In-vehicle device, program, and information processing method

By detecting the device definition information of external devices and executing authentication procedures in the vehicle-mounted unit, the security and compatibility issues of the vehicle ECU when connecting to external devices are resolved, achieving efficient authentication and function control and ensuring the security of the in-vehicle communication environment.

CN121359415APending Publication Date: 2026-01-16AUTONETWORKS TECH LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202480039466.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-06-19
Filing Date
2024-06-10
Publication Date
2026-01-16

AI Technical Summary

Technical Problem

In existing technologies, vehicle ECUs fail to perform efficient authentication processing when connecting to external devices, leading to safety and compatibility issues.

Method used

By setting up a connection port and processing unit in the vehicle-mounted device, the device definition information of the external device is detected, the authentication process is executed to ensure its legitimacy, and functional restrictions are imposed or lifted based on the authentication results, thereby realizing the secure authentication and functional control of the external device.

Benefits of technology

It enables efficient authentication of external devices, ensuring the security and compatibility of the in-vehicle communication environment, preventing attacks from unauthorized devices, and improving the availability of the in-vehicle system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121359415A_ABST
    Figure CN121359415A_ABST
Patent Text Reader

Abstract

The in-vehicle device is provided with: a connection port which is mounted on a vehicle and to which an external device is connected; and a processing unit that performs processing pertaining to the external device connected to the connection port, the processing unit acquiring device definition information from the external device connected to the connection port, and if an authentication device category is included in the acquired device definition information, the processing unit performs processing pertaining to the external device connected to the connection port. An authentication program corresponding to the authentication device type is executed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to an in-vehicle device, a program, and an information processing method.

[0002] This application claims priority based on Japanese Application No. 2023-100128 filed on June 19, 2023, and all the contents described in the above Japanese application are incorporated by reference. BACKGROUND

[0003] In a vehicle, for example, a vehicle-mounted ECU (an in-vehicle ECU) that controls devices of a vehicle body system such as a wiper drive device, a lighting device for the inside and outside of the vehicle, a door lock device, a power window, and the like uniformly (for example, Patent Literature 1) is mounted. The wiper drive device of Patent Literature 1 includes a vehicle-mounted ECU (a vehicle body ECU), and is driven by a control program applied to the vehicle-mounted ECU.

[0004] PRIOR ART DOCUMENT

[0005] PATENT LITERATURE

[0006] Patent Literature 1: Japanese Patent Application Publication No. 2017-224926 SUMMARY

[0007] An in-vehicle device of one embodiment of the present disclosure includes a connection port mounted on a vehicle, and an external device connected to the connection port, and a processing unit that performs processing related to the external device connected to the connection port, wherein the processing unit acquires device definition information from the external device connected to the connection port, and executes an authentication program corresponding to an authentication device class in a case where the acquired device definition information includes the authentication device class. BRIEF DESCRIPTION OF DRAWINGS

[0008] Figure 1 is a schematic view illustrating a structure of an in-vehicle system including an in-vehicle device and the like according to Embodiment 1.

[0009] Figure 2 is a block diagram illustrating an internal structure of an in-vehicle device.

[0010] Figure 3 is a explanatory diagram (sequence chart) illustrating each processing performed by an in-vehicle device and the like.

[0011] Figure 4 is a flowchart illustrating processing of a processing unit of an in-vehicle device.

[0012] Figure 5 is a flowchart illustrating processing of a processing unit of an in-vehicle device according to Embodiment 2 (single device definition information).

[0013] Figure 6is a flowchart of processing of a processing section of an in-vehicle device related to Embodiment 3 (a state of a vehicle). DETAILED DESCRIPTION

[0014] [Problem to be Solved by the Invention]

[0015] It is assumed that an external device such as a USB device is connected to such an in-vehicle ECU, but in the in-vehicle ECU of Patent Literature 1, it is not considered that the processing related to authentication for the connected external device is efficiently performed.

[0016] An object of the present disclosure is to provide an in-vehicle device or the like capable of efficiently performing the processing related to authentication for a connected external device.

[0017] [Effects of the Invention]

[0018] According to one embodiment of the present disclosure, it is possible to provide an in-vehicle device or the like capable of efficiently performing the processing related to authentication for a connected external device.

[0019] [Explanation of Embodiments of the Invention]

[0020] First, an embodiment of the present disclosure is described. In addition, at least a part of the embodiments described below can be arbitrarily combined.

[0021] (1) An in-vehicle device according to one embodiment of the present disclosure includes a connection port mounted on a vehicle to which an external device is connected, and a processing section that performs processing related to the external device connected to the connection port, wherein the processing section acquires device definition information from the external device connected to the connection port, and executes an authentication program corresponding to an authentication device class in a case where the acquired device definition information includes the authentication device class.

[0022] In this aspect, the in-vehicle device has, for example, a connection port such as a USB port. The processing section of the in-vehicle device detects connection of an external device such as a USB device when the external device is connected to the connection port. The processing section of the in-vehicle device requests transmission of device definition information (descriptor information) from the external device (USB device) detected to be connected. The external device (USB device) transmits the device definition information (descriptor information) to the in-vehicle device in response to the request. The processing section of the in-vehicle device determines whether the authentication device class is included in the device definition information (descriptor information), and executes an authentication procedure corresponding to the authentication device class when the authentication device class is included. The authentication procedure is stored in a storage area such as a storage section of the in-vehicle device that is accessible by the processing section of the in-vehicle device, and a correspondence relationship between the authentication device class and the authentication procedure is stored in the storage section or the like. The processing section of the in-vehicle device starts an authentication process for the connected external device by executing the authentication procedure stored in the storage section or the like. The authentication process can be performed individually or in combination with various authentication processes such as a process based on a digital certificate issued by a CA (Certificate Authority), CHAP (Challenge Handshake Authentication Protocol) authentication, a process based on a MAC (Message Authentication Code), authentication using an encryption key, a private key, or a public key, and the like. In this way, the processing section of the in-vehicle device executes an authentication procedure on the device definition information (descriptor information) transmitted from the external device in accordance with the authentication device class when connection of the external device is detected at the connection port, and thus can ensure the security of the connected external device. That is, even when such an external device is connected by plug and play, and communication via an in-vehicle network to which the in-vehicle device or the like is connected is performed by the external device, the security of the external device can be ensured, and a secure in-vehicle communication environment can be constructed.

[0023] (2) In the in-vehicle device according to one aspect of the present disclosure, the external device is a USB device, and the connection port is a USB port. The USB device and the USB port comply with USB 2.0 or USB 1.1.

[0024] In this mode, the external device is a USB device, and the connection port is a USB port. The USB device (external device) complies with the USB 2.0 or USB 1.1 standard. In the USB 2.0 or the like, authentication of the USB device is not supported (not included), and the processing section of the in-vehicle device performs processing corresponding to the authentication device class included in the device definition information (descriptor information) in a sequence (USB device identification processing) performed when the connection of the USB device is detected. Therefore, the processing section of the in-vehicle device can follow the sequence (descriptor request and acquisition) of the standard at the time of detection of the USB device (external device), and perform the authentication procedure corresponding to the authentication device class before performing processing for causing the USB device (external device) to actually function as a storage device or an actuator or the like. Thus, even in the case where the authentication class processing is not defined on the standard such as the USB 2.0 or the like, the sequence of the standard at the time of detection of the USB device (external device) can be followed, and the authentication processing for the USB device (external device) can be performed. In particular, the USB port used by the in-vehicle device such as an ECU mounted on a vehicle (a USB port attached to a microcomputer or the like accompanying the in-vehicle device) is generally a USB port based on the standard of USB 2.0, and in such a state, even in the case of the in-vehicle device and the standard of USB 2.0, authentication of the USB device (external device) can be achieved.

[0025] (3) In the in-vehicle device according to one embodiment of the present disclosure, the processing section executes processing corresponding to the application device class included in the device definition information acquired from the external device without imposing a function restriction in a case where the execution result of the authentication procedure corresponding to the authentication device class is a positive authentication result, and executes processing corresponding to the application device class included in the device definition information acquired from the external device with imposing a function restriction in a case where the execution result of the authentication procedure corresponding to the authentication device class is a negative authentication result.

[0026] In this mode, the processing section of the in-vehicle device makes the function restriction at the time of causing the external device to act different depending on the execution result (authentication result) of the authentication procedure performed in correspondence with the authentication device class. The processing section of the in-vehicle device determines (extracts) the application device class included in the device definition information acquired from the external device after the authentication procedure corresponding to the authentication device class is executed. The processing section of the in-vehicle device executes the application program corresponding to the application device class. The application program corresponding to the application device class includes, for example, a device driver for causing the external device to act or various software corresponding to the hardware specifications of the external device, and is defined as, for example, a common class specification in the standard of USB 2.0 in the storage section of the in-vehicle device. The processing section of the in-vehicle device executes the processing corresponding to the application device class without imposing the function restriction in the case where the execution result of the authentication procedure is a positive authentication result (authentication success). In the case where the execution result of the authentication procedure is a positive authentication result (authentication success), the legality in terms of security of the external device is guaranteed, and thus the application program is executed without imposing the function restriction at the time of causing the external device to act. The processing section of the in-vehicle device can also impose the function restriction as an initial state at the time of detecting the connection of the USB device, and release the function restriction as a trigger of the positive authentication result (authentication success). Thus, in the case where the external device is, for example, a USB lamp, a USB camera, a wireless sub, various sensors such as a temperature sensor, or an installation device (reprogramming device) of an update program, the external device can be caused to act with the function possessed on the product specifications. The processing section of the in-vehicle device executes the processing corresponding to the application device class with imposing the function restriction in the case where the execution result of the authentication procedure is a negative authentication result (authentication failure). In the case where the execution result of the authentication procedure is a negative authentication result (authentication failure), the legality in terms of security of the external device is not guaranteed, and thus the external device is caused to act with imposing the function restriction. The processing section of the in-vehicle device can also impose the function restriction as an initial state at the time of detecting the connection of the USB device, and maintain the function restriction as a trigger of the negative authentication result (authentication failure). The function restriction includes, for example, an act restriction of supplying power to the USB device only or an act restriction of performing communication of non-secure information such as media data only. Alternatively, the processing section of the in-vehicle device can also perform the cutoff of the power and the communication with respect to the USB device for which the negative authentication result (authentication failure) is made, as the function restriction with respect to the USB device. In this way, the processing section of the in-vehicle device can ensure a secure in-vehicle communication environment by providing the function restriction at the time of causing the external device to act in the case of the negative authentication result (authentication failure).

[0027] (4) In the in-vehicle device according to the present disclosure in one embodiment, the processing portion saves the device definition information including the authentication device class in a case where the execution result of the authentication program corresponding to the authentication device class is a negative authentication result.

[0028] In the present embodiment, the processing portion of the in-vehicle device saves the device definition information (descriptor information) acquired from the USB device (external device) in a case where the execution result of the authentication program for the connected USB device (external device) is a negative authentication result (authentication failure), for example, in the storage portion of the in-vehicle device. The processing portion of the in-vehicle device can save (store) the device definition information in association with the date and time (acquisition date and time) acquired from the USB device (external device) when saving the device definition information. The USB device (external device) that becomes a negative authentication result (authentication failure) can be an illegal device, but by saving the device definition information (descriptor information) transmitted from the USB device (external device) as log information or the like, for example, it becomes possible to serve as raw data for analyzing an attack pattern based on an illegal device or the like.

[0029] (5) In the in-vehicle device according to the present disclosure in one embodiment, the processing portion executes the processing related to the device definition information including the application device class after executing the processing related to the device definition information including the authentication device class on the external device in a case where the external device is detected to be connected to the connection port.

[0030] In the present embodiment, the processing portion of the in-vehicle device first requests the device definition information (descriptor information) including the authentication device class from the external device when detecting that the external device is connected to the connection port. The processing portion of the in-vehicle device requests the device definition information (descriptor information) including the application device class from the external device after requesting the device definition information (descriptor information) including the authentication device class. In this way, the processing portion of the in-vehicle device performs communication related to the authentication device class on the external device and then performs communication related to the application device class. Therefore, in the sequence of the in-vehicle device and the external device, the first half performs processing for the authentication device class and the second half performs processing for the application device class, and the switching of the device class can be performed during the execution of the sequence. The device class is used as a control factor (element) for determining the kind of the USB device and causing it to act when the USB device is connected to the USB port, and by performing the switching of the device class in this way, it is possible to efficiently shift from the authentication class processing based on the authentication program to the action class processing based on the application program execution.

[0031] (6) In the vehicle-mounted device according to the present disclosure in one embodiment, the processing section determines that the external device is an authentication non-compliant device when the device definition information acquired by the processing section upon detection of the connection of the external device to the connection port does not include the authentication device class, and executes processing corresponding to the application device class included in the device definition information acquired from the external device while imposing a function restriction.

[0032] In this embodiment, upon detection of the connection of an external device (USB device) to a connection port, the processing section of the vehicle-mounted device determines that the external device (USB device) is an authentication non-compliant device when the authentication device class is not included in the initial device definition information (descriptor information) acquired from the external device. In this case, the processing section of the vehicle-mounted device executes the application program corresponding to the application device class included in the device definition information (descriptor information) while imposing a function restriction when the external device determined to be an authentication non-compliant device is caused to operate. The external device (USB device) determined to be an authentication non-compliant device does not include the authentication device class, and outputs (transmits) device definition information (descriptor information) including the application device class to the vehicle-mounted device. The processing section of the vehicle-mounted device executes the application program corresponding to the application device class included in the device definition information (descriptor information) while imposing a function restriction when the external device (USB device) is caused to operate. In this way, even if the connected external device (USB device) is an authentication non-compliant device, the processing section of the vehicle-mounted device causes the external device to operate while imposing a function restriction, and thus, for example, compatibility or versatility with respect to USB devices compliant with standards such as USB 2.0 can be ensured. On this basis, in the case where the connected external device (USB device) is an authentication non-compliant device, the external device is caused to operate while imposing a function restriction, and thus, a safe in-vehicle communication environment can be ensured. The processing section of the vehicle-mounted device can also cause the function restriction with respect to the external device determined to be an authentication non-compliant device to be different from the function restriction with respect to the external device for which the execution result of the authentication program is a negative authentication result (authentication failure) when the function restriction is set. In this way, by causing the function restriction to be different depending on the category of the determination result, flexible responses corresponding to the connected external device (USB device) can be realized, and the usability as a vehicle-mounted system can be improved.

[0033] (7) In the vehicle-mounted device according to the present disclosure in one embodiment, the processing section acquires state information related to the state of the vehicle, and retains at least a part of the processing related to the device definition information transmitted from the external device when the state information indicates a running state.

[0034] In the present mode, the processing section of the in-vehicle device, based on the acquired state information, retains at least a part of the processing corresponding to the device definition information (descriptor information) acquired from the connected external device (USB device) in the processing of the authentication-use device class. The state information is information related to the state of the vehicle, such as a state indicating running and a state indicating a stop other than the running. The processing section of the in-vehicle device, for example, can also acquire a signal from a power switch or an IG switch that controls the start or stop of the vehicle, and based on the signal, derive whether the state of the vehicle is the running or the stop. Alternatively, the processing section of the in-vehicle device, for example, can also acquire an output value (sensor value) from a vehicle speed sensor, an engine or motor rotation speed sensor, or the like, and based on the output value (sensor value), derive whether the state of the vehicle is the running or the stop. The processing section of the in-vehicle device can also, in the case where the state information indicates the running (the vehicle is running), when the external device is detected to be connected to the connection port, in the sequence of the in-vehicle device and the external device, perform only the processing of the authentication-use device class that becomes the first half, and retain (stop the sequence) the processing of the application-use device class that becomes the second half. The processing section of the in-vehicle device can also, in the case where the state information changes from the running to the stop, execute the retained processing of the application-use device class (restart the sequence). It is assumed that by executing the application program corresponding to the application-use device class, the action on the external device (USB device) is started, and as a result of the drive or function of the external device, the change in the in-vehicle communication environment occurs in which the communication data is transmitted from the external device to the in-vehicle network. In contrast, in the case where the vehicle is running (the state information is the running), by retaining the processing of the application-use device class, the influence of the newly connected external device (USB device) on the in-vehicle network can be mitigated.

[0035] (8) A program according to one embodiment of the present disclosure causes a computer provided with a connection port for connecting an external device mounted on a vehicle to execute processing of acquiring device definition information from the external device connected to the connection port, and in the case where the acquired device definition information includes an authentication-use device class, executing an authentication program corresponding to the authentication-use device class.

[0036] In the present mode, it is possible to provide a program that causes a computer to function as an in-vehicle device that efficiently performs processing related to authentication of a connected external device.

[0037] (9) An information processing method according to one embodiment of the present disclosure causes a computer provided with a connection port for connecting an external device mounted on a vehicle to execute processing of acquiring device definition information from the external device connected to the connection port, and in the case where the acquired device definition information includes an authentication-use device class, executing an authentication program corresponding to the authentication-use device class.

[0038] In the present embodiment, an information processing method can be provided in which a computer functions as an in-vehicle device that efficiently performs processing related to authentication of a connected external device.

[0039] [Details of Embodiments of the Invention]

[0040] The present disclosure will be specifically described based on the drawings representing embodiments thereof. Hereinafter, an in-vehicle device 1 related to an embodiment of the present disclosure will be described with reference to the drawings. Furthermore, the present disclosure is not limited to these examples, and is intended to be shown by the scope of the claims, including the meaning and scope equivalent to the scope of the claims and all modifications within the scope.

[0041] (Embodiment 1)

[0042] Hereinafter, an embodiment will be described based on the drawings. Figure 1 is a schematic view illustrating the structure of an in-vehicle system S including the in-vehicle device 1 and the like related to Embodiment 1. Figure 2 is a block diagram illustrating the internal structure of the in-vehicle device 1. The in-vehicle system S is configured as a device mainly including the in-vehicle device 1 mounted on a vehicle C, which is configured to be able to additionally connect (post-install) an external device 141. The in-vehicle device 1 is connected in a communicable manner with a plurality of in-vehicle ECUs 2 via an in-vehicle network 3 constituted by a communication line 31, and performs various processing based on messages transmitted from these in-vehicle ECUs 2 or output signals from various sensors and the like.

[0043] The in-vehicle device 1 is connected with the external device 141. The external device 141 is, for example, a USB (Universal Serial Bus) device complying with a standard such as USB 2.0. The in-vehicle device 1 has a connection port 14 (USB port) for connecting the external device 141 (USB device), and functions as a USB host. When the in-vehicle device 1 detects that the external device 141 (USB device) is connected to the connection port 14 (USB port), the in-vehicle device 1 performs, for example, communication complying with a standard such as USB 2.0 between the in-vehicle device 1 and the external device 141 (USB device), and performs a request for and acquisition of device definition information (descriptor information).

[0044] A power supply device 5 constituted by a lead storage battery, an alternator, or a secondary battery, and the like is mounted on the vehicle C. The power supply device 5 is connected with the in-vehicle device 1 through a power line 51. The power supply device 5 and the in-vehicle device 1 are not limited to the case where they are directly connected through the power line 51, and can be indirectly connected with an electrical box (junction box) such as a relay box or a fuse box interposed therebetween.

[0045] The in-vehicle device 1 may, for example, also be a relay device (CAN gateway, Ethernet switch) having a relay function such as a CAN gateway or an Ethernet switch. Alternatively, the in-vehicle device 1 may also be a comprehensive ECU (vehicle computer) that comprehensively controls the entire vehicle C and has a relay function. Alternatively, the in-vehicle device 1 may also be an individual ECU that is subordinate to the comprehensive ECU and is arranged in each region of the vehicle C. Alternatively, the in-vehicle device 1 may also be a body ECU or the like that controls a body system actuator of the vehicle C. Alternatively, the in-vehicle device 1 may also be a PLB (Power Lan Box) that functions as a power distribution device that distributes and relays electric power output from a power source device 5 such as a secondary battery and supplies the electric power to in-vehicle equipment such as an actuator, in addition to relaying communication. Alternatively, the in-vehicle device 1 may also be an information terminal device that is connected to the in-vehicle network 3 through wireless communication.

[0046] The in-vehicle device 1 includes a processing section 11, a storage section 12, a communication section 13, and a connection port 14, which may, for example, also be configured by being packaged by a microcomputer or the like. The processing section 11 is configured by a CPU (Central Processing Unit) or an MPU (Micro Processing Unit) or the like, and performs various control processing and arithmetic processing and the like by reading out and executing a control program P (program product) and data that are stored in the storage section 12 in advance.

[0047] The storage section 12 is configured by a volatile memory element such as a RAM (Random Access Memory) or a non-volatile memory element such as a ROM (Read Only Memory), an EEPROM (Electrically Erasable Programmable ROM), or a flash memory, or a combination of these storage devices, and stores a control program P (program product) and data that are referred to at the time of processing in advance. The control program P (program product) stored in the storage section 12 may also be a control program P (program product) that is read out from a recording medium M that can be read by the in-vehicle device 1. In addition, the control program P (program product) may also be downloaded from an external computer that is not shown and that is connected to a communication network that is not shown, and stored in the storage section 12.

[0048] The communication section 13 is, for example, an input and output interface that uses a communication protocol such as CAN, CAN-FD, or Ethernet (registered trademark), and the processing section 11 communicates with the in-vehicle ECUs 2 connected to the in-vehicle network 3 via the communication section 13. In the in-vehicle device 1, the communication section 13 may also be provided in plurality.

[0049] The connection port 14 is, for example, a USB port compliant with USB 2.0 or USB 1.1 standards, and functions as an input / output interface for a connected external device 141 (USB device). The in-vehicle device 1 is provided with one or more (three in the illustration) connection ports 14 (USB ports).

[0050] Figure 3 is an explanatory diagram (sequence diagram) illustrating one mode of each processing performed by the in-vehicle device 1 or the like. The in-vehicle device 1 (USB host) and the external device 141 (USB device) connected to the connection port 14 (USB port) of the in-vehicle device 1 (USB host) perform, for example, serial communication compliant with USB 2.0 standards, and perform the following sequence processing.

[0051] The in-vehicle device 1 detects the external device 141 connected to the connection port 14 (S01). The in-vehicle device 1 requests (descriptor request) the external device 141 to transmit device definition information (descriptor information) (S02). The in-vehicle device 1 always performs processing of detecting whether the external device 141 is connected to the connection port 14. The in-vehicle device 1 requests (descriptor request) the external device 141 to transmit device definition information (descriptor information) in a case where the external device 141 is connected to the connection port 14. The device definition information is referred to as descriptor information in the standards of USB 2.0, and contains, for example, identifiers such as a vendor ID, a product ID, and a serial number ID, in addition to a device class indicating a kind of the external device 141 as a USB device, power information, and information about an endpoint or the like.

[0052] The device definition information (descriptor information) initially requested by the in-vehicle device 1 to the external device 141 at the time of detection of connection of the external device 141 to the connection port 14 is descriptor information containing an authentication-use device class. The in-vehicle device 1 can also explicitly perform a transmission request of the device definition information (descriptor information) containing the authentication-use device class to the external device 141. The in-vehicle device 1 can also set (initially set) a function restriction (device restriction release) for the external device 141 at the time of detection of connection of the external device 141.

[0053] The external device 141 (USB device) transmits the device definition information (descriptor information) to the in-vehicle device 1 (descriptor transmission) (S03). The external device 141 transmits the device definition information (descriptor information) containing the authentication-use device class to the in-vehicle device 1 in accordance with the descriptor request (transmission request of the descriptor information containing the authentication-use device class) from the in-vehicle device 1.

[0054] The in-vehicle device 1 acquires the device definition information (descriptor information) and detects (extracts) the authentication device class (S04). The in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 and detects (extracts) the authentication device class included in the device definition information.

[0055] The in-vehicle device 1 executes the authentication procedure corresponding to the authentication device class (S05). The in-vehicle device 1 determines the authentication procedure corresponding to the detected authentication device class and executes the authentication procedure. The in-vehicle device 1 communicates with the external device 141 by executing the authentication procedure, for example, performs various authentication processes such as a process based on a digital certificate issued by a CA (Certificate Authority), CHAP (Challenge Handshake Authentication Protocol) authentication, a process based on a MAC (Message Authentication Code), authentication using an encryption key, a private key, or a public key, and the like, alone or in combination. The in-vehicle device 1 acquires (derives) a positive authentication result (authentication success) indicating that the authentication is successful or a negative authentication result (authentication failure) indicating that the authentication is failed as a result of execution of the authentication procedure.

[0056] The in-vehicle device 1 releases the function restriction (device restriction release) set as an initial state at the time when the connection of the USB device is detected, in a case where the result of execution of the authentication procedure corresponding to the authentication device class is the positive authentication result (authentication success) (S06). The in-vehicle device 1 sets the function restriction (device restriction) for the external device 141 as an initial setting at the time when the connection of the external device 141 is detected. The in-vehicle device 1 can become a state in which the external device 141 can exert all the functions possessed on the product specifications by releasing the function restriction (device restriction) in a case where the result of execution of the authentication procedure is the positive authentication result (authentication success). The in-vehicle device 1 can also maintain the function restriction set as an initial state at the time when the connection of the USB device is detected, in a case where the result of execution of the authentication procedure corresponding to the authentication device class is the negative authentication result (authentication failure). In this sequence diagram, the processing after that is explained in a case where the result is the positive authentication result (authentication success).

[0057] After the authentication procedure corresponding to the authentication-use device class is executed, in the sequence of the in-vehicle device 1 and the external device 141, switching of the applied device class (device class switching) is performed. That is, the external device 141 switches its own device class from the authentication-use device class to the application-use device class before and after the authentication procedure is executed. Therefore, in the sequence of the in-vehicle device 1 and the external device 141, the first half performs processing for the authentication-use device class, and the latter half performs processing for the application-use device class.

[0058] The in-vehicle device 1 detects the external device 141 connected to the connection port 14 in a state where the function restriction is released (S07). The in-vehicle device 1 requests (descriptor request) the external device 141 for transmission of the device definition information (descriptor information) (S08). The in-vehicle device 1 and the external device 141 perform S07 to S08 similarly to the processing of S01 to S02 after switching the device class to be the object from the authentication-use device class to the application-use device class. The device definition information (descriptor information) requested by the in-vehicle device 1 to the external device 141 for the second time upon detecting the connection of the external device 141 to the connection port 14 is descriptor information including the application-use device class. The in-vehicle device 1 can also explicitly perform a request for transmission of the device definition information (descriptor information) including the application-use device class to the external device 141. That is, the in-vehicle device 1 can also output different transmission request data (signals) to the external device 141 at the time of the transmission request of the device definition information (descriptor information) to the external device 141 between the transmission request of the device definition information (descriptor information) including the authentication-use device class and the transmission request of the device definition information (descriptor information) including the application-use device class.

[0059] The external device 141 (USB device) transmits (descriptor transmission) the device definition information (descriptor information) to the in-vehicle device 1 (S09). The device class of the external device 141 (USB device) is switched from the authentication-use device class to the application-use device class triggered by the approval processing by the in-vehicle device 1. The external device 141 transmits the device definition information (descriptor information) including the application-use device class to the in-vehicle device 1 in accordance with the descriptor request (transmission request of the descriptor information including the application-use device class) from the in-vehicle device 1.

[0060] The in-vehicle device 1 acquires the device definition information (descriptor information) and detects (extracts) the application-use device class (S10). The in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 and detects (extracts) the application-use device class included in the device definition information.

[0061] The in-vehicle device 1 executes an application program corresponding to the application device class (S11). The in-vehicle device 1 determines an application program corresponding to the detected application device class, and executes the application program. The application program corresponding to the application device class includes, for example, a device driver for causing the external device 141 to act, or various software corresponding to the hardware specifications of the external device 141, which are stored in the storage section 12. Thus, the in-vehicle device 1 (USB host) and the external device 141 (USB device) function in accordance with the executed application program (start USB communication), and the external device 141 (USB device) is able to start the action process based on the product specifications.

[0062] For example, in the case where the external device 141 (USB device) is an external USB camera, the function of the automatic driving or the drive recorder can be updated. In the case where the external device 141 (USB device) is a USB memory, for a vehicle C not equipped with a vehicle-external communication device that performs wireless communication with a vehicle-external server such as an OTA server, it is possible to download an update program such as firmware to the USB memory, and perform the update (reprogramming) of the software via the connected USB memory. In the case where the external device 141 (USB device) is a USB wireless device having a wireless function such as 4G or 5G, by connecting (after-installing) the USB wireless device to a vehicle C not equipped with a vehicle-external communication device as a standard equipment, it is possible to add the wireless communication function with a vehicle-external server such as an OTA server.

[0063] Figure 4 is a flowchart illustrating the process of the processing section 11 of the in-vehicle device 1. The processing section 11 of the in-vehicle device 1 performs the following process, for example, at the start or stop of the vehicle C.

[0064] The processing section 11 of the in-vehicle device 1 determines whether the external device 141 (USB device) is connected to the connection port 14 (USB port) (S101). The connection port 14 is, for example, a USB port conforming to the standard of USB 2.0, and the processing section 11 of the in-vehicle device 1 stably or continuously performs the process of determining whether the external device 141 (USB device) is connected to the connection port 14 (USB port). In the case where the external device 141 is not connected to the connection port 14 (S101: No), the processing section 11 of the in-vehicle device 1 performs a loop process in order to execute the process of S101 again.

[0065] When the external device 141 is connected to the connection port 14 (S101: YES), the processing section 11 of the in-vehicle device 1 requests (descriptor request) the transmission of the device definition information (descriptor information) to the external device 141 (S102). The processing section 11 of the in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 (S103). Immediately after detecting the connection of the external device 141 to the connection port 14, the processing section 11 of the in-vehicle device 1 requests the descriptor information including the authentication device class to the external device 141. The external device 141 transmits (outputs) the device definition information (descriptor information) to the in-vehicle device 1 in accordance with the request from the processing section 11 of the in-vehicle device 1. The processing section 11 of the in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 and stores it in the storage section 12.

[0066] The processing section 11 of the in-vehicle device 1 determines whether the authentication device class is included in the acquired device definition information (descriptor information) (S104). The external device 141 (USB device) includes an authentication corresponding device corresponding to the authentication device class and an authentication non-corresponding device not corresponding to the authentication device class.

[0067] When the external device 141 (USB device) is the authentication corresponding device, the device definition information (descriptor information) including the authentication device class is transmitted (output) to the in-vehicle device 1 for the initial (first time after the connection port 14 detects the connection) descriptor request from the in-vehicle device 1. When the external device 141 (USB device) is the authentication non-corresponding device, the device definition information (descriptor information) including the application device class is transmitted (output) to the in-vehicle device 1 for the initial (first time after the connection port 14 detects the connection) descriptor request from the in-vehicle device 1. The processing section 11 of the in-vehicle device 1 can determine whether the external device 141 (USB device) connected to the connection port 14 (USB port) is the authentication corresponding device or the authentication non-corresponding device in accordance with whether the authentication device class is included in the acquired device definition information (descriptor information).

[0068] In a case where the authentication-use device category is included (S104: YES), the processing section 11 of the in-vehicle device 1 executes an authentication program corresponding to the authentication-use device category (S105). The processing section 11 of the in-vehicle device 1 determines the authentication program corresponding to the authentication-use device category in a case where the authentication-use device category is included in the acquired device definition information (descriptor information). The processing section 11 of the in-vehicle device 1 can determine the authentication program by referring to the storage. In a case where a plurality of authentication-use device categories are defined in advance, each authentication-use device category and each authentication program corresponding to the authentication-use device category are defined, for example, by a table form (authentication-use device category table) and stored in the storage section 12. The processing section 11 of the in-vehicle device 1 can also determine the authentication program by referring to the authentication-use device category table.

[0069] The processing section 11 of the in-vehicle device 1 performs communication corresponding to various authentication processes between the in-vehicle device 1 and the external device 141 by executing the determined authentication program. The authentication process is performed, for example, individually or in combination of various authentication processes such as a process based on a digital certificate issued by a CA (Certificate Authority), a CHAP (Challenge Handshake Authentication Protocol) authentication, a process based on a MAC (Message Authentication Code), an authentication using an encryption key, a private key, or a public key, and the like. In this way, in the authentication process, by adopting an authentication method using an encryption key or the like, it is possible to effectively defend against impersonation or the like.

[0070] The processing section 11 of the in-vehicle device 1 determines whether the execution result of the authentication program is a positive authentication result (authentication success) (S106). The processing section 11 of the in-vehicle device 1 acquires (derives) the execution result of the authentication program (determination result of the authentication process). The determination result of the authentication process shows a positive authentication result (authentication success) indicating that the authentication is successful, or a negative authentication result (authentication failure) indicating that the authentication is failed.

[0071] In a case where the execution result of the authentication program is a positive authentication result (authentication success) (S106: YES), the function restriction (device restriction release) on the external device 141 is released (S107). The processing section 11 of the in-vehicle device 1 releases the function restriction (device restriction release) on the external device 141 applied as an initial setting in a case where the execution result of the authentication program is a positive authentication result (authentication success). The processing section 11 of the in-vehicle device 1 switches the device category in the sequence of the in-vehicle device 1 (USB host) and the external device 141 (USB device) from the authentication-use device category to the application-use device category after executing the authentication program.

[0072] The processing section 11 of the in-vehicle device 1 requests (descriptor request) the transmission of the device definition information (descriptor information) to the external device 141 (S108). The processing section 11 of the in-vehicle device 1 can also perform the process of detecting the external device 141 again at the connection port 14 at the time of re-executing the descriptor request or the like. The processing section 11 of the in-vehicle device 1 requests (descriptor request) the transmission of the device definition information (descriptor information) as the second time to the external device 141. In this second descriptor request, the processing section 11 of the in-vehicle device 1 requests the device definition information (descriptor information) including the application device class from the external device 141.

[0073] The processing section 11 of the in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 (S109). The external device 141 transmits (outputs) the device definition information (descriptor information) including the application device class to the in-vehicle device 1 according to the request from the processing section 11 of the in-vehicle device 1. The processing section 11 of the in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 and stores it in the storage section 12.

[0074] The processing section 11 of the in-vehicle device 1 detects (extracts) the application device class included in the device definition information (descriptor information) (S110). The processing section 11 of the in-vehicle device 1 determines the application program corresponding to the application device class included in the device definition information (descriptor information) (S111). The processing section 11 of the in-vehicle device 1 determines the application program based on the application device class detected (extracted) from the device definition information (descriptor information). The correspondence relationship between each application device class and each application program is defined, for example, by a table form (application device class table) and stored in the storage section 12. The processing section 11 of the in-vehicle device 1 can also determine the application program by referring to the application device class table.

[0075] The processing section 11 of the in-vehicle device 1 executes the determined application program (S112). The processing section 11 of the in-vehicle device 1 enables the external device 141 to exert all the functions possessed on the product specifications by executing the determined application program. This process is performed in the case of a positive authentication result (authentication success), and the function restriction (device restriction) to the external device 141 is released. Therefore, the in-vehicle device 1 (USB host) and the external device 141 (USB device) can exert the functions corresponding to the executed application program (start USB communication) and cause the external device 141 (USB device) to act according to the product specifications.

[0076] In a case where the execution result of the authentication program is not the affirmative authentication result (authentication success) (S106: No), the function restriction on the external device 141 is maintained (device restriction maintenance) (S1061). The processing portion 11 of the in-vehicle device 1 maintains (device restriction maintenance) the function restriction on the external device 141, which is initially set when the connection port 14 detects the connection, in a case where the execution result of the authentication program is not the affirmative authentication result (authentication success), that is, in a case of the negative authentication result (authentication failure). The processing portion 11 of the in-vehicle device 1 can also store the device definition information (descriptor information) in a case of the negative authentication result (authentication failure) in the storage portion 12 as the illegal device detection result on the connected external device 141 (USB device).

[0077] The processing portion 11 of the in-vehicle device 1 requests (descriptor request) the transmission of the device definition information (descriptor information) from the external device 141 (S1062). The processing portion 11 of the in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 (S1063). The processing portion 11 of the in-vehicle device 1 can also perform the process of detecting the external device 141 again at the connection port 14 when the descriptor request or the like is performed again. The processing portion 11 of the in-vehicle device 1 detects (extracts) the application device class included in the device definition information (descriptor information) (S1064). The processing portion 11 of the in-vehicle device 1 determines the application program corresponding to the application device class included in the device definition information (descriptor information) (S1065). The processing portion 11 of the in-vehicle device 1 performs the processes of S1062 to S1065 similarly to the processes of S108 to S111.

[0078] The processing portion 11 of the in-vehicle device 1 executes the determined application program (S1066). This process is performed in a case of the negative authentication result (authentication failure), and the function restriction (device restriction) on the external device 141 is maintained. The function restriction (device restriction) includes, for example, an action restriction of performing only the power supply to the USB device or an action restriction of performing communication of only non-secure information such as media data. The processing portion 11 of the in-vehicle device 1 can cause the external device 141 (USB device) to perform only the limited action process by performing the application program corresponding to the application device class on the basis of the function restriction (device restriction) thus imposed. Alternatively, the processing portion 11 of the in-vehicle device 1 can perform the function restriction (device restriction) of cutting off the power and the communication to the USB device. In this way, the processing portion 11 of the in-vehicle device 1 causes the external device 141 to act with the function restriction imposed in a case of the negative authentication result (authentication failure), and thus can ensure a secure in-vehicle communication environment.

[0079] In the case where the authentication device category is not included (S104: No), the processing section 11 of the in-vehicle device 1 maintains the function restriction (device restriction) on the external device 141 (S1041). The processing section 11 of the in-vehicle device 1 determines that the external device 141 connected to the connection port 14 is the authentication non-correspondence device in the case where the authentication device category is not included in the device definition information (descriptor information). On this basis, the processing section 11 of the in-vehicle device 1 performs S1041 similarly to the processing S1061.

[0080] The processing section 11 of the in-vehicle device 1 detects (extracts) the application device category included in the device definition information (descriptor information) acquired at the outset (in the processing of S103) (S1042). The processing section 11 of the in-vehicle device 1 determines the application program corresponding to the application device category included in the device definition information (descriptor information) (S1043). The processing section 11 of the in-vehicle device 1 executes the determined application program (S1044). The processing section 11 of the in-vehicle device 1 performs S1042 to S1044 similarly to the processing S1064 to S1066. The present processing is performed in the case of the negative authentication result (authentication failure), and the function restriction (device restriction) on the external device 141 is maintained. The function restriction (device restriction) can be the same kind of restriction as in the case where the execution result of the authentication program is the negative authentication result (authentication failure), or can be a different kind of restriction.

[0081] (Embodiment 2)

[0082] Figure 5 is a flowchart illustrating the processing of the processing section 11 of the in-vehicle device 1 according to Embodiment 2 (single device definition information). The processing section 11 of the in-vehicle device 1 performs the following processing at all times, for example, at the start or stop of the vehicle C. The processing section 11 of the in-vehicle device 1 performs the processing of S201 to S202 similarly to S101 to S102 of Embodiment 1.

[0083] The processing section 11 of the in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 (S203). The external device 141 connected to the connection port 14 assumes both the case of the authentication correspondence device corresponding to the authentication device category and the case of the authentication non-correspondence device not corresponding to the authentication device category. The device definition information (descriptor information) from the external device 141 as the authentication correspondence device includes both the authentication device category and the application device category as the device categories. The device definition information (descriptor information) from the external device 141 as the authentication non-correspondence device includes only the application device category as the device category.

[0084] The processing section 11 of the in-vehicle device 1 determines whether the authentication-use device category is included in the acquired device definition information (descriptor information) (S204). The device category included in the device definition information (descriptor information) differs depending on whether the external device 141 connected to the connection port 14 is an authentication- corresponding device or an authentication-non-corresponding device. The processing section 11 of the in-vehicle device 1 can determine whether the external device 141 is an authentication- corresponding device or an authentication-non-corresponding device depending on whether the authentication-use device category is included in the device definition information (descriptor information).

[0085] The processing section 11 of the in-vehicle device 1 performs the processes of S205 to S207 similarly to S105 to S107 of the embodiment. Also, the processing section 11 of the in-vehicle device 1 performs the processes of S208 to S210 similarly to S110 to S112 of the embodiment. Also, the processing section 11 of the in-vehicle device 1 performs the processes of S2061 and S2062 to S2064 similarly to S1061 and S1064 to S1066 of the embodiment. Also, the processing section 11 of the in-vehicle device 1 performs the processes of S2041 to S2044 similarly to S1041 to S1044 of the embodiment.

[0086] In the present embodiment, the device definition information (descriptor information) from the external device 141 that is an authentication- corresponding device includes the authentication-use device category and the application-use device category. Therefore, it is possible to cause the descriptor request between the in-vehicle device 1 and the external device 141 to be only once, and it is possible to shorten the required time in the sequence processing of the in-vehicle device 1 and the external device 141.

[0087] (Embodiment Three)

[0088] Figure 6 is a flowchart illustrating the process of the processing section 11 of the in-vehicle device 1 related to Embodiment Three (the state of the vehicle C). The processing section 11 of the in-vehicle device 1 performs the following process, for example, at the time of starting or stopping of the vehicle C. The processing section 11 of the in-vehicle device 1 performs the process of S301 similarly to S101 of the embodiment.

[0089] The processing section 11 of the in-vehicle device 1 determines whether the vehicle C is in a running state (S302). The processing section 11 of the in-vehicle device 1, for example, acquires state information related to the state of the vehicle C from the in-vehicle ECU 2 connected in a communicable manner via the in-vehicle network 3, and determines whether the vehicle C is in a running state on the basis of the state information. The state information is information related to the state of the vehicle C, such as a running state and a stop state indicating a state other than the running state. The processing section 11 of the in-vehicle device 1, for example, can also acquire a signal from a power switch or an IG switch that controls the start or stop of the vehicle C, and derive whether the state of the vehicle C is a running state or a stop state on the basis of the signal. Alternatively, the processing section 11 of the in-vehicle device 1, for example, can also acquire output values (sensor values) of the actuators, such as a vehicle speed sensor, an engine, or a drive motor, from the in-vehicle ECU 2 that controls these actuators, and derive whether the state of the vehicle C is a running state or a stop state on the basis of the output values (sensor values).

[0090] In a case where the vehicle C is in a running state (S302: YES), the processing section 11 of the in-vehicle device 1 performs loop processing in order to execute the processing of S302 again. Thereby, the processing section 11 of the in-vehicle device 1 performs standby processing until the vehicle C becomes not in a running state, that is, becomes in a stop state. By thus performing standby processing, even in a case where the external device 141 (USB device) is detected as connected to the connection port 14 (USB port) in the running of the vehicle C, it is possible to reserve a series of processing for the external device 141. On this basis, in a case where the vehicle C is transitioned from a running state to a stop state, it is possible to start the reserved processing again, and execute authentication processing and action processing, and the like for the external device 141.

[0091] In a case where the vehicle C is not in a running state (S302: NO), the processing section 11 of the in-vehicle device 1 requests (descriptor request) the external device 141 to transmit device definition information (descriptor information) (S303). The processing section 11 of the in-vehicle device 1 performs the processing of S303 to S313, S3054, and S3076 similarly to S102 to S112, S1044, and S1066 of Embodiment 1.

[0092] In the present embodiment, in a case where the vehicle C is in the running state (in a case where the state information indicates the running state), the processing from S302, that is, the processing related to the request and the acquisition of the descriptor information including the authentication device class, is reserved, but is not limited thereto. The processing section 11 of the in-vehicle device 1 can also reserve the processing from S308, that is, the processing after the switching of the device class from the authentication device class to the application device class, in a case where the vehicle C is in the running state (in a case where the state information indicates the running state). Alternatively, the reservation definition information defining the processing (for example, the step number in the flowchart) to be reserved when the vehicle C is in the running state can be stored in the storage section 12 of the in-vehicle device 1, and the processing section 11 of the in-vehicle device 1 can determine the processing to be reserved when the vehicle C is in the running state in accordance with the reservation definition information.

[0093] It should be understood that the embodiments disclosed herein are illustrative in all aspects and are not restrictive. The scope of the present application is not intended to be limited to the above-described aspects, but is shown by the scope of claims, and is intended to include all modifications equivalent in meaning and scope to the scope of claims.

[0094] As for the plurality of claims recited in the scope of claims, they can be combined with each other regardless of the citation form. In the scope of claims, a plurality of dependent claims subordinate to a plurality of claims can be recited. A plurality of dependent claims subordinate to a plurality of dependent claims can be recited. Even in a case where a plurality of dependent claims subordinate to a plurality of dependent claims is not recited, it is not limited to the recitation of the plurality of dependent claims subordinate to the plurality of dependent claims.

[0095] Mark Description

[0096] C vehicle;

[0097] S in-vehicle system;

[0098] 1 in-vehicle device (USB host);

[0099] 11 processing section;

[0100] 12 storage section;

[0101] M recording medium;

[0102] P control program (program product);

[0103] 13 communication section;

[0104] 14 connection port (USB port);

[0105] 141 external device (USB device);

[0106] 2 in-vehicle ECU;

[0107] 3 in-vehicle network;

[0108] 31 communication line;

[0109] 5 power supply device;

[0110] 51 power line.

Claims

1. An in-vehicle device comprising: a connection port mounted on a vehicle, to which an external device is connected; and a processing section that performs processing related to the external device connected to the connection port, wherein the processing section acquires device definition information from the external device connected to the connection port, and the processing section executes an authentication program corresponding to an authentication device class included in the acquired device definition information.

2. The in-vehicle device according to claim 1, wherein the external device is a USB device, the connection port is a USB port, and the USB device and the USB port comply with USB 2.0 or USB 1.

1.

3. The in-vehicle device according to claim 2, wherein the processing section executes processing corresponding to an application device class included in the device definition information acquired from the external device without imposing a function restriction, in a case where a result of execution of the authentication program corresponding to the authentication device class is a positive authentication result, and the processing section executes the processing corresponding to the application device class included in the device definition information acquired from the external device with imposing a function restriction, in a case where the result of execution of the authentication program corresponding to the authentication device class is a negative authentication result.

4. The in-vehicle device according to claim 3, wherein the processing section saves the device definition information including the authentication device class, in a case where the result of execution of the authentication program corresponding to the authentication device class is the negative authentication result.

5. The in-vehicle device according to claim 3, wherein the processing section executes the processing related to the device definition information including the application device class after executing the processing related to the device definition information including the authentication device class with respect to the external device, in a case where the external device is detected to be connected to the connection port.

6. The in-vehicle device according to claim 3, wherein the processing section determines that the external device is an authentication non-correspondence device, and executes the processing corresponding to the application device class included in the device definition information acquired from the external device with imposing a function restriction, in a case where the device definition information acquired when the external device is detected to be connected to the connection port does not include the authentication device class.

7. The in-vehicle device according to claim 3, wherein the processing section acquires state information related to a state of the vehicle, and the processing section reserves at least a part of the processing related to the device definition information transmitted from the external device, in a case where the state information indicates a running state.

8. A program that causes a computer provided with a connection port for connecting an external device mounted on a vehicle to execute the following processing: acquiring device definition information from the external device connected to the connection port, and executing an authentication program corresponding to an authentication device class included in the acquired device definition information, in a case where the authentication device class is included in the acquired device definition information.

9. An information processing method that causes a computer provided with a connection port for connecting an external device mounted on a vehicle to execute the following processing: acquiring device definition information from the external device connected to the connection port, and executing an authentication program corresponding to an authentication device class included in the acquired device definition information, in a case where the authentication device class is included in the acquired device definition information. ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ acquiring device definition information from the external device connected to the connection port, in a case where the acquired device definition information includes a device class for authentication, executing an authentication procedure corresponding to the device class for authentication.

Citation Information

Patent Citations

  • Chattering elimination circuit

    JP2017224926A

  • Music score plate-supporting structure of musical instrument

    JP2023100128A