Information processing method, information processing device, and program

By detecting and updating the software information list in the vehicle and switching the function operation according to the user contract, the problem of improper software management in the vehicle is solved, and the real-time consistency and security of the software information list with actual use are achieved.

CN121175656APending Publication Date: 2025-12-19PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202480034196.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-05-30
Filing Date
2024-02-08
Publication Date
2025-12-19

AI Technical Summary

Technical Problem

In the existing technology, the software management in vehicles is inadequate and cannot update information in real time to conform to the user contract. This leads to inconsistencies between the hardware and software information of the functions, affecting the software information processing that the existing technology cannot effectively solve, and resulting in improper software management.

Method used

By using information processing methods performed by computers in vehicles, new annotations to the software are detected and the software information list is updated. Based on the operation of the user contract switching function, the SBOM management department detects the addition of hardware and software, and updates the software information list. This includes detection, judgment, acquisition and updating steps to ensure that the software information list is consistent with actual use.

Benefits of technology

This enables proper management of software within vehicles, ensuring that the software information list is consistent with actual usage, and allows for dynamic updates to adapt to changes in user contracts, thereby improving the appropriateness and security of software management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121175656A_ABST
    Figure CN121175656A_ABST
Patent Text Reader

Abstract

An information processing method is an information processing method executed using a computer in a vehicle (100) that switches whether or not to enable operation of each function equipped with the vehicle according to the presence or absence of a contract of a user of the vehicle, the information processing method comprising: a detection step (S11) of detecting whether or not a contract is present by the user of the vehicle; detecting a new addition of software for operating the one or more functions; a determination step (S14) for determining whether or not there is a contract of the user with respect to a function operated by the newly added software detected; an acquisition step for acquiring software information corresponding to the software determined to have the contract of the user; and an updating step (step S15, step S16, and step S17) for updating a software information list of functions that can be operated in the vehicle by adding the acquired software information.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to an information processing method, an information processing apparatus, and a program. BACKGROUND

[0002] In Patent Literature 1, a technology is described in which, when a software called a container is transmitted to a device, a change prohibition area provided within the software is used to ensure that the change prohibition area is not changed, thereby appropriately providing information (hereinafter, also simply referred to as vulnerability information) related to vulnerability of the software included in the change prohibition area. With detection of vulnerability of software by using vulnerability information appropriately transmitted as described in Patent Literature 1 as a starting point, technologies related to information processing for appropriately managing software imported to a device are sought.

[0003] PRIOR ART DOCUMENTS

[0004] PATENT LITERATURE

[0005] Patent Literature 1: International Publication No. 2021 / 260753 SUMMARY

[0006] PROBLEMS TO BE SOLVED BY THE INVENTION

[0007] The present disclosure more appropriately provides an information processing method and the like for appropriately managing software.

[0008] TECHNICAL SOLUTION FOR SOLVING THE PROBLEMS

[0009] A technical solution of the present disclosure relates to an information processing method executed by a computer in a vehicle that switches whether to enable operation for each function equipped according to presence or absence of a contract of a user of the vehicle, the information processing method including: a detection step of detecting new addition of software for enabling operation of one or more functions; a determination step of determining, for a function operated by the software for which new addition is detected, whether there is the contract of the user; a acquisition step of acquiring software information corresponding to the software determined to have the contract of the user; and an update step of updating a list of software information of functions that can be operated in the vehicle by adding the acquired software information.

[0010] Another aspect of the present disclosure relates to an information processing device mounted on a vehicle that switches whether to enable operation for each function equipped in the vehicle according to the presence or absence of a contract of a user of the vehicle, the information processing device including a detection unit that detects a new addition of software for enabling operation of one or more functions, a determination unit that determines, for the function operated by the software for which the new addition is detected, whether the contract of the user is present, an acquisition unit that acquires software information corresponding to the software for which the contract of the user is determined to be present, a storage unit that stores a list of software information of functions that can be operated in the vehicle, and an update unit that updates the stored list of software information by adding the acquired software information.

[0011] A program according to an aspect of the present disclosure is a program for causing a computer to execute the information processing method described above.

[0012] Furthermore, these general or specific aspects can be implemented by a device, an integrated circuit, a computer program, or a non-transitory recording medium such as a CD-ROM that is readable by a computer, and can also be implemented by any combination of a device, an integrated circuit, a computer program, and a non-transitory recording medium.

[0013] Effects of the Invention

[0014] According to the information processing method and the like in the present disclosure, software can be managed more appropriately. BRIEF DESCRIPTION OF DRAWINGS

[0015] Figure 1 is a block diagram illustrating an example of a functional configuration of an information processing system according to an embodiment.

[0016] Figure 2 is a flowchart illustrating an example of operation in hardware addition of an information processing system according to an embodiment.

[0017] Figure 3 is a diagram illustrating an example of an SBOM and an available SBOM of an information processing system according to an embodiment.

[0018] Figure 4 is a diagram illustrating an example of software information of software for enabling operation of added hardware of an information processing system according to an embodiment.

[0019] Figure 5 is a diagram illustrating an example of SFOP information of an information processing system according to an embodiment.

[0020] Figure 6 is a diagram illustrating changes in an SBOM, an available SBOM, and S / W information of an information processing system according to an embodiment.

[0021] Figure 7 FIG. 1 is a diagram showing a change in an SBOM, an available SBOM, and S / W information of an information processing system to which the embodiment relates.

[0022] Figure 8 FIG. 1 is a diagram showing a change in an SBOM, an available SBOM, and S / W information of an information processing system to which the embodiment relates.

[0023] Figure 9 FIG. 1 is a diagram showing a change in an SBOM, an available SBOM, and S / W information of an information processing system to which the embodiment relates.

[0024] Figure 10 FIG. 1 is a diagram showing a change in an SBOM, an available SBOM, and S / W information of an information processing system to which the embodiment relates. DETAILED DESCRIPTION

[0025] (SUMMARY OF THE DISCLOSURE)

[0026] The summary of the disclosure is as follows.

[0027] The first technical solution of the disclosure relates to an information processing method performed by a computer in a vehicle that switches whether to enable operation for each function equipped according to the presence or absence of a contract of a user of the vehicle, the information processing method including: a detection step of detecting a new addition of software for enabling operation of one or more functions; a determination step of determining, for a function operated by the software for which the new addition is detected, whether there is a contract of the user; a retrieval step of retrieving software information corresponding to the software determined to have the contract of the user; and an update step of updating a list of software information of functions that can be operated in the vehicle by adding the retrieved software information.

[0028] According to such an information processing method, in the vehicle, it is possible to manage, as software information, software for enabling operation of hardware (hardware that executes a function that can be operated) that is in a usable state by actually having a contract, by a list of software information. Therefore, software information that is not included in the list of software information in the disclosure, such as "software that is used although not included in the list of software information because of the addition of software" and "software that is not used although included in the list of software information because the hardware is equipped although no contract is made", is not included, so more appropriate software management can be performed.

[0029] Further, the information processing method according to a second aspect of the present disclosure further includes, in the information processing method according to the first aspect, in the acquisition step, acquiring software information corresponding to software determined not to have the contract with the user, and in the update step, updating the list of software information of the functions executable in the vehicle by adding the software information corresponding to the software determined to have the contract with the user among the acquired software information, and updating the list of installed software information of the functions installed in the vehicle by adding all the acquired software information.

[0030] Thus, the management of the software can be performed using the list of software information of the functions executable in the vehicle, which is different from the list of software information.

[0031] Further, the information processing method according to a third aspect of the present disclosure further includes, in the information processing method according to the first or second aspect, in the detection step, detecting the new addition of the software according to the introduction of hardware that executes a function corresponding to the software as the hardware operated by the software.

[0032] Thus, the addition of the hardware can be considered as a trigger condition for the update of the list of software information as the addition of the software.

[0033] Further, the information processing method according to a fourth aspect of the present disclosure further includes, in the information processing method according to any one of the first to third aspects, a switching detection step of further detecting switching of one or more of the software executable to the software not executable, and a deletion update step of updating the list of software information by deleting software information corresponding to the software detected to be switched from the list of software information.

[0034] Thus, by detecting the switching of the software to the software not executable, and deleting the software information of the software not executable from the list of software information, the list of software information can be maintained in a state corresponding to the software actually available.

[0035] Further, the information processing method according to a fifth aspect of the present disclosure further includes, in the information processing method according to the fourth aspect, in the switching detection step, detecting the switching of one or more of the software to the software not executable according to a change from a state having a contract with the user for a function operated by the software to a state not having the contract.

[0036] Thus, the switching of the software to the software not executable can be detected according to the change from the state having the contract with the user to the state not having the contract.

[0037] Further, the information processing method according to a seventh aspect of the present disclosure is the information processing method according to the sixth aspect, wherein in the deletion update step, in a case where the information related to the type of the function executed by the software detected to be switched satisfies the first condition, deletion of the software information corresponding to the software detected to be switched from the software information list is prohibited.

[0038] Thus, it is possible to perform management of the software using the information related to the type of the function executed by the software.

[0039] Further, the information processing method according to a seventh aspect of the present disclosure is the information processing method according to the sixth aspect, wherein in the deletion update step, in a case where the information related to the type of the function executed by the software detected to be switched satisfies the first condition, deletion of the software information corresponding to the software detected to be switched from the software information list is prohibited.

[0040] Thus, it is possible to perform management of the software using the information related to the type of the function executed by the software.

[0041] Further, the information processing method according to a seventh aspect of the present disclosure is the information processing method according to the sixth aspect, wherein in the deletion update step, in a case where the information related to the type of the function executed by the software detected to be switched satisfies the first condition, deletion of the software information corresponding to the software detected to be switched from the software information list is prohibited.

[0042] Thus, it is possible to perform management of the software using the information related to the type of the function executed by the software.

[0043] Further, the information processing method according to a ninth aspect of the present disclosure is the information processing method according to any one of the first to eighth aspects, further comprising a vulnerability management step of managing a vulnerability of the software for executing the function executable in the vehicle using the updated software information list.

[0044] Thus, it is possible to perform management of the software using the information related to the type of the function executed by the software.

[0045] Further, the information processing method according to a tenth aspect of the present disclosure is the information processing method according to the ninth aspect, wherein the vulnerability management step is executed at a predetermined interval.

[0046] Thus, the software information list can be updated, and the management of the vulnerability of the software for causing the function executable in the vehicle to operate can be performed every predetermined period (i.e., periodically).

[0047] In addition, the information processing device according to the 11th aspect of the present disclosure is an information processing device mounted on a vehicle that switches whether to enable each function equipped in the vehicle to operate depending on the presence or absence of a contract of a user of the vehicle, and includes a detection unit that detects a new addition of software for causing one or more functions to operate, a determination unit that determines whether the function operated by the software of which the new addition is detected has a contract of a user, a retrieval unit that retrieves software information corresponding to the software determined to have the contract of the user, a storage unit that stores a list of software information of functions executable in the vehicle, and an update unit that updates the stored list of software information by adding the retrieved software information.

[0048] Thus, the same effects as those of the above-described information processing method are achieved.

[0049] In addition, the program according to the 12th aspect of the present disclosure is a program for causing a computer to execute the information processing method according to any one of the 1st to 10th aspects.

[0050] Thus, the same effects as those of the above-described information processing method are achieved.

[0051] Further, these general and specific aspects can be implemented by devices, integrated circuits, computer programs, or non-transitory recording media such as CD-ROMs, and can also be implemented by any combination of the devices, integrated circuits, computer programs, and non-transitory recording media.

[0052] Hereinafter, the embodiments will be described in detail with appropriate reference to the accompanying drawings. However, sometimes, excessively detailed descriptions beyond necessity will be omitted. For example, sometimes, detailed descriptions of matters already known or repeated descriptions of substantially the same constitutions will be omitted. This is to avoid the following description from becoming excessively lengthy and to make it easier for those skilled in the art to understand.

[0053] Further, the drawings and the following description provided by the present inventors and the like are for the purpose of enabling those skilled in the art to sufficiently understand the present disclosure, and are not intended to limit the subject matter recited in the claims by these.

[0054] (Embodiments)

[0055] Figure 1 is a diagram for explaining an outline of the information processing system according to the embodiments. In Figure 1The vehicle 100, the server 200, and the wireless audio device 300 as an example of an additional hardware (hereinafter, sometimes referred to as H / W) that constitute the information processing system in the embodiment are illustrated in FIG. 1. Here, an example in which software (hereinafter, sometimes referred to as S / W) for running control for causing the wireless audio device 300 to run is added as one of the software of the vehicle 100 when the wireless audio device 300 is added by being connected to the vehicle 100 is explained.

[0056] The S / W added here is S / W for causing the wireless audio device 300 to run, which is one of the many H / W that can be connected to the vehicle 100. In other words, each S / W for causing each of the many H / W to run is introduced in the vehicle 100 including the S / W added here. Generally, such S / W is managed by the manufacturer of the vehicle 100 or the like by information of one or a plurality of S / W components included in each S / W, that is, a software bill of material (SBOM) or the like. In the case where a failure occurs in the vehicle 100, the SBOM can be used for the manufacturer to refer to correction of the S / W required by the SBOM or can be used for updating of a corresponding S / W component when a S / W component in which a vulnerability is newly found is included in the SBOM. As such, the SBOM is used for managing the S / W introduced to the vehicle 100.

[0057] On the other hand, conventionally, the SBOM can be uniformly managed by the server, and based on this, the SBOM is kept in the server or the like used by the manufacturer side without being kept in the vehicle 100. In view of this, the present inventors and the like found that, if the SBOM is kept in the vehicle, even in the case where connection to the server is not possible or in the case where there is a communication delay, the SBOM can be dynamically changed and used on the vehicle side, and thus such SBOM can be used for verification of vulnerability in a zero trust environment of the S / W introduced to the vehicle. The present application is completed based on such insight.

[0058] As Figure 1As shown, the vehicle 100 is provided with an SBOM management section 101, an authentication section 102, an execution control section 103, a vulnerability management section 104, a camera 105, a fingerprint authentication sensor 106, an SBOM 107, an available SBOM 108, function SFOP information 109, an autonomous driving system 110, an audio player 111, and the like. The configuration of the vehicle 100 is not limited to this example, and one or more of the above components can be omitted at times. Among the above components included in the vehicle 100, there are processing sections that are hypothetical functional configurations implemented by computer processing using an on-board computer, a memory, a program, and the like, and device sections that are functional configurations accompanied by physical devices and the like.

[0059] The SBOM management section 101 is a processing section that updates the SBOM 107 and the available SBOM 108 by adding new S / W information to the SBOM 107 and the available SBOM 108, deleting S / W information, and the like. The SBOM 107 is a list of S / W information corresponding to each of the S / W imported to the vehicle 100, and the available SBOM 108 is a list of S / W information that each user of the S / W imported to the vehicle 100 can use. The SBOM management section 101 detects the addition of new H / W to the vehicle 100, and thereby detects the addition of S / W for operating the H / W in conjunction with the addition of the H / W. Then, the SBOM 107 and the available SBOM 108 are updated by adding S / W information corresponding to the added S / W to them. In addition, the SBOM management section 101 updates the SBOM 107 and the available SBOM 108 individually by adding S / W information corresponding to all of the added S / W to the SBOM 107, and on the other hand, adding only a part of the S / W information corresponding to the added S / W to the available SBOM 108, depending on the situation. Furthermore, the SBOM management section 101 can detect the addition of S / W instead of the addition of H / W.

[0060] Specifically, the SBOM management unit 101 determines whether a function executed by the user of the vehicle 100 through the operation of each H / W mounted on the vehicle 100 is a function to which the user has contracted, and decides S / W information to be added to or deleted from the available SBOM 108, based on the determination result. That is, in the present embodiment, the vehicle 100 can switch whether to enable the operation of each function executed by the mounted H / W, depending on the presence or absence of the contract of the user of the vehicle 100. Further, the management of each function as to whether to enable the operation in the vehicle 100 depends on the presence or absence of the contract of the user of the function in the authentication information of the user of the server 200 and the contract information 201 of the user. In addition, among the functions mounted on the vehicle 100, there are functions for which the contract of the user is not present. The S / W information corresponding to the S / W for operating the H / W for executing such a function for which the contract of the user is not present (for example, a function for basic driving of the vehicle 100, and a basic function of the car audio device, and the like) is also included in the available SBOM 108. Thus, if the available SBOM 108 is referred to, the S / W information that the user can use at present can be acquired in real time, and even in the case where the user is changed or the contract is updated, the vulnerability management and the access control based on the latest information can be performed by using the S / W information.

[0061] The authentication unit 102 is a processing unit that acquires input information for user authentication by using the camera 105 and the fingerprint authentication sensor 106, and the like, and determines whether the user who is using the vehicle 100 is a registered user. In addition, the authentication unit 102 also performs processing of determining which of the registered users is using the vehicle 100 at the point in time, in the case where there are a plurality of such registered users.

[0062] The execution control unit 103 is a processing unit that controls the execution of S / W mounted on the vehicle. The execution control unit 103, for example, allows the execution of S / W corresponding to S / W information included in the available SBOM 108, and does not allow the execution of S / W corresponding to S / W information that is imported to the vehicle 100 but is not included in the available SBOM 108. Thus, part of the H / W is operated by S / W corresponding to S / W information included in the available SBOM 108. As described above, since only S / W information corresponding to a function for which the user has contracted or a function for which the contract of the user is not necessary is included in the available SBOM 108, the execution control unit 103 can cause only S / W corresponding to a function that can be substantially operated with respect to the user to operate.

[0063] The vulnerability management section 104 is a processing section that determines whether or not the S / W introduced into the vehicle 100 has a vulnerability, and performs a response to the vulnerability as necessary. In addition, the vulnerability management section 104, in the case where a response to a vulnerability is performed, since a modification of the S / W related to the response and the like is performed, sometimes instructs the SBOM management section 101 to perform an update of the S / W information of each of the SBOM 107 and the usable SBOM 108.

[0064] The camera 105 is a device section mounted on the vehicle 100 in a posture capable of photographing the face of the user. The camera 105 is used in the case of performing face authentication of the user and the like.

[0065] The fingerprint authentication sensor 106 is a device section mounted on a position capable of detecting the fingerprint of the user in the vehicle 100. The fingerprint authentication sensor 106 is used in the case of performing fingerprint authentication of the user and the like.

[0066] The camera 105 and the fingerprint authentication sensor 106 are not necessarily constituted, and instead of them, a microphone used in the case of performing voiceprint authentication of the user and the like can be provided, and a vein sensor used in the case of performing vein authentication of the user and the like can be provided.

[0067] The SBOM 107 is an example of an equipment software information list, and is information stored in a storage section and the like not shown. As long as the S / W information is listed in the SBOM 107, the format and the like thereof are not particularly limited.

[0068] The usable SBOM 108 is an example of a software information list, and is information stored in a storage section and the like not shown. Although as long as the S / W information is listed in the usable SBOM 108, the format and the like thereof are not particularly limited, since the S / W information of the SBOM 107 is sometimes referred to and taken into the usable SBOM 108, it is preferable to unify the format with that of the SBOM 107.

[0069] The function SFOP information 109 is information related to the type when each function mounted on the vehicle 100 is classified from the viewpoints of safety (S), financial (F), operational (O), and privacy (P), and is stored in a storage section or the like not shown. The function SFOP information 109 includes, for each function, four values of whether or not it corresponds to S of SFOP, whether or not it corresponds to F of SFOP, whether or not it corresponds to O of SFOP, and whether or not it corresponds to P of SFOP, but is not limited thereto. For example, the function SFOP information 109 can include only information of whether or not each function corresponds to S of SFOP. The function SFOP information 109 specifies a reference target from the S / W information included in the SBOM 107 or the available SBOM 108. That is, the decided information in the function SFOP information 109 is referred to for each S / W information, and the four values of SFOP for each function are provided.

[0070] The automatic driving system 110 is an example of a function requiring a contract of a user, and is a device section including various sensors, an automatic steering device, and a control device that processes a sensing result and controls the automatic steering device. The automatic driving system 110 is installed in the vehicle 100 by a manufacturer at the time of manufacturing the vehicle 100, for example.

[0071] The audio player 111 is an example of a function requiring a contract of a user, and is a device section including a sound source data input section, a speaker, and a driving device that drives the speaker based on sound source data input by the sound source data input section. The audio player 111 can be installed in the vehicle 100 by a manufacturer at the time of manufacturing the vehicle 100, or can be installed or replaced by a contractor or the like different from the manufacturer, or the like, according to a user.

[0072] The server 200 is a data server used by a manufacturer of the vehicle 100. The server 200 includes authentication information of a user and contract information 201 of the user, S / W information 202 of an additional H / W, a SBOM 203 of a vehicle, an available SBOM 204 of a vehicle, function SFOP information 205, and a vulnerability database 206.

[0073] Each of the components included in the server 200 is information stored in a storage section or the like not shown.

[0074] The user's authentication information and the user's contract information 201 is a database in which user input authentication information such as a camera image or a fingerprint is associated with the user's personal information, and the user's personal information is associated with information of functions with which the user has contracted. The authentication unit 102 refers to the user's authentication information and the user's contract information 201 with the input information as a search condition, and reads out the user's personal information and the information of functions with which the user has contracted.

[0075] The S / W information of the additional H / W 202 is a database of one or more S / W information of H / W that can be added per vehicle model or vehicle. For example, a manufacturer of the additional H / W that has contracted with the manufacturer of the vehicle 100 associates S / W information of S / W for operating the additional H / W with authentication information for attaching to the additional H / W, and delivers it to the manufacturer of the vehicle 100 in advance. The manufacturer of the vehicle 100 constructs the S / W information of the additional H / W 202 using the delivered authentication information and the S / W information of S / W for operating the additional H / W. Also, when the additional H / W is connected to the vehicle 100, for example, the authentication unit 102 refers to the S / W information of the additional H / W 202 with the authentication information of the additional H / W as a search condition, and reads out the S / W information of S / W for operating the additional H / W. Thus, it is possible to ensure the security that the additional H / W is H / W of the additional H / W manufacturer that has contracted with the vehicle manufacturer, and it is possible to obtain the S / W information of S / W for operating the additional H / W.

[0076] The vehicle's SBOM 203 is a database for synchronously holding one or more individual vehicle's SBOM 107. For example, the SBOM management unit 101 periodically copies and transmits the SBOM 107 to the server 200, thereby updating the vehicle's SBOM 203.

[0077] The vehicle's available SBOM 204 existing in the server 200 is synchronized with the available SBOM 108 in the vehicle 100. For example, the SBOM management unit 101 periodically copies and transmits the available SBOM 108 to the server 200, thereby updating the vehicle's available SBOM 204. The vehicle's SBOM 203 and the vehicle's available SBOM 204 are provided per vehicle 100.

[0078] The function SFOP information 205 existing in the server 200 is synchronized with the function SFOP information 109 in the vehicle 100. For example, the SBOM management section 101 updates the function SFOP information 109 by copying the function SFOP information 205 of the server 200 when the SBOM 107 and the available SBOM 108 are updated. Thus, if the function SFOP information 205 of the server 200 is updated, the function SFOP information 109 of the vehicle 100 is automatically kept up to date.

[0079] The vulnerability database 206 is a database constructed by collecting information related to vulnerabilities of S / W. The vulnerability database 206 periodically or at any time collects information related to vulnerabilities of S / W and updates.

[0080] The wireless audio device 300 is an example of an additional H / W, and here is H / W capable of inputting sound source data from a wireless transmitting device to the sound source data input section of the audio player 111 through close-range wireless communication.

[0081] The wireless audio device 300 includes a wireless communication module 301, an audio control section 302, H / W authentication information 303, and S / W 304 for operating the wireless audio device 300.

[0082] The wireless communication module 301 receives sound source data from a wireless transmitting device through close-range wireless communication. The wireless communication module 301 includes an antenna, an amplifier, a signal conversion circuit, and the like.

[0083] The audio control section 302 is a processing section that converts sound source data received by the wireless communication module 301 into a form capable of being input to the sound source data input section of the audio player 111 and inputs the same.

[0084] The H / W authentication information 303 is authentication information of the wireless audio device 300. When the wireless audio device 300 is connected, the authentication section 102 reads authentication information from the H / W authentication information 303 and inquires the server 200, thereby confirming that the wireless audio device 300 is a regular product sold from a manufacturer of additional H / W that has signed a contract with the manufacturer of the vehicle 100, and reads S / W information corresponding to the S / W 304 from the additional H / W S / W information 202.

[0085] The S / W 304 is S / W for operating the wireless audio device 300 on the vehicle 100 side.

[0086] Next, the operation of the information processing system configured as described above will be described. Figure 2 The operation of the information processing system configured as described above will be described. Figure 2 is a flowchart showing an example of the operation in the H / W addition of the information processing system to which the embodiment is applied. As shown inFigure 2 As shown, for example, in the case where the wireless audio device 300 is connected to the vehicle 100, the vehicle 100 detects the addition of the H / W by detecting the connection (detection step Sll).

[0087] The authentication section 102 reads the authentication information of the wireless audio device 300 and inquires the server, and performs authentication of the H / W (1st authentication step S12). At this time, the vehicle 100 reads and acquires the S / W information corresponding to the S / W 304 from the S / W information 202 of the added H / W (acquisition step). If the authentication of the H / W is successful (YES in the 1st authentication step S12), the authentication section 102 also performs authentication of the user by inquiring the server using the input information (2nd authentication step S13). If the user is proved to be a user who is in agreement with the use of the vehicle 100 through the user authentication, the authentication is successful (YES in the 2nd authentication step S13), and it is determined whether the user has contracted for a function executed by the operation of the wireless audio device 300 (determination step S14). For example, in the 2nd authentication step, the authentication section 102 reads the personal information of the user and information of functions for which the user has contracted in association with the personal information. Based on the information of functions for which the user has contracted, it is determined whether the user has contracted for a function executed by the operation of the wireless audio device 300.

[0088] In the case where it is determined that the user has contracted for a function executed by the operation of the wireless audio device 300 (YES in the determination step S14), the SBOM 107 and the available SBOM 108 are updated by importing the S / W 304 for operating the wireless audio device 300, adding the S / W information to the SBOM 107, and adding the S / W information to the available SBOM 108 (steps S15 and S16).

[0089] On the other hand, in the case where it is determined that the user has not contracted for a function executed by the operation of the wireless audio device 300 (NO in the determination step S14), the SBOM 107 is updated by importing the S / W 304 for operating the wireless audio device 300 and adding the S / W information to the SBOM 107 (step S17). At this time, although the S / W 304 is imported, the S / W information is not added to the available SBOM 108, and the available SBOM 108 is not updated. The steps S15, S16, and S17 are included in the update step.

[0090] Further, in the case where the authentication of the H / W is not successful (NO in the 1st authentication step S12), and in the case where the authentication of the user is not successful (NO in the 2nd authentication step S13), no subsequent processing is performed, and the processing ends.

[0091] By this operation, the S / W information corresponding to all the S / W introduced to the vehicle 100 is included in the SBOM 107, and the S / W information corresponding to the S / W that can be used by the user by signing a contract is included in the usable SBOM 108. Thus, in the vehicle 100, a list of the S / W actually used in the usable SBOM 108, by using such a usable SBOM 108, it is possible to cope with the vulnerability of the S / W, access control, and the like for the S / W actually used. For example, in a case where the SBOM including the S / W information of the S / W introduced by the manufacturer is kept only in the server operated by the manufacturer, there are cases where the S / W information does not match between the SBOM and the S / W actually used due to the addition of H / W by the user. In view of this, by dynamically keeping the S / W information of the S / W actually used in the vehicle 100 as the usable SBOM 108 as in the present embodiment, it is possible to cope with the vulnerability of the S / W, access control, and the like for the S / W based on the actual use at all times. That is, it is possible to cope with the attack on the S / W in the case of zero trust.

[0092] In addition, it is possible to perform a list of the S / W introduced to the vehicle 100 in the SBOM 107 that is updated independently of the usable SBOM 108. From the deletion or the like of the S / W information of the usable SBOM 108 (described later), even in a case where the vehicle 100 does not communicate with the server 200, it is possible to keep the information of the S / W introduced to the vehicle 100, so it is possible to delete the S / W information from the usable SBOM 108 even if the usable SBOM does not communicate with the server 200. Therefore, even in a case where the vehicle 100 does not communicate with the server 200, it is possible to switch to not use the S / W and switch the function executed by the S / W to a state where it cannot be executed. Therefore, by having the SBOM 107 in addition to the usable SBOM 108, it is possible to improve responsiveness.

[0093] Hereinafter, an example of the format of the specific SBOM 107 and the usable SBOM 108 will be described. Figure 3 is a diagram illustrating an example of the SBOM and the usable SBOM of the information processing system according to the embodiment. Figure 4 is a diagram illustrating an example of the software information of the software for causing the added hardware to operate of the information processing system according to the embodiment.

[0094] As Figure 3 and Figure 4As shown, SBOM107, available SBOM108, and S / W information in this example are recorded in SPDX format. As shown, all are SPDX-2.2 versions, with a data license of CC0-1.0. Here, as an example, "USB_AUDIO_1" is appended to SBOM107 and available SBOM108 of "IVI_1" as an example of adding H / W. "SPDXRef-DOCUMENT" is set in SPDXID, and "https: / / ...." is declared in the namespace.

[0095] like Figure 3 As shown, SBOM107 and the available SBOM108 contain "linux_kernel", "glibc", and S / W (not shown), containing multiple S / W information. Although detailed information about each S / W is omitted, the S / W information for each S / W includes, for example, "SPDXID", "PackageVersion", "PackageDownloadLocation", "PackageLicenseDeclared", "PackageLicenseComments", "FileName", "SPDXID", and "FileChecksum" (information used to verify consistency). For example, from the perspective of addressing vulnerabilities in S / Ws, the S / W version and license information are important, so sometimes it is sufficient to include this information in SBOM107 and the available SBOM108, or other information may not be included. Additionally, depending on how SBOM107 and the available SBOM108 are used, they may also consist of other information only, without including the version and license information of the S / W.

[0096] like Figure 4 As shown, the S / W information for the S / W used to run the additional H / W includes "libusb", "curl", and S / Ws not shown, and contains multiple S / W information. Although details of each S / W are omitted, the S / W information for the S / W used to run each additional H / W includes the same information as SBOM 107 and available SBOM 108. Additionally, the S / W information for the S / W used to run the additional H / W includes "OTHER SFOP_information", that is, information related to the SFOP in the function of the additional H / W as the value of "Relationship". Here, the reference target of the SFOP information of each function when referring to function SFOP information 109 is included as information.

[0097] Figure 5 is a diagram showing an example of SFOP information of an information processing system to which the embodiments are applied.

[0098] As shown in Figure 5 , the SFOP information is constituted of four values indicating whether it is True (true) or False (false) in terms of "Safety", True or False in terms of "Financial", True or False in terms of "Operational", and True or False in terms of "Privacy". In the example in the diagram, True in terms of "Safety" and "Operational" and False in terms of "Financial" and "Privacy" is shown.

[0099] Further, such SFOP information will be referred to in the deletion of S / W information from the available SBOM 108 to be described later.

[0100] Here, Figures 6-8 is a diagram showing changes in the SBOM, the available SBOM, and the S / W information of the information processing system to which the embodiments are applied. In Figures 6-8 , the SBOM 107 is shown in (a), the available SBOM 108 is shown in (b), and the S / W information of the S / W for running the added H / W is shown in (c). Further, Figure 6 shows a state before the H / W is added to the vehicle 100, Figure 7 shows a state after the H / W is added to the vehicle 100 and before the user subscribes to the function, Figure 8 shows a state after the H / W is added to the vehicle 100 and after the user subscribes to the function.

[0101] As shown in Figures 6-8 , in the case where the H / W is added before the subscription to the function, only the S / W information of the added H / W is added in the SBOM 107, and no S / W information of the added H / W is added in the available SBOM 108. In this state, in the case where the user subscribes to the function, the S / W information of the added H / W is also added to the available SBOM 108, and thus the function executed by the running of the H / W can be utilized. Here, in the case where the S / W information of the added H / W is added in the SBOM 107, the S / W information of the added H / W can be acquired from the server 200 or from the SBOM 107. That is, in the case where the S / W information of the added H / W is already added in the SBOM 107, the update of the available SBOM 108 in the vehicle 100 is completed after the subscription to the function.

[0102] Next, with reference to Figure 9 Other operations of the information processing system configured as described above will be described. Figure 9 is a flowchart showing an example of an operation in re-authentication of the information processing system according to the embodiment. In Figure 9 the flowchart, an example in which the user authentication is performed again after the addition of H / W is completed is shown. For example, in a case where the use of the vehicle 100 is once ended and the reuse is started again, or the use of the vehicle 100 exceeds a certain time, or the like, the operation as shown in Figure 2 is performed. Figure 9

[0103] As shown in Figure 9 , first, the authentication unit 102 performs re-authentication of the user (step S21). Here, if the authentication of the user is not successful (NO in step S21), the user who is not the user is using the vehicle 100, and thus it is necessary to update the available SBOM 108 in correspondence with the user who is currently using the vehicle 100. Here, an example in which the available SBOM 108 is added in the update is omitted from the description by referring to Figure 2 and the description thereof, and an example in which the available SBOM 108 and the S / W information are deleted in the update will be described.

[0104] If the authentication of the user is not successful (NO in step S21), the SBOM management unit 101 performs determination of a stop candidate function (step S22). The determination of the stop candidate function is an example of the switching detection step of detecting the switching of the S / W to the non-operation. The SBOM management unit 101 determines a function that should be switched to the non-operation as the stop candidate function, for example, on the basis of the available SBOM 108 of the original user, and the information of the function to which the user associated with the personal information of the current user has subscribed a contract.

[0105] Here, the SBOM management unit 101 determines whether the determined stop candidate function satisfies a predetermined first condition (step S23). The first condition is, for example, a condition that the function is a function that conforms to "Safety" in the SFOP information in which the stop candidate function is classified. Further, the first condition here is only an example, and can be appropriately set in accordance with the management of the S / W that is intended to be implemented using the SBOM 107 and the available SBOM 108.

[0106] ​The SBOM management unit 101 refers to the determined SFOP information of the stop candidate function, and if "Safety" is True, determines that the predetermined first condition is satisfied (YES in step S23), and acquires the state of the vehicle 100 (step S24). If "Safety" is True in the determined SFOP information of the stop candidate function, switching the stop candidate function to be inoperable can lead to a situation involving safety, and thus it is further determined whether to switch the stop candidate function to be inoperable depending on the state of the vehicle.

[0107] Therefore, the SBOM management unit 101 further determines whether the acquired state of the vehicle 100 satisfies a second condition (step S25). The second condition is a condition that the acquired state of the vehicle 100 is a state in which the stop of the stop candidate function is not recommended (for example, a state of traveling, a state of IG power being on, or the like). Furthermore, the second condition here is one example, and can be appropriately set depending on the management of S / W that is intended to be implemented using the SBOM 107 and the available SBOM 108.

[0108] The SBOM management unit 101 ends the processing in a case where it is determined that the predetermined second condition is satisfied depending on the acquired state of the vehicle 100 (YES in step S25). In this way, the SBOM management unit 101 prohibits switching the determined stop candidate function to be inoperable in a case where it is determined that the determined stop candidate function satisfies the predetermined first condition and satisfies the predetermined second condition.

[0109] On the other hand, the SBOM management unit 101 refers to the determined SFOP information of the stop candidate function, and if "Safety" is False, determines that the predetermined first condition is not satisfied (NO in step S23), and does not acquire the state of the vehicle 100 and directly proceeds to the deletion update step S26. Similarly, the SBOM management unit 101 proceeds to the deletion update step S26 in a case where it is determined that the predetermined second condition is not satisfied depending on the acquired state of the vehicle 100 (NO in step S25).

[0110] In the deletion update step S26, the S / W information of the S / W that makes the stop candidate function operate is deleted from the available SBOM 108 and is updated. Further, in a case where the authentication of the user is successful (YES in step S21), it is determined whether the contract of the function continues for the user (step S27). In a case where the contract of the function does not continue (NO in step S27), that is, if there is a change from a state having the contract of the user for the function to a state not having the contract, step S22 is executed to determine the function for which the contract does not continue as the stop candidate function. In a case where the authentication of the user is successful (YES in step S21), in a case where the contract of the function continues for the user (YES in step S27), the processing ends.

[0111] Further, such re-authentication processing is periodically or at any time executed. That is, after the processing ends, if the start condition of the re-authentication is satisfied, the processing is started again from step S21.

[0112] Next, reference will be made to Figure 10 Another other operation of the information processing system configured as described above will be described. Figure 10 is a flowchart showing an example of the operation in the countermeasure against vulnerability of the information processing system to which the embodiment is related.

[0113] In the present embodiment, a case where the countermeasure against vulnerability of the S / W imported to the vehicle 100 is performed using the available SBOM 108 will be described. In the present embodiment, the available SBOM 108 is used to perform the countermeasure against vulnerability of the S / W imported to the vehicle 100. Figure 10 In the operation example shown in FIG. 10, the operation of the information processing system in the countermeasure against vulnerability will be described.

[0114] As described above Figure 10As shown, first, any S / W information in the available SBOM 108 is subjected to processing for coping with the S / W information, that is, management of vulnerability of software (vulnerability management step S30). In the vulnerability management step S30, for the S / W information, a query is made to the vulnerability database 206, and the latest vulnerability information is acquired (step S301). Then, it is determined whether there is vulnerability information that needs to be coped with (step S302), for example, in a case where there is new vulnerability information in the vulnerability database, it is determined that there is vulnerability information that needs to be coped with (YES in step S302), and coping for vulnerability is implemented (step S303). In a case where it is determined that there is no vulnerability information that needs to be coped with (NO in step S302), the vulnerability management step S30 is ended. Then, it is determined whether the processing for all the S / W information included in the available SBOM 108 has been completed (step S31), and if the processing for all the S / W information has not been completed (NO in step S31), the vulnerability management step S30 is started for the next S / W information. In a case where the processing for all the S / W information has been completed (YES in step S31), the processing is ended.

[0115] Further, such coping processing for vulnerability is periodically or at any time performed. That is, after the processing is ended, if a start condition of re-authentication is satisfied, the processing is started again from step S30.

[0116] (Other Embodiments)

[0117] The above describes the control device and the like involved in the embodiment of the present disclosure, but the present disclosure is not limited to this embodiment.

[0118] For example, in the above-described embodiment, each constituent element can be constituted by a dedicated hardware or realized by executing a software program suitable for each constituent element. Each constituent element can also be realized by a program execution unit such as a CPU or a processor reading and executing a software program recorded in a recording medium such as a hard disk or a semiconductor memory.

[0119] In addition, each constituent element can be a circuit (or an integrated circuit). These circuits can be constituted as one circuit in its entirety, or each as an independent circuit. In addition, each of these circuits can be a general-purpose circuit, or a dedicated circuit.

[0120] In addition, the overall or specific technical solutions of the present disclosure can also be implemented by a system, an apparatus, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM. In addition, it can be implemented by any combination of a system, an apparatus, a method, an integrated circuit, a computer program, and a non-transitory recording medium. In addition, in the above-described embodiments, the processing performed by a specific processing unit can be performed by another processing unit. In addition, the order of the plurality of processes in the operation of the communication system described in the above-described embodiments can be changed, and a plurality of processes can be executed in parallel.

[0121] In addition, the present disclosure also includes embodiments obtained by various modifications that can be conceived by those skilled in the art with respect to each of the embodiments, or embodiments implemented by arbitrarily combining constituent elements and functions in each of the embodiments within a range that does not depart from the gist of the present disclosure.

[0122] Industrial applicability

[0123] The present disclosure is useful in the management of S / W in a vehicle.

[0124] Explanation of reference numerals

[0125] 100 vehicle

[0126] 101 SBOM management unit

[0127] 102 authentication unit

[0128] 103 execution control unit

[0129] 104 vulnerability management unit

[0130] 105 camera

[0131] 106 fingerprint authentication sensor

[0132] 107 SBOM

[0133] 108 available SBOM

[0134] 109, 205 function SFOP information

[0135] 110 autonomous driving system

[0136] 111 audio player

[0137] 200 server

[0138] 201 authentication information of user and contract information of user

[0139] 202 S / W information of added H / W

[0140] 203 SBOM of the vehicle

[0141] 204 available SBOM of the vehicle

[0142] 206 vulnerability database

[0143] 300 wireless audio

[0144] 301 wireless communication module

[0145] 302 audio control section

[0146] 303 H / W authentication information

[0147] 304 S / W

Claims

1. An information processing method, executed by a computer in a vehicle, wherein the vehicle switches between enabling and disabling various equipped functions based on the presence or absence of a user's contract. The information processing method includes the following steps: The detection step detects new additions to the software used to enable more than one function; The determination step involves determining whether the function, which is operated by the newly added software, has the user's contract. The acquisition step involves obtaining software information corresponding to the software that is determined to have the contract of the user; and The update step involves updating the list of software information for functions that can operate in the vehicle by adding the acquired software information.

2. The information processing method according to claim 1, In the acquisition step, software information corresponding to the software determined not to have a contract with the user is further acquired. In the update step, By adding the software information corresponding to the software identified as having the user's contract from the acquired software information, the list of software information for functions that can run in the vehicle is updated. The list of equipment software information for the functions equipped in the vehicle is updated by adding all the acquired software information.

3. The information processing method according to claim 1, In the detection step, new additions to the software are detected based on the introduction of hardware, which is the hardware that runs the software and performs the functions corresponding to the software, into the vehicle.

4. The information processing method according to claim 1, The information processing method further includes the following steps: The switching detection step further detects the switching of one or more of the executable software programs to non-executable software programs; and The deletion and update step updates the software information list by deleting the software information corresponding to the detected switched software from the software information list.

5. The information processing method according to claim 4, In the switching detection step, based on the change from a state of having a contract for the user to run the software to a state of not having such a contract, a switch of more than one software to be unable to run is detected.

6. The information processing method according to claim 5, The software information includes information related to the type of function that is performed through the corresponding software.

7. The information processing method according to claim 6, In the deletion and update step, if the information related to the type of function to be run by the detected switched software meets the first condition, the deletion of the software information corresponding to the detected switched software from the software information list is prohibited.

8. The information processing method according to claim 7, In the deletion and update step, if the information related to the type of function that is run by the detected switched software satisfies the first condition and the state of the vehicle satisfies the second condition, the deletion of the software information corresponding to the detected switched software from the software information list is prohibited.

9. The information processing method according to any one of claims 1 to 8, It also includes a vulnerability management step, which uses the updated software information list to manage the vulnerabilities of the software used to enable functions that can operate in the vehicle.

10. The information processing method according to claim 9, The vulnerability management steps are performed at predetermined intervals.

11. An information processing device, mounted on a vehicle, wherein the vehicle switches between enabling and disabling various equipped functions based on the presence or absence of a user's contract. The information processing device includes: The testing department tests new additions to the software used to enable more than one function. The determination unit determines whether the function, which is run by the newly added software, has the user's contract. The acquisition unit acquires software information corresponding to the software that is determined to have the contract of the user. The storage unit stores a list of software information about functions that can be operated in the vehicle; and The updating unit updates the stored list of software information by adding the acquired software information.

12. A program, Used to enable a computer to perform the information processing method of claim 1.

Citation Information

Patent Citations

  • Transmission device, reception device, container transmission system, method, and program

    WO2021260753A1