determines whether the running state of the vehicle 3001 is a state of stopping (S3308). The external device 3002 interrupts the invalidation process of the 3rd certificate and ends when the vehicle 3001 is not in stopping (NO in S3308), and monitors the communication state (S3301) and continues the invalidation process when the vehicle 3001 is in stopping (YES in S3308).
[0267] [3.9 Effects of Modification Example of Embodiment 3]
[0268] In the automatic driving system 3000 illustrated in Embodiment 3, the 3rd certificate different from the 1st certificate of the vehicle 3001 and the 2nd certificate of the external device 3002 is issued by the server 2600, and the issued 3rd certificate is managed in the external device 3002. Further, the validity and invalidity of the 3rd certificate is switched according to the running state of the vehicle 3001 in addition to the communication result between the vehicle 3001 and the external device 3002, and thus it is possible to determine the appropriate automatic driving level when the vehicle 3001 and the external device 3002 are integrated and operate, and it is possible to ensure safety.
[0269] (Other Modification Examples)
[0270] In addition, the present disclosure has been described in accordance with each of the embodiments, but the present disclosure is not limited to each of the embodiments. The present disclosure also includes the following cases.
[0271] (1) In the embodiments, Ethernet, CAN protocol is used as the in-vehicle network, but is not limited thereto. For example, CAN-FD (CAN with Flexible Data Rate), LIN (Local Interconnect Network), or MOST (registered trademark) (Media Oriented Systems Transport), or the like can be used as the in-vehicle network. Alternatively, the in-vehicle network can be a network configuration in which these networks are combined as subnets.
[0272] (2) In any of the forms of the embodiments, an example in which the 3rd certificate that is newly valid is managed by either the vehicle side or the external device side, but is not limited to this example. It is also possible that both the vehicle side and the external device side have the 3rd certificate, and it is also possible to separate the types of certificates that the vehicle side or the external device side has according to the use.
[0273] (3) In the embodiment, an example is described in which the communication ECU that communicates between the vehicle and the external device includes a certificate management unit that performs authentication processing and management of certificates, but the configuration is not limited to this. The certificate management unit can be included in a dedicated ECU for certificate management, or can be included in the automatic driving ECU or another ECU. Furthermore, in Embodiments 2 and 3, the certificate management unit can be included in the V2X communication ECU.
[0274] (4) In the embodiment, the communication ECU determines the abnormality, but this is not limited to this. The communication content can be mirrored to another ECU, and the other ECU can determine the abnormality. In addition, the other ECU can be physically separate from the communication ECU, or can be logically separate. For example, a virtual environment can be constructed on a multifunctional ECU called a central gateway, a regional ECU, or a domain controller, and an application can be installed on one virtual operating system (hereinafter, OS) to detect the communication state. In addition, the same virtual environment can be constructed on the communication ECU, and the communication state can be monitored by another OS different from the OS that performs communication.
[0275] (5) In the embodiment, as the state of the vehicle and the external device, the communication state between the vehicle and the external device is described as an example, but this is not limited to this. For example, in Embodiment 3, in the case where the external device itself has a failure, the failure can be detected by itself and notified to the vehicle or the server.
[0276] (6) In Embodiments 2 and 3, the server functions as a certification authority that issues a new public key certificate (the third certificate), but this is not limited to this. For example, the server can obtain and store a certificate issued in advance by another certification authority, and transmit it to the vehicle or the external device at a predetermined timing.
[0277] (7) In the embodiment, the combination of the vehicle and the external device is determined using the certificate table, and the automatic driving level is determined, but the automatic driving level of the entire automatic driving system after combination can be embedded in the certificate in advance. In other words, information similar to the certificate table is already embedded in the certificate, so it is not necessary to refer to the certificate table to determine the automatic driving level of the entire automatic driving system.
[0278] (8) In the modification example of the embodiment, the running state of the vehicle is determined, but this can be determined by a specific ECU, the running state can be obtained by another ECU via the in-vehicle network, or the running state can be determined by each ECU independently. In addition, in addition to the running states of running, stopping, or parking, the states of the accessory being on, the ignition being on, low-speed running, or high-speed running can be determined.
[0279] (9) In the modification of the embodiment, an example in which the third certificate is made valid only in parking is shown, but the present application is not limited to this. For example, the third certificate can be made valid only in parking or in a specific driving state other than parking, such as driving. Further, the third certificate can be made valid at the timing at which the driving state changes, from driving to parking, from parking to driving, and the like.
[0280] (10) In the modification of the embodiment, an example in which the third certificate is made invalid only in parking is shown, but the present application is not limited to this. For example, the third certificate can be made invalid only in parking or in a specific driving state other than parking, such as driving. Further, the third certificate can be made invalid at the timing at which the driving state changes, from parking to driving, from low-speed driving to high-speed driving, and the like.
[0281] (11) In the modification of the embodiment, the third certificate is made invalid, that is, the automatic driving level is changed, according to the communication result, but the driver can be notified of this at the timing of the change. The ECU having a display device, such as an infotainment system or a speedometer, notifies the driver of the change at the timing of the change by outputting a pop-up display or an icon, or by eliminating or changing these, and the like.
[0282] (12) Each of the devices and systems in the above embodiments can be a computer system including a microprocessor, a ROM, a RAM, a hard disk device, a display unit, a keyboard, a mouse, and the like. A computer program is recorded in the RAM or the hard disk device. The microprocessor operates according to the computer program, and each of the devices and systems achieves the function. Here, the computer program is composed of a plurality of command codes that show instructions to the computer in order to achieve a predetermined function.
[0283] (13) A part of the components that constitute each of the devices and systems described above can be constituted by one system LSI (Large Scale Integration). The system LSI is a super multifunctional LSI in which a plurality of components are integrated on one chip, and specifically, is a computer system including a microprocessor, a ROM, a RAM, and the like. The RAM records a computer program. The microprocessor operates according to the computer program, and the system LSI achieves the function.
[0284] Further, each of the components that constitute each of the devices and systems described above can be monolithic, or monolithic including a part or all of the components.
[0285] Further, the system LSI is also called as an IC, an LSI, a super LSI, a ultra LSI depending on the degree of integration. Further, the method of the integration is not limited to the LSI and a dedicated circuit or a general purpose processor can be used. Further, a FPGA (Field Programmable Gate Array) that can be programmed after the manufacture of the LSI or a reconfigurable processor in which the connections and the settings of circuit cells included in the LSI can be reconfigured can be used.
[0286] Further, with the advancement of semiconductor technology or other technology, when an integrated circuit technology that can replace the LSI appears, the technology can be used for the integration of the functional blocks, of course. It is possible to apply biotechnology or the like.
[0287] (14) A part or all of the components that constitute each of the devices described above can be constituted by an IC card or a single module that can be attached to and detached from each of the devices. The IC card or the module is a computer system constituted by a microprocessor, a ROM, a RAM, and the like. The IC card or the module can include the super multifunctional LSI. The microprocessor operates in accordance with a computer program, and thus the IC card or the module achieves the function. The IC card or the module can have tamper resistance.
[0288] (15) The present disclosure can be an authentication method.
[0289] For example, the authentication method is a method in an automatic driving system that includes a vehicle and an external device that communicates with the vehicle and provides a function for the vehicle to automatically travel. The vehicle holds a first certificate for proving the legitimacy of the vehicle, and the external device holds a second certificate for proving the legitimacy of the external device. In the authentication method, the computer performs processes (for example, S1201 to S1203 of FIG. 12) including the following, and makes a third certificate for proving the legitimacy of the combination of the vehicle and the external device valid in accordance with the result of the device authentication of the vehicle and the external device using the first certificate and the second certificate. Figure 9
[0290] Further, the authentication method in the present disclosure can be a computer program implemented by a computer or a digital signal constituted by a computer program.
[0291] Further, the present disclosure can be a non-transitory recording medium that can be read by a computer, such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, and the like, in which the computer program or the digital signal is recorded. Further, the present disclosure can also be a digital signal recorded in such a recording medium.
[0292] Moreover, the present disclosure can be a computer program or digital signal that is transmitted via an electric communication line, a wireless or wired communication line, a network represented by the Internet, or a data broadcast, and the like.
[0293] Moreover, the present disclosure can be a computer system equipped with a microprocessor and a memory that stores the computer program, the microprocessor acting in accordance with the computer program.
[0294] Moreover, the program or digital signal can be implemented by an independent other computer system by being recorded in a recording medium and being transferred, or by being transferred via a network or the like.
[0295] (16) The embodiments and the modified examples can be combined respectively.
[0296] The present disclosure is applicable to an automated driving system including a vehicle and an external device that communicates with the vehicle and provides a function for the vehicle to automatically travel.
[0297] Legend
[0298] 1000, 2000, 3000 automated driving system
[0299] 1001, 2001, 3001 vehicle
[0300] 1002, 3002 external device
[0301] 1010 camera
[0302] 1011 brake
[0303] 1012 steering wheel
[0304] 1013 accelerator
[0305] 1014 Lidar
[0306] 1100a, 1100b, 1100c, 1100d, 1100e ECU
[0307] 1101, 1201, 1301, 1401, 2301, 2501, 2601, 3301, 3401 communication unit
[0308] 1102, 2502 message conversion unit
[0309] 1200 automated driving ECU
[0310] 1202 determination unit
[0311] 1203 automated driving level management unit
[0312] 1300, 1400, 2300, 3300, 3400 communication ECU
[0313] 1302, 1402, 2602, 3302, 3402 authentication processing section
[0314] 1303, 1403, 2603 authentication information holding section
[0315] 1304, 2304, 2604, 3404 certificate management section
[0316] 1305, 2605 certificate holding section
[0317] 2500 V2X communication ECU
[0318] 2600 server
Claims
1. An authentication method, which is an authentication method in an automated driving system including a vehicle and an external device mounted to the vehicle, the external device communicating with the vehicle and providing a function for the vehicle to perform automated driving, in the authentication method, the vehicle holds a first certificate for proving legitimacy of the vehicle, the external device holds a second certificate for proving legitimacy of the external device, in the authentication method, based on a result of device authentication of the vehicle and the external device using the first certificate and the second certificate, a third certificate for proving legitimacy of a combination of the vehicle and the external device is made valid, each of the third certificates corresponding to an automated driving level of the automated driving system as a whole for each combination of the vehicle and the external device, in the authentication method, information on the automated driving level of the automated driving system as a whole when the vehicle and the external device are combined, corresponding to the third certificate made valid, is further output, the vehicle is constituted by a plurality of ECUs connected through an in-vehicle network, the authentication method is implemented by one of the plurality of ECUs.
2. The authentication method according to claim 1, at least two of the plurality of ECUs are taken as one multifunctional ECU, and a virtual environment is constructed on the one multifunctional ECU, the authentication method is implemented on the virtual environment.
3. The authentication method according to claim 1, in the making valid of the third certificate, the third certificate corresponding to at least one of a vehicle ID of the vehicle and a device ID of the external device is made valid, the at least one of the vehicle ID of the vehicle and the device ID of the external device being obtained as a result of the device authentication.
4. The authentication method according to claim 1, the third certificate is issued at the time of manufacturing the vehicle and is held in the vehicle in advance.
5. The authentication method according to claim 1, the automated driving system further includes a server, in the device authentication, the third certificate is transmitted from the server to the vehicle or the external device.
6. The authentication method according to claim 1, in the making valid of the third certificate, the third certificate is made valid in a case where a running state of the vehicle satisfies a specific condition.
7. The authentication method according to claim 6, the running state of the vehicle satisfying the specific condition is a state of parking.
8. The authentication method according to claim 1, further, a state of the vehicle and the external device is monitored, the third certificate is made invalid in accordance with a change in the state.
9. The authentication method according to claim 8, the state is a communication state between the vehicle and the external device, in the invalidation of the third certificate, the third certificate is made invalid in a case where the communication state becomes abnormal.
10. The authentication method according to claim 8, In the invalidation of the third certificate, the driver of the vehicle is notified that the third certificate is invalidated.
11. The authentication method according to claim 8 or 9, wherein In the monitoring of the state, the state is monitored in a case where a traveling state of the vehicle satisfies a specific condition.
12. The authentication method according to claim 11, wherein The traveling state of the vehicle that satisfies the specific condition is a state of parking.
13. An authentication method is an authentication method in an automated driving system including a vehicle and an external device mounted on the vehicle, the external device communicating with the vehicle and providing a function for the vehicle to travel automatically, In the authentication method, the vehicle holds a first certificate for proving legitimacy of the vehicle, the external device holds a second certificate for proving legitimacy of the external device, In the authentication method, a third certificate proving legitimacy of a combination of the vehicle and the external device is made valid in accordance with a result of device authentication of the vehicle and the external device using the first certificate and the second certificate, each of the third certificates corresponding to an automated driving level of the automated driving system as a whole for each combination of the vehicle and the external device, In the authentication method, information on the automated driving level of the automated driving system as a whole when the vehicle and the external device are combined, corresponding to the third certificate made valid, is further output, the external device is constituted by a plurality of ECUs connected through an in-vehicle network, the authentication method is implemented by one of the plurality of ECUs.
14. The authentication method according to claim 13, at least two of the plurality of ECUs are taken as one multifunctional ECU, and a virtual environment is constructed on the one multifunctional ECU, the authentication method is implemented on the virtual environment.
15. The authentication method according to claim 13, further, a state of the vehicle and the external device is monitored, the third certificate is invalidated in accordance with a change in the state.
16. The authentication method according to claim 15, In the invalidation of the third certificate, the driver of the vehicle is notified that the third certificate is invalidated.
17. An authentication system is an authentication system in an automated driving system including a vehicle and an external device mounted on the vehicle, the external device communicating with the vehicle and providing a function for the vehicle to travel automatically, In the authentication system, the vehicle holds a first certificate for proving legitimacy of the vehicle, the external device holds a second certificate for proving legitimacy of the external device, the authentication system is provided with: a certificate management unit that, based on a result of the device authentication of the vehicle and the external device using the first certificate and the second certificate, makes valid a third certificate that certifies the legitimacy of the combination of the vehicle and the external device, each of the third certificates corresponding to an autonomous driving level of the entire autonomous driving system for each combination of the vehicle and the external device; and a communication unit that outputs information about the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, which corresponds to the third certificate that is valid, the authentication system further, monitors a state of the vehicle and the external device, invalidates the third certificate in accordance with a change in the state.
18. The authentication system according to claim 17, in the invalidation of the third certificate, notifies a driver of the vehicle that the third certificate is invalidated.
19. The authentication system according to claim 17, the state is a state of the external device, in the invalidation of the third certificate, invalidates the third certificate in a case where a failure occurs in the external device.
20. An authentication device that is provided in a vehicle in an autonomous driving system that includes the vehicle and an external device mounted to the vehicle, the external device communicating with the vehicle and providing a function for the vehicle to autonomously travel, the authentication device includes: a holding unit that holds a first certificate that certifies the legitimacy of the vehicle; an authentication unit that authenticates the external device using a second certificate that certifies the legitimacy of the external device; a certificate management unit that, based on a result of the authentication, makes valid a third certificate that certifies the legitimacy of the combination of the vehicle and the external device, each of the third certificates corresponding to an autonomous driving level of the entire autonomous driving system for each combination of the vehicle and the external device; and a communication unit that outputs information about the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, which corresponds to the third certificate that is valid, the authentication device further, monitors a state of the vehicle and the external device, invalidates the third certificate in accordance with a change in the state.
21. The authentication device according to claim 20, in the invalidation of the third certificate, notifies a driver of the vehicle that the third certificate is invalidated.
22. The authentication device according to claim 20, the state is a state of the external device, in the invalidation of the third certificate, invalidates the third certificate in a case where a failure occurs in the external device.
23. An authentication device that is provided in an external device in an autonomous driving system that includes a vehicle and the external device mounted to the vehicle, the external device communicating with the vehicle and providing a function for the vehicle to autonomously travel, the authentication device includes: a holding unit that holds a second certificate that certifies the legitimacy of the external device; and an authentication unit that authenticates the vehicle using a first certificate that certifies the legitimacy of the vehicle. an authentication unit that authenticates the vehicle using a first certificate for proving legitimacy of the vehicle; a certificate management unit that, using a result of the authentication, makes a third certificate for proving legitimacy of a combination of the vehicle and the external device valid, each of the third certificates corresponding to an autonomous driving level of the automatic driving system as a whole for each combination of the vehicle and the external device; and a communication unit that outputs information about the autonomous driving level of the automatic driving system as a whole when the vehicle and the external device are combined, which corresponds to the third certificate that is made valid, the authentication device further, monitors states of the vehicle and the external device, and makes the third certificate invalid in accordance with a change in the states.
24. The authentication device according to claim 23, in the invalidation of the third certificate, informs a driver of the vehicle that the third certificate is invalidated.
25. The authentication device according to claim 23, the states are states of the external device, in the invalidation of the third certificate, makes the third certificate invalid in a case where a failure occurs in the external device.
26. An authentication method that is an authentication method in an automatic driving system including a vehicle and an external device mounted on the vehicle, the external device communicating with the vehicle and providing a function for the vehicle to automatically travel, in the authentication method, the vehicle holds a first certificate for proving legitimacy of the vehicle, the external device holds a second certificate for proving legitimacy of the external device, in the authentication method, in accordance with a result of device authentication of the vehicle and the external device using the first certificate and the second certificate, makes a third certificate for proving legitimacy of a combination of the vehicle and the external device valid, each of the third certificates corresponding to an autonomous driving level of the automatic driving system as a whole for each combination of the vehicle and the external device, in the authentication method, further outputs information about the autonomous driving level of the automatic driving system as a whole when the vehicle and the external device are combined, which corresponds to the third certificate that is made valid, in the authentication method, further, monitors states of the vehicle and the external device, and makes the third certificate invalid in accordance with a change in the states, the states are states of the external device, in the invalidation of the third certificate, makes the third certificate invalid in a case where a failure occurs in the external device.