Electronic control device, key verification method, key verification program, and key management system

JP2024044158A5Active Publication Date: 2025-06-20DENSO CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022149536
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-09-20
Publication Date
2025-06-20
Estimated Expiration
2042-09-20

AI Technical Summary

Technical Problem

Existing vehicle communication systems are vulnerable to cyberattacks, which can compromise the security of encryption keys used between electronic control devices, potentially leading to loss of vehicle control.

Method used

An electronic control device that stores encryption keys in a distributed ledger outside the vehicle and verifies them at predetermined intervals using a certificate authority, ensuring the integrity and reliability of the keys.

Benefits of technology

Enhances the security and reliability of encryption keys by making it difficult for cyberattacks to tamper with them, thereby improving the overall security of vehicle communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide an electronic control device, a key verification method, a key verification program, and a key management system that provide stronger protection means against cyber-attacks within a mobile device in order to prevent an encryption key used in communications between a plurality of electronic control devices from being tampered with by cyber attacks.SOLUTION: In an electronic control system 100, electronic control units (ECU) 11 and 12 installed in a vehicle include storage units 111 and 121 that store keys, collation units 115 and 125 that collate the key stored in the storage unit with key information that is information regarding the key stored in a distributed ledger 200 provided outside the vehicle at predetermined timing.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an electronic control device, a key matching method, a key matching program, and a key management system for matching keys used for encryption, decryption, etc. [Background technology]

[0002] In recent years, technologies that utilize V2X, such as vehicle-to-vehicle and vehicle-to-infrastructure communications, to assist vehicles in driving and control autonomous driving have been attracting attention. As a result, vehicles are equipped with communication functions, and the possibility of them being subject to cyber attacks such as hacking is increasing. Furthermore, vehicles may lose control due to cyber attacks, so stronger defense measures against cyber attacks are required.

[0003] A vehicle is equipped with multiple electronic control devices that are connected to each other via a network. Driving the vehicle, particularly driving assistance and autonomous driving control, requires the transmission and reception of information through communication between these multiple electronic control devices. As a countermeasure against cyber attacks on communication between multiple electronic control devices, for example, Patent Document 1 describes encrypting data to be communicated in communication between multiple control devices and managing the encryption key used for this encryption within the vehicle. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2019-47281 A Summary of the Invention [Problem to be solved by the invention]

[0005] Here, the present inventors have found the following problem. The driving assistance and autonomous driving control described above require highly reliable vehicle control. Therefore, more robust measures against cyber attacks in communication between multiple electronic control devices are required. Of course, the same applies to normal driving. However, if the encryption key used in communication between multiple electronic control devices is managed only within the vehicle, there is a risk that the encryption key may be tampered with by a cyber attack within the vehicle, posing a threat to the security of the network within the vehicle.

[0006] An object of the present invention is to provide an electronic control unit, a key matching method, a key matching program, and a key management system that can improve the reliability of encryption keys used in communications between electronic control units of mobile bodies. [Means for solving the problem]

[0007] The electronic control device of the present disclosure is an electronic control device mounted on a vehicle, A storage unit (111, 121, 211, 221, 311, 321, 411, 421) for storing a key; a matching unit (115, 125, 215, 225, 315, 325, 415, 425) that matches the key stored in the storage unit with key information, which is information about the key stored in a distributed ledger (200) provided outside the vehicle, at a predetermined timing; Equipped with.

[0008] In addition, the claims and the numbers in parentheses attached to the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described below, and are not intended to limit the present invention. Effect of the Invention

[0009] With the above-mentioned configuration, it is possible to improve the reliability of the encryption key used in the communication between electronic control devices of mobile bodies. [Brief description of the drawings]

[0010] [Figure 1]FIG. 1 is a diagram illustrating an example of the configuration of a key management system according to each embodiment of the present disclosure. [Diagram 2] FIG. 1 is a block diagram showing a configuration example of an electronic control system according to each embodiment of the present disclosure. [Diagram 3] FIG. 1 is a block diagram outlining features of embodiments of the present disclosure. [Figure 4] FIG. 1 is a block diagram outlining features of embodiments of the present disclosure. [Diagram 5] FIG. 1 is a block diagram showing a configuration example of an electronic control system and an electronic control device according to a first embodiment of the present disclosure. [Figure 6] A flowchart showing the operation of the electronic control device according to the first embodiment of the present disclosure. [Figure 7] A flowchart showing the operation of the electronic control device according to the first embodiment of the present disclosure. [Figure 8] FIG. 11 is a block diagram showing a configuration example of an electronic control system and an electronic control device according to a second embodiment of the present disclosure. [Figure 9] FIG. 11 is a block diagram showing a configuration example of an electronic control system and an electronic control device according to a modified example of the second embodiment of the present disclosure. [Figure 10] FIG. 11 is a block diagram showing a configuration example of an electronic control system and an electronic control device according to a third embodiment of the present disclosure. [Figure 11] FIG. 13 is a block diagram showing a configuration example of an electronic control system and an electronic control device according to a modification of the third embodiment of the present disclosure. [Figure 12] A flowchart showing the operation of an electronic control device according to a third embodiment of the present disclosure. [Figure 13] 11 is a flowchart showing the operation of an electronic control device according to a modified example of the third embodiment of the present disclosure. [Figure 14] FIG. 11 is a block diagram showing an outline of an electronic control system according to a fourth embodiment of the present disclosure. [Figure 15] FIG. 11 is a block diagram showing a configuration example of an electronic control system and an electronic control device according to a fourth embodiment of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0012] The present invention means the invention described in the claims or in the Summary of the Invention section, and is not limited to the following embodiments. Furthermore, at least the words in quotation marks mean the words described in the claims or in the Summary of the Invention section, and are not limited to the following embodiments.

[0013] The configurations and methods described in the dependent claims are optional configurations and methods in the invention described in the independent claims. The configurations and methods of the embodiments corresponding to the configurations and methods described in the dependent claims, and the configurations and methods described only in the embodiments without being described in the claims, are optional configurations and methods in the present invention. The configurations and methods described in the embodiments when the description of the claims is broader than the description of the embodiments are also optional configurations and methods in the present invention in the sense that they are examples of the configurations and methods of the present invention. In either case, by being described in the independent claims, they become essential configurations and methods of the present invention.

[0014] The effects described in the embodiments are effects obtained when the configurations of the embodiments are provided as examples of the present invention, and are not necessarily effects that the present invention possesses.

[0015] When there are multiple embodiments, the configurations disclosed in each embodiment are not limited to each embodiment, but can be combined across the embodiments. For example, a configuration disclosed in one embodiment may be combined with another embodiment. Also, configurations disclosed in each of the multiple embodiments may be collected and combined.

[0016] The problem described in the section on problems that the invention is intended to solve is not a publicly known problem, but was discovered independently by the inventor, and this, together with the configuration and method of the present invention, is a fact that affirms the inventive step of the invention.

[0017] 1. Prerequisites for each embodiment (1) Overall configuration of key management system S First, the overall configuration of the key management system S will be described with reference to FIG.

[0018] The key management system S has an electronic control system 100 “on-board” a “vehicle”, which is a moving body, a distributed ledger 200, and a certificate authority 300. Where: "Vehicle" refers to a movable object that can move at any speed. It also includes a vehicle that is stationary. Examples of the vehicle include, but are not limited to, automobiles, motorcycles, bicycles, and items mounted thereon. "Mounted" includes not only the case where the device is directly fixed to the moving body, but also the case where the device is not fixed to the moving body but moves with the moving body. For example, the case where the device is carried by a person riding on the moving body, or the case where the device is mounted on cargo placed on the moving body can be mentioned.

[0019] The electronic control system 100 includes a plurality of electronic control units (ECUs (Electric Control Units), hereinafter abbreviated as ECUs) and an in-vehicle network that connects the ECUs together. The electronic control system 100 will be described in detail later with reference to FIG.

[0020] The distributed ledger 200, also known as a shared ledger or distributed ledger technology (DLT), is digital data that is agreed to be replicated, shared, and synchronized across multiple geographically different locations, countries, institutions, etc. More specifically, a portion of a database (ledger information) is shared among multiple users, and the same ledger information is held within each user's system.

[0021] The distributed ledger 200 stores key information, which is information about the key used in the electronic control system 100, in the key management system S of each embodiment. In each embodiment, the distributed ledger 200 is provided outside the vehicle. In each embodiment, the key is expressed as key Xn (n is an integer) and the key information is expressed as key information Xn (n is an integer), but key information having the same Xn as the key means key information generated from the key Xn. Note that, for X, K indicates a common key, S indicates a private key, and P indicates a public key, but this is merely an example and other types of keys may be used.

[0022] 1, the distributed ledger 200 is illustrated as a single storage device, but in reality, the distributed ledger 200 is distributed and stored in multiple storage devices. Each storage device is realized, for example, by a server outside the vehicle or a cloud server. However, the distributed ledger 200 may be provided in the vehicle so as to be connected to the electronic control system 100, or may be provided inside the electronic control system 100.

[0023] The certification authority 300 issues a digital certificate that electronically proves the authenticity of the key. For example, the certification authority 300 verifies the identity of the key owner in some way and issues a digital certificate that guarantees the key and its owner. In particular, in the key management system S of the third and fourth embodiments, the certificate authority 300 verifies the validity of an electronic certificate in response to a request from an ECU constituting the electronic control system 100 .

[0024] The certificate authority 300 is realized, for example, by a server external to the vehicle or a cloud server. Examples of the external server or cloud server include servers installed by manufacturers or sellers of the vehicle or the electronic control system 100.

[0025] In addition, in FIG. 1, the distributed ledger 200 and the certificate authority 300 are realized as separate devices, but the distributed ledger 200 and the certificate authority 300 may be realized on the same server or cloud server.

[0026] The electronic control system 100 and the distributed ledger 200, and the electronic control system 100 and the certificate authority 300 are connected via a communication network using a wireless communication method and / or a wired communication method. Examples of wireless communication methods include IEEE802.11 (Wi-Fi (registered trademark)), IEEE802.16 (WiMAX (registered trademark)), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed ​​Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, 5G, etc. Alternatively, DSRC (Dedicated Short Range Communication) can be used. Examples of wired communication methods include a LAN (Local Area Network) such as Ethernet (registered trademark), the Internet, an optical fiber line, and a fixed telephone line. When the vehicle is parked in a parking lot or in a repair shop, a wired communication method can be used instead of a wireless communication method.

[0027] Alternatively, the communication line may be a combination of a wireless communication line and a wired communication line. For example, the electronic control system 100 and a base station device in a cellular system may be connected by a wireless communication method such as 4G, and the base station device and the distributed ledger 200 or the certificate authority 300 may be connected by a wired communication method such as a trunk line of a telecommunications carrier or the Internet. A gateway device may be provided at the point of contact between the trunk line and the Internet. In addition, communication between the distributed ledger 200 and the certification authority 300 can be carried out using any line, including the Internet.

[0028] (2) Overall Configuration of Electronic Control System 100 Fig. 2 is a diagram showing an example of the configuration of the electronic control system 100. The electronic control system 100 is composed of multiple ECUs including an external communication ECU and an integrated ECU. Fig. 2 illustrates one external communication ECU, one integrated ECU, and four individual ECUs, but the electronic control system 100 may naturally be composed of any number of ECUs. Hereinafter, the term "ECU" will be used to collectively refer to the external communication ECU, the integrated ECU, and the individual ECUs.

[0029] The external communication ECU is an ECU that communicates with the outside. The communication method used by the external communication ECU is as described above in the wireless communication method and the wired communication method. Note that in order to realize a plurality of communication methods, a plurality of external communication ECUs may be provided.

[0030] The integrated ECU is an ECU equipped with a gateway function that mediates between the individual ECUs and the external communication ECU. The integrated ECU may also be provided with a function for controlling the entire electronic control system 100, such as a security function. The integrated ECU may also be called a gateway ECU (G-ECU) or a mobility computer (MC). The integrated ECU may also be a relay device or a gateway device.

[0031] The individual ECUs of the electronic control system 100 can be configured with ECUs having any desired functions. For example, they can be drive system electronic control devices that control the engine, steering, brakes, etc., vehicle body electronic control devices that control meters, power windows, etc., information system electronic control devices such as navigation devices, or safety control system electronic control devices that perform control to prevent collisions with obstacles or pedestrians. Furthermore, the ECUs may not be parallel to each other, but may be classified as master and slave.

[0032] Furthermore, the ECU may be a physically independent ECU, or may be a virtual ECU (also called a virtual machine) that is virtually realized.

[0033] 2, the ECUs are connected to each other via an in-vehicle communication network such as a Controller Area Network (CAN) or a Local Interconnect Network (LIN). Alternatively, the ECUs may be connected to each other using any communication method, whether wired or wireless, such as Ethernet (registered trademark), Wi-Fi (registered trademark), or Bluetooth (registered trademark). In addition, a connection refers to a state in which data can be exchanged, and includes not only cases in which different hardware is connected via a wired or wireless communication network, but also cases in which virtual machines realized on the same hardware are virtually connected to each other.

[0034] (3) Overview of each embodiment 3 and 4 are diagrams showing an outline of the features of each embodiment. 3A corresponds to the first embodiment. In the first embodiment, the ECU 11 and the ECU 12 check the common key used when transmitting and receiving data between the ECU 11 and the ECU 12 against key information stored in the distributed ledger 200. 3(b1) and (b2) correspond to embodiment 2. In embodiment 2, the ECU 21 or the ECU 22 collates a public key used when transmitting and receiving data between the ECU 21 and the ECU 22 with key information stored in the distributed ledger 200. Figures 4(c1) and (c2) correspond to embodiment 3. In embodiment 3, in addition to the configuration of embodiment 2 shown in Figures 3(b1) and (b2), ECU 31 or ECU 32 verifies the validity of the electronic certificate with a certificate authority. The features of the fourth embodiment will be described separately with reference to FIG.

[0035] 2. Embodiment 1 (1) Configuration of electronic control units (ECUs) 11 and 12 The configurations of the ECU 11 and the ECU 12 in this embodiment will be described with reference to Fig. 5. This embodiment corresponds to Fig. 3(a).

[0036] The ECU 11 and the ECU 12 may be any combination of the ECUs shown in FIG. 2, but in this embodiment, they are individual ECUs connected via an integrated ECU. The ECU 11 includes a storage unit 111, a control unit 112, a transmission unit 113, and a reception unit 114. The control unit 112 includes a collating unit 115. The ECU 12 includes a storage unit 121, a control unit 122, a transmission unit 123, and a reception unit 124. The control unit 122 includes a collating unit 125.

[0037] The ECUs 11 and 12 can be configured with a general-purpose CPU (Central Processing Unit), a volatile memory such as a RAM, a non-volatile memory such as a ROM, a flash memory, or a hard disk, various interfaces, and an internal bus connecting these. The ECUs can be configured to perform the functions of the functional blocks shown in Fig. 5 by executing software on these pieces of hardware. Of course, the ECUs 11 and 12 may be realized by dedicated hardware such as an LSI. The same applies to the ECUs of the other embodiments.

[0038] In this embodiment, the ECUs 11 and 12 are assumed to be in the form of semi-finished electronic control devices, but are not limited thereto. For example, the form of parts may be a semiconductor circuit or a semiconductor module, and the form of finished products may be a personal computer (PC), a smartphone, a mobile phone, or a navigation system. The same applies to ECUs in other embodiments.

[0039] In the following, the blocks of ECU 12 corresponding to the blocks of ECU 11 will be described as representative of ECU 11, except in cases where the blocks have different operations or functions, and the descriptions of the blocks of ECU 11 will be quoted for the blocks of ECU 12.

[0040] The storage units 111 and 121 store common keys K1 and K2 as "keys," respectively. Common keys K1 and K2 are the same key, but are stored in different storage units, and may become different keys if one of them is tampered with. Therefore, different symbols are used here to distinguish between them. Here, a "key" is data for controlling the procedure of a cryptographic algorithm, and is used not only for encryption, but also for digital signatures, message authentication codes (such as keyed-hash), and the like. A seed used in pseudo-random numbers is also a type of key. The "key" stored in the memory unit may be a key used by this electronic control device, or a key used by another electronic control device, etc. Examples of "keys" include common keys, secret keys, and public keys. The key may be a newly generated key, or a new key obtained by updating an old key. The key may have an expiration date.

[0041] The control unit 112 controls the operations of the storage unit 111, the transmission unit 113, and the reception unit 114. The control unit 112 also realizes a matching unit 115 by itself. In addition, the control unit 112 uses the common key K1 read from the storage unit 111 to decrypt encrypted data transmitted from the ECU 12 to the ECU 11, generate a message authentication code, and compare it with a received message authentication code. The control unit 122 uses the common key K2 read from the storage unit 121 to encrypt data to be transmitted from the ECU 12 to the ECU 11 and to generate a message authentication code.

[0042] The transmission unit 113 transmits data and the like to each ECU of the electronic control system 100, including the ECU 12. It also transmits data and the like to the distributed ledger 200 and other devices via the external communication ECU.

[0043] The receiving unit 114 receives data and the like from each ECU of the electronic control system 100, including the ECU 12. It also receives data and the like from the distributed ledger 200 and other devices via the external communication ECU.

[0044] The matching unit 115 "matches" the common key K1 stored in the memory unit 111 with the "key information" K1 stored in the distributed ledger 200 at a "predetermined timing". The matching unit 125 similarly "matches" the common key K2 stored in the memory unit 121 with the "key information" K2 stored in the distributed ledger 200 at a "predetermined timing". The matching result by the matching unit 115 may be stored in the memories 111 and 121. Details of the matching unit 115 will be explained in the next section. Where: The "predetermined timing" may be a time index based on a predetermined rule, and may be expressed, for example, as time, duration, clock count, counter, cycle, or frequency. In addition to a fixed value, it may be a variable value that varies depending on conditions. The "key information" may be information about the key itself, or it may be the key itself. "Matching" includes not only directly verifying the identity of keys, but also indirectly verifying whether key information, which is information about a key, originates from the key.

[0045] (2) Details of the collation unit 115 (a) Reason for Providing the Collation Unit 115 The control unit 122 of the ECU 12 encrypts data to be transmitted to the ECU 11 using the common key K2 read from the storage unit 121. The transmission unit 123 transmits the encrypted data to the ECU 11 via the integrated ECU. The reception unit 114 of the ECU 11 receives the encrypted data. The control unit 112 then decrypts the encrypted data using the common key K1 read from the storage unit 111.

[0046] When transmitting and receiving such data, if the common key K1 has been tampered with by hacking or the like, the originally required data cannot be decrypted. Furthermore, if the common key K1 and the common key K2 have been tampered with by hacking or the like, there is a possibility that counterfeit data will be decrypted and used. To prevent this, in this embodiment, the common key K1 is compared with the key information K1 stored in the distributed ledger 200 to check whether it has been rewritten by hacking or the like.

[0047] By managing the common key K1 using the distributed ledger 200 provided outside the electronic control system 100, rather than managing the common key K1 only within the electronic control system 100, it becomes difficult to tamper with the common key K1. That is, to tamper with the common key K11, not only hacking the electronic control system 100 but also hacking the distributed ledger 200 is required. Furthermore, by storing the key information K1 in the distributed ledger 200 instead of in a normal server or a cloud server, in light of the characteristics of the blockchain, the key information K1 becomes more difficult to tamper with, and even if it is tampered with, the tampering can be easily detected.

[0048] (b) Key information stored in the distributed ledger 200 The key information K1 stored in the distributed ledger 200 is information related to the key K1. The key information K1 may be any information sufficient to verify the identity of the key K1. For example, the key information K1 may be the serial number of the common key K1, the MAC value of the serial number, the MAC value of the common key K1, or attribute information of the common key K1. Of course, the key information K1 may be the common key K1 itself.

[0049] The method of registering the key information K1 in the distributed ledger 200, i.e., the method of storing the key information K1 in the distributed ledger 200, is arbitrary, but several examples will be described below.

[0050] As a first example, the ECU 11 itself may transmit the key information K1 to the distributed ledger 200. That is, the control unit 112 may read the common key K1 from the storage unit 111 and transmit the common key K1 from the transmission unit 113, or the control unit 112 may obtain and transmit the serial number of the common key K1, the MAC value of the common key, or the like. When transmitting, the information may be transmitted directly to the distributed ledger 200, or indirectly to the distributed ledger 200. That is, the information may be transmitted from the transmitter 113 to another ECU in the electronic control system 100 (for example, a DCM (Data Communication Module) or another ECU in a moving body, etc.), and the information may be transmitted from the other ECU to the distributed ledger 200. The information may also be transmitted via another external device such as a server, relay device, or certificate authority 300. The distributed ledger that receives the key information K1 may store the received key information K1 as is, or may calculate and store, for example, the serial number of the common key K1 or the MAC value of the common key K1 from the received common key K1.

[0051] As a second example, when a vehicle is registered or repaired, a vehicle manufacturer, dealer, repair shop, etc. may write the common key K1 and key information K1 to the ECU 11 and the distributed ledger 200 from a computer or the like that they manage.

[0052] As a third example, an integrated ECU or the like of the electronic control system 100 may transmit the common key K1 and the key information K1 to the ECU 11 and the distributed ledger.

[0053] (c) Mode of collation The common key K1 stored in the memory unit 111 may be collated with the key information K1 stored in the distributed ledger by the ECU 11 itself, or by another device.

[0054] When performed by the ECU 11 itself, the control unit 112 reads out the common key K1 from the memory unit 111, and the receiving unit 114 receives the key information K1 sent from the distributed ledger 200 in response to a request for key information sent from the transmitting unit 113 based on an instruction from the control unit 112. Then, the collation unit 115 compares the common key K1 with the key information K1, and verifies whether the common key K1 has been tampered with based on the presence or absence of common points that the common key K1 and the key information K1 should have.

[0055] As an example of a case where another device performs the matching, a device that manages the distributed ledger 200 may perform the matching. Based on an instruction from the control unit 112 of the ECU 11, the transmission unit 113 generates and transmits key information K1 from the common key K1 stored in the memory unit 111. The device that manages the distributed ledger 200 then performs the matching by comparing the key information K1 stored in the distributed ledger 200 with the key information K1 transmitted from the ECU 11, and transmits the result to the ECU 11. The ECU 11 receives the result at the receiving unit 114, and checks the result at the matching unit 115. Examples of devices other than the device that manages the distributed ledger 200 include other external devices and other ECUs other than ECU 11, including ECU 12.

[0056] (d) Timing of collation In order to detect tampering caused by cyber attacks, it is desirable for the ECU 11 to perform a comparison every time it receives encrypted data from the ECU 12 . However, the number of communications between ECUs mounted in the electronic control system 100 is very high, for example, 10 or more times per second. In addition, since a vehicle mounted with the electronic control system 100 moves, communication with the outside is not always stable. Therefore, if the distributed ledger 200 is checked every time communication between ECUs is performed, the communication volume increases and the communication line becomes saturated, which may make it difficult to perform the check itself. In addition, since communication with the outside world is not performed while the vehicle is parked, verification is impossible. Therefore, it is desirable to perform verification as soon as communication with the outside world is restored. Therefore, the collation unit 115 performs the collation at a predetermined timing. The predetermined timing will be exemplified below.

[0057] Example 1 When the electronic control system 100 mounted on the vehicle is capable of communicating with the outside while the vehicle is traveling, the ECU 11 performs a check once or multiple times at every predetermined time (corresponding to a "first predetermined time"), or once or multiple times at every predetermined number of communications (corresponding to a "first predetermined time") between the ECU 11 and other ECUs in the electronic control system 100. In other words, the check may be performed either in synchronization with the timing of the communications between the ECU 11 and other ECUs, or asynchronously. The above configuration makes it possible to prevent an increase in the amount of communication with the distributed ledger 200 and saturation of the communication line, thereby enabling more stable matching of the common key K1.

[0058] Moreover, the predetermined time or the predetermined number of communications may be determined according to the speed of the vehicle. In other words, it may change according to the speed of the vehicle. When the vehicle speed is fast, the amount of communication between the ECUs is generally large, and when the vehicle speed is slow, the amount of communication between the ECUs is generally small. Therefore, the faster the vehicle speed, the shorter the predetermined time may be. For example, when the speed is fast (e.g., 40 km / h or more), the predetermined time may be 1 second, and when the speed is slow (e.g., 10 km / h or less), the predetermined time may be 3 seconds. Alternatively, the predetermined time may be determined by dividing it into categories such as low speed, medium speed, and high speed. The number of categories is arbitrary. Alternatively, the predetermined time may be changed continuously without dividing it. The above configuration can reduce and equalize the risk of cyber attacks and the damage caused by them, and in particular, can prevent excessive use of resources required for communication with the outside world.

[0059] Example 2 When the electronic control system 100 mounted on the vehicle has not communicated with the outside for a predetermined time (corresponding to the "second predetermined time") or more, the matching is performed within a predetermined time (corresponding to the "third predetermined time") after communication with the outside is resumed. Examples of resumption of communication include the start of communication after a communication interruption is resolved, as well as the start of communication accompanying startup of the vehicle, such as starting the engine. It also includes the start of communication with a new external device. The second predetermined time is an arbitrary time, such as 5 minutes or 10 minutes. The third predetermined time is, for example, within an arbitrary time, such as within 1 second or within 3 seconds, from the start of communication with the outside, and the shorter the time, the better. With the above configuration, matching can be performed quickly when communication is restored after a communication blackout when matching is not possible, or when starting up a vehicle whose system is unstable and vulnerable to cyber attacks.

[0060] Example 3 When the electronic control system 100 mounted on the vehicle is capable of communicating with the outside during parking of the vehicle, it is every predetermined time (corresponding to the "fourth predetermined time"). During parking of the vehicle, the engine is turned off. During parking of the vehicle, the vehicle is often unattended, and in contrast to cyber attacks, there is a risk of attacks such as hacking by suspicious people through physical connections. Therefore, it is desirable to periodically perform the verification even during parking of the vehicle. The fourth predetermined time is an arbitrary time such as one hour or two hours. Unlike during driving of the vehicle, the risk of losing control of the vehicle is low, so the fourth predetermined time can be set to a time longer than the first predetermined time or the second predetermined time. Since communication is necessary even when the engine is turned off, it is desirable to perform communication using a communication method with low power consumption such as LPWA (Low Power Wide Area). With the above configuration, even when the vehicle is parked, it is possible to perform a comparison while anticipating the possibility of an attack on the electronic control system 100.

[0061] (e) Vehicle communication status The predetermined timing may be determined according to the communication state of the vehicle. The communication state of the vehicle may change depending on, for example, the running state including stopping and parking of the vehicle, the running location, the running speed, etc. In addition, when a plurality of wireless communication methods are used for communication with the outside, the wireless communication method to be used may be changed. For example, the frequency of matching when a line with a high communication speed is used may be set to be higher than the frequency of matching when a line with a low communication speed is used, thereby making it possible to avoid saturation of the communication line. Alternatively, the frequency of matching may be set higher when a free or low-cost line is used than when a high-cost line is used. Alternatively, when the same line is used continuously, the frequency of matching may be changed according to the response speed, signal-to-noise ratio, or radio wave reception strength of the line.

[0062] (f) Verification in electronic control systems The above explanation focuses on the ECU 11, but as shown in Fig. 2, the electronic control system 100 mounted on a vehicle is usually composed of multiple ECUs. Each ECU included in the electronic control system 100 individually performs the above-mentioned verification. However, it is not necessarily required that all ECUs included in the electronic control system 100 perform the verification.

[0063] The predetermined timing for each ECU may be different. For example, it is desirable to set the frequency of the predetermined timing of the external communication ECU (corresponding to the "first electronic control unit"), which is the entry point, higher than the frequency of the predetermined timing of other ECUs (corresponding to the "second electronic control unit"). This makes it possible to increase the security level of the external communication ECU, which is at high risk of cyber attacks. Alternatively, it is desirable to set the frequency of the predetermined timing of the ECU that controls autonomous driving and the drive system ECU (corresponding to the "first electronic control unit") higher than the frequency of the predetermined timing of other ECUs (corresponding to the "second electronic control unit"). This can prevent the danger of cyber attacks from becoming apparent. Alternatively, it is desirable to set the frequency of a predetermined timing in an ECU (corresponding to a "first electronic control unit") that has a large amount of communication or a large frequency of communication within the vehicle higher than the frequency of a predetermined timing in other ECUs (corresponding to "second electronic control units"). For example, the integrated ECU has a gateway function, and therefore has a larger amount of communication than other ECUs. This can increase the reliability of each communication within the vehicle.

[0064] (g) Other In the above description of the collation unit 115, the common key K1 is used to decrypt encrypted data, but it may be used for other purposes such as message authentication. Furthermore, the matching may be performed synchronously or asynchronously with the transmission and reception of data. Furthermore, the above explanation of the comparison unit 115 has focused on the ECU 11 and the common key K1 that decrypt the encrypted data, but the same applies to the ECU 12 and the common key K2 that encrypt the data, and in this case, the explanation should be read as the ECU 12 and the common key K2. A vehicle ID for identifying a vehicle and an ECU ID for identifying an ECU may be stored together with the key information in the distributed ledger 200. Then, when obtaining the key information from the distributed ledger, the vehicle ID and the ECU ID may be specified. The above description of the collation unit 115 can be applied not only to this embodiment but also to other embodiments. In the other embodiments, a private key and a public key are used, so the description of the common key K1 should be read as a public key Pn (n is an integer).

[0065] (3) Operation of electronic control units (ECUs) 11 and 12 The operation of verifying the common key K1 and decrypting received data in the ECU 11 of this embodiment will be described with reference to the flowchart of FIG. Note that the following operations not only show the key matching method executed by the ECU 11, but also show the processing procedure of a key matching program that can be executed by the ECU 11. The order of these processes is not limited to the order shown in Fig. 6. In other words, the order may be changed as long as there are no constraints such as a relationship in which a certain step uses the result of the previous step. The same applies to the flowcharts other than Fig. 6 in all the embodiments described above.

[0066] The ECU 11 stores the common key K1 in the storage unit 111 (S111). The transmission unit 113 of the ECU 11 transmits the key information K1, which is information related to the common key K1 stored in the memory unit 111, to the distributed ledger 200 (S112). Thereafter, at any timing, the receiving unit 114 of the ECU 11 receives the encrypted data (S113). For example, when the common keys K1 and K2 are the same key, the receiving unit 114 of the ECU 11 receives the data encrypted by the ECU 12 using the common key K2.

[0067] The collation unit 115 determines whether it is a predetermined timing (S114). If it is determined that it is a predetermined timing (S114: YES), the transmission unit 113 transmits a request for key information to the distributed ledger 200, and the reception unit 114 receives the key information K1 transmitted from the distributed ledger 200 (S115). The collation unit 115 collates the common key K1 read from the storage unit 111 with the key information K1 received from the distributed ledger 200 (S116). If it is determined that the common key K1 has not been tampered with (S117: YES), the encrypted data received in S113 is decrypted using the common key K1 (S118). If it is determined that the common key K1 has been tampered with (S117: NO), the encrypted data received in S113 is not decrypted (S119). Furthermore, if it is not determined that the predetermined timing has arrived (S114: NO), the encrypted data received in S113 is decrypted (S118).

[0068] As already mentioned, it is not necessarily the ECU 11 that transmits the key information K1, which is information related to the common key K1, to the distributed ledger 200, so S112 is an optional step in this embodiment. Moreover, the decryption may involve decrypting all of the data transmitted between the ECUs, or it may involve decrypting only a portion of the data, for example, the data portion of an Ethernet frame. 6, the predetermined timing is synchronized with the decryption of the encrypted data, but they may be asynchronous. For example, the collation result by the collation unit 115 may be stored in the storage unit 111, and when the encrypted data is decrypted using the common key K1, the collation result may be read from the storage unit 111, and the control unit 112 may determine whether or not to use the common key K1 based on the collation result.

[0069] The operation of verifying the common key K2 and encrypting transmission data in the ECU 12 of this embodiment will be described with reference to the flowchart of FIG.

[0070] The ECU 12 stores the common key K2 in the storage unit 121 (S121). The transmission unit 123 of the ECU 12 transmits the key information K2, which is information related to the common key K2 stored in the storage unit 121, to the distributed ledger 200 (S122).

[0071] The collation unit 125 determines whether it is a predetermined timing (S123). If it is determined that it is a predetermined timing (S123: YES), the transmission unit 123 transmits a request for key information to the distributed ledger 200, and the reception unit 124 receives the key information K2 transmitted from the distributed ledger 200 (S124). The collation unit 125 collates the common key K2 read from the storage unit 121 with the key information K2 received from the distributed ledger 200 (S125). If it is determined that the common key K2 has not been tampered with (S126: YES), the data is encrypted using the common key K2 and transmitted (S127). If it is determined that the common key K2 has been tampered with (S126: NO), the data is not encrypted or transmitted (S128). Furthermore, if it is not determined that the predetermined timing has arrived (S123: NO), the data is encrypted and transmitted (S127).

[0072] As already mentioned, it is not necessarily the ECU 12 that transmits the key information K2, which is information related to the common key K2, to the distributed ledger 200, so S122 is an optional step in this embodiment. Further, the encryption may encrypt all data transmitted between ECUs, or may encrypt only a portion of the data, for example, the data portion of an Ethernet frame. 7, the encryption and transmission of data are synchronized with the predetermined timing, but they may be asynchronous. For example, the collation result by the collation unit 125 may be stored in the storage unit 121, and when encrypting data using the common key K2, the collation result may be read from the storage unit 121, and the control unit 122 may determine whether to use the common key K2 based on the collation result.

[0073] (4) Summary As described above, according to this embodiment, the key information K1 and the key information K2 are stored in the distributed ledger and compared with the common key K1 and the common key K2, so that tampering of the common key K1 and the common key K2 can be detected more accurately. Furthermore, according to this embodiment, the common key K1 is compared with the key information K1, and the common key K2 is compared with the key information K2 at a predetermined timing, which prevents the communication line from becoming saturated due to an increase in the amount of communication with the distributed ledger 200, and allows for more stable comparison of the common key K1 and the common key K2. As a result, the security of the common key K1 and the common key K2 can be ensured.

[0074] 3. Embodiment 2 (1) Configuration of Electronic Control Units (ECUs) 21 and 22 In the first embodiment, data is transmitted and received using a common key in the electronic control system 100. This embodiment differs from the first embodiment in that a private key and a public key are used instead of the common key. Only the differences from the first embodiment will be explained below, and the explanation of the first embodiment will be quoted for the parts that are the same as the first embodiment.

[0075] The configurations of the ECU 21 and the ECU 22 in this embodiment will be described with reference to Fig. 8. This embodiment corresponds to Fig. 3(b1).

[0076] The ECU 21 and the ECU 22 may be any combination of ECUs shown in FIG. 2, but in this embodiment, the ECUs are individual ECUs connected via an integrated ECU. The ECU 21 includes a storage unit 211 , a control unit 212 , a transmission unit 213 , and a reception unit 214 . The ECU 22 includes a storage unit 221, a control unit 222, a transmission unit 223, and a reception unit 224. The control unit 222 includes a collation unit 225.

[0077] Storage unit 221 stores public key P2. Storage unit 211 stores private key S1 and public key P1. Public key P2 and public key P1 are the same key, but are stored in different storage units, and may become different keys if one of them is tampered with, so different symbols are used here to distinguish them.

[0078] In this embodiment, the ECU 21 generates a public key P1 using the private key S1. Then, the transmission unit 213 transmits the public key P1 to the ECU 22, and the reception unit 224 of the ECU 22 receives the public key P1. The ECU 22 that has received the public key stores the public key P1 in the storage unit 221 as a public key P2.

[0079] In this embodiment, the control unit 222 of the ECU 22 encrypts data to be transmitted to the ECU 21 using the public key P2 read from the storage unit 221. The transmission unit 223 transmits the encrypted data to the ECU 21 via the integrated ECU. The reception unit 214 of the ECU 21 receives the encrypted data. Then, the control unit 212 decrypts the encrypted data using the private key S1 read from the storage unit 211.

[0080] At a predetermined timing, the matching unit 225 of the ECU 22 matches the public key P2 stored in the memory unit 221 with the key information P2 stored in the distributed ledger 200. Details of the matching unit 225 are similar to the details of the matching unit 115 described in the first embodiment, except that the matching unit 225 uses the public key P2 and the key information P2. Therefore, the description of the first embodiment will be quoted under the premise of this embodiment, and a description thereof will be omitted. Of course, the ECU 21 also has a public key P1, but the purpose is to distribute it to other ECUs, etc., and the ECU 21 does not normally use the public key P1. Therefore, no matching unit is provided in the control unit 212. However, as in the first embodiment, the ECU 21 may also be provided with a matching unit 215, which can match the public key P1 stored in the memory unit 211 with the key information P1 stored in the distributed ledger 200.

[0081] The operation of the ECU 22 is similar to that of the ECU 12 in the first embodiment and FIG. 7, so the description of the first embodiment will be quoted and reinterpreted on the premise of this embodiment, and a description thereof will be omitted.

[0082] (2) Variations FIG. 9 shows the configuration of the ECU 21 and the ECU 22 in a modified example of this embodiment, and corresponds to FIG. 3(b2).

[0083] The ECU 21 and the ECU 22 may be any combination of ECUs shown in FIG. 2, but in this embodiment, the ECUs are individual ECUs connected via an integrated ECU. The ECU 21 includes a storage unit 211, a control unit 212, a transmission unit 213, and a reception unit 214. The control unit 212 includes a collating unit 215. The ECU 22 includes a storage unit 221 , a control unit 222 , a transmission unit 223 , and a reception unit 224 .

[0084] Storage unit 221 stores private key S1 and public key P1. Storage unit 211 stores public key P2. Public key P1 and public key P2 are the same key, but are stored in different storage units and may become different keys if one of them is tampered with, so different symbols are used here to distinguish them.

[0085] In this modification, the ECU 22 generates a public key P1 using the private key S1. Then, the transmitter 223 transmits the public key P1 to the ECU 21, and the receiver 214 of the ECU 21 receives the public key P1. The ECU 21, having received the public key, stores the public key P1 in the memory 211 as a public key P2.

[0086] In this embodiment, the control unit 222 of the ECU 22 generates an electronic signature for data to be transmitted to the ECU 21, using the private key S1 read from the storage unit 221. The transmission unit 223 transmits the data and the electronic signature to the ECU 21 via the integrated ECU. The reception unit 214 of the ECU 21 receives the data and the electronic signature. The control unit 212 then decrypts the electronic signature, using the public key P2 read from the storage unit 211.

[0087] At a predetermined timing, the matching unit 215 of the ECU 21 matches the public key P2 stored in the memory unit 211 with the key information P2 stored in the distributed ledger 200. Details of the matching unit 215 are similar to the details of the matching unit 115 described in the first embodiment, except that the matching unit 215 uses the public key P2 and the key information P2. Therefore, the description of the first embodiment will be quoted under the premise of this embodiment, and the description will be omitted. Of course, the ECU 22 also has a public key P1, but the purpose is to distribute it to other ECUs, etc., and the ECU 22 does not normally use the public key P1. Therefore, a matching unit is not provided in the control unit 222. However, as in the first embodiment, the ECU 22 may also be provided with a matching unit 225, which can match the public key P1 stored in the memory unit 221 with the key information P1 stored in the distributed ledger 200.

[0088] The operation of the ECU 21 is similar to that of the ECU 11 in the first embodiment and FIG. 6, so the description of the first embodiment will be quoted and reinterpreted on the premise of this embodiment, and a description thereof will be omitted.

[0089] (3) Summary As described above, according to this embodiment, the key information K1 and the key information K2 are stored in the distributed ledger and compared with the common key K1 and the common key K2, so that tampering of the common key K1 and the common key K2 can be detected more accurately. In addition, since the public key P2 is compared with the key information P2 at a predetermined timing, it is possible to prevent an increase in the amount of communication with the distributed ledger 200 and saturation of the communication line, and it is possible to more stably compare the public key P2. As a result, it is possible to ensure the security of the public key P2.

[0090] 4. Embodiment 3 (1) Configuration of Electronic Control Units (ECUs) 31, 32 In this embodiment, in addition to the public key verification in embodiment 2, an electronic certificate for the public key is issued and the validity of the electronic certificate is confirmed. Below, only the parts added to embodiment 2 and the parts different from embodiment 2 will be explained, and the explanation of embodiment 2 will be quoted for the parts that are the same as embodiment 2.

[0091] The configurations of the ECU 31 and the ECU 32 in this embodiment will be described with reference to Fig. 10. This embodiment corresponds to Fig. 4(c1).

[0092] The ECU 31 and the ECU 32 may be any combination of ECUs shown in FIG. 2, but in this embodiment, they are individual ECUs connected via an integrated ECU. The ECU 31 includes a storage unit 311 , a control unit 312 , a transmission unit 313 , and a reception unit 314 . The ECU 32 includes a storage unit 321, a control unit 322, a transmission unit 323, and a reception unit 324. The control unit 322 includes a collation unit 325 and a validity confirmation unit 326.

[0093] Storage unit 321 stores public key P2. Storage unit 311 stores private key S1 and public key P1. Public key P2 and public key P1 are the same key, but are stored in different storage units, and may become different keys if one of them is tampered with, so different symbols are used here to distinguish them.

[0094] In this embodiment, similarly to the second embodiment, the ECU 31 generates a public key P1 by using the private key S1. Then, the transmission unit 313 transmits the public key P1 to the ECU 32, and the reception unit 324 of the ECU 32 receives the public key P1. The ECU 32 that has received the public key stores the public key P1 in the storage unit 321 as a public key P2.

[0095] Furthermore, in this embodiment, the ECU 31 transmits the generated public key P1 from the transmission unit 313 to the certificate authority 300, and the certificate authority 300 issues a digital certificate for the public key P1 and transmits it to the ECU 31. The digital certificate is a certificate that guarantees the public key P1 and the device that owns it. The reception unit 314 of the ECU 31 receives the public key P1 with the digital certificate attached, and stores the digital certificate in the memory unit 311. The transmission unit 313 of the ECU 31 then transmits the digital certificate to the ECU 32, and the reception unit 324 of the ECU 32 receives the digital certificate. The ECU 32 that has received the digital certificate stores the digital certificate in the memory unit 321. The electronic certificate may be sent from the ECU 31 to the ECU 32 at the same time as the public key P1 is sent. Furthermore, the electronic certificate may be sent only once at the beginning, or may be sent periodically.

[0096] The method of storing the key information P2 in the distributed ledger 200 can be the method exemplified in embodiment 1, but it is also possible for the certification authority 300 to transmit the public key P1 to the distributed ledger 200, which then generates and stores the key information P2. Alternatively, the certification authority 300 may generate and transmit the key information P2 from the public key P1, and the distributed ledger 200 may then store the key information P2.

[0097] In this embodiment, the control unit 322 of the ECU 32 encrypts data to be transmitted to the ECU 31 using the public key P2 read from the storage unit 321. The transmission unit 323 transmits the encrypted data to the ECU 31 via the integrated ECU. The reception unit 314 of the ECU 31 receives the encrypted data. Then, the control unit 312 decrypts the encrypted data using the private key S1 read from the storage unit 311.

[0098] The matching unit 325, at a predetermined timing, matches the public key P2 stored in the storage unit 321 with the key information P2 stored in the distributed ledger 200. Details of the matching unit 325 are similar to the details of the matching unit 115 described in the first embodiment, except that the matching unit 325 uses the public key P2 and the key information P2. Therefore, the description of the first embodiment will be quoted under the premise of this embodiment, and the description will be omitted.

[0099] The validity checking unit 326 checks the validity of the electronic certificate received from the ECU 31. Specifically, the validity checking unit 326 transmits a confirmation signal from the transmission unit 323 to the certificate authority 300, inquiring about the validity of the electronic certificate of the public key P2. Then, upon receiving the confirmation signal, the certificate authority 300 checks the validity of the electronic certificate indicated in the confirmation signal and sends the confirmation result to the ECU 32. The validity check includes, for example, checking the authenticity of the electronic certificate as well as the expiration date of the electronic certificate. The reception unit 324 of the ECU 32 receives the confirmation result.

[0100] It is desirable that the “frequency” of validity confirmation by the validity confirmation unit 326 is lower than the “frequency” of the predetermined timing of collation by the collation unit 325 . Here, the "frequency" may directly or indirectly indicate the number of times information is transmitted within a given period of time, and may be indicated by a period, time, or the like in addition to the number of times.

[0101] For example, the frequency of the validation check can be set to coincide with the vehicle's legal inspection or vehicle inspection, or can be set to a relatively long period such as once a year. The frequency of the validation check can also be set arbitrarily, or can be set to the first time when the vehicle is started or when the vehicle is delivered. Alternatively, if a problem is detected in the collation by the collation unit 325, a validity check may be performed.

[0102] (2) Variations FIG. 11 shows the configuration of the ECU 31 and the ECU 32 in a modified example of this embodiment, and corresponds to FIG. 4(c2).

[0103] The ECU 31 and the ECU 32 may be any combination of ECUs shown in FIG. 2, but in this embodiment, they are individual ECUs connected via an integrated ECU. The ECU 31 includes a storage unit 311, a control unit 312, a transmission unit 313, and a reception unit 314. The control unit 312 includes a collation unit 315 and a validity confirmation unit 316. The ECU 32 includes a storage unit 321 , a control unit 322 , a transmission unit 323 , and a reception unit 324 .

[0104] Storage unit 321 stores private key S1 and public key P1. Storage unit 311 stores public key P2. Public key P1 and public key P2 are the same key, but are stored in different storage units and may become different keys if one of them is tampered with, so different symbols are used here to distinguish them.

[0105] In this embodiment, similarly to the modified example of the second embodiment, the ECU 32 generates a public key P1 by using the private key S1. Then, the transmission unit 323 transmits the public key P1 to the ECU 31, and the reception unit 314 of the ECU 31 receives the public key P1. The ECU 31 that has received the public key stores the public key P1 in the storage unit 311 as a public key P2.

[0106] Furthermore, in this embodiment, the ECU 32 transmits the generated public key P1 from the transmission unit 323 to the certificate authority 300, and the certificate authority 300 issues a digital certificate for the public key P1 and transmits it to the ECU 32. The digital certificate is a certificate that guarantees the public key P1 and the device that owns it. The reception unit 324 of the ECU 32 receives the public key P1 with the digital certificate attached, and stores the digital certificate in the memory unit 321. The transmission unit 323 of the ECU 32 then transmits the digital certificate to the ECU 31, and the reception unit 314 of the ECU 31 receives the digital certificate. The ECU 31 that has received the digital certificate stores it in the memory unit 311. The ECU 32 may transmit the electronic certificate to the ECU 31 at the same time as transmitting the public key P1. The electronic certificate may be sent only once at the beginning, or periodically.

[0107] The method of storing the key information P2 in the distributed ledger 200 can be the method exemplified in embodiment 1, but it is also possible for the certification authority 300 to transmit the public key P1 to the distributed ledger 200, which then generates and stores the key information P2. Alternatively, the certification authority 300 may generate and transmit the key information P2 from the public key P1, and the distributed ledger 200 may then store the key information P2.

[0108] In this embodiment, the control unit 322 of the ECU 32 generates an electronic signature for data to be transmitted to the ECU 31, using the private key S1 read from the storage unit 321. The transmission unit 323 transmits the data and the electronic signature to the ECU 31 via the integrated ECU. The reception unit 314 of the ECU 31 receives the data and the electronic signature. The control unit 312 then decrypts the electronic signature, using the public key P1 read from the storage unit 311.

[0109] The matching unit 315, at a predetermined timing, matches the public key P2 stored in the memory unit 311 with the key information P2 stored in the distributed ledger 200. Details of the matching unit 315 are similar to the details of the matching unit 115 described in the first embodiment, except that the matching unit 315 uses the public key P2 and the key information P2. Therefore, the description of the first embodiment will be quoted under the premise of this embodiment, and the description will be omitted.

[0110] The validity checking unit 316 checks the validity of the electronic certificate received from the ECU 32. Specifically, the validity checking unit 316 transmits a confirmation signal from the transmission unit 313 to the certificate authority 300, inquiring about the validity of the electronic certificate of the public key P2. Then, upon receiving the confirmation signal, the certificate authority 300 checks the validity of the electronic certificate indicated in the confirmation signal and sends the confirmation result to the ECU 31. The validity check includes, for example, checking the authenticity of the electronic certificate as well as the expiration date of the electronic certificate. The reception unit 314 of the ECU 31 receives the confirmation result.

[0111] (3) Operation of Electronic Control Units (ECUs) 31 and 32 The operation of verifying the public key P2 and encrypting transmission data in the ECU 32 of this embodiment will be described with reference to the flowchart of FIG.

[0112] First, the operation of the ECU 31. The control unit 312 of the ECU 31 generates the public key P1 using the private key S1 (S311). The transmission unit 313 transmits the generated public key P1 and a request for issuing a digital certificate to the certificate authority 300 (S312). The receiving unit 314 receives the electronic certificate issued by the certificate authority 300 (S313). Then, the transmission unit 313 transmits the public key P1 and the electronic certificate to the ECU 32 (S314).

[0113] Next, the operation of the ECU 32. The receiving unit 324 of the ECU 32 receives the public key P1 and the electronic certificate, and stores them in the storage unit 321 as the public key P2 and the electronic certificate (S321). The validity checking unit 326 judges whether it is time to check the validity of the electronic certificate (S322). If it is time to check the validity of the electronic certificate (S322: YES), the validity checking unit 326 transmits a confirmation signal to the certificate authority 300 inquiring about the validity of the electronic certificate, and receives the authentication result from the certificate authority 300 (S323). If it is not time to check the validity (S322: NO), the unit 326 proceeds to judge whether it is a predetermined time (S325). If the electronic certificate is valid (S324: YES), the collation unit 325 judges whether it is the specified timing (S325). If it is judged that it is the specified timing (S325: YES), the transmission unit 323 transmits a request for key information to the distributed ledger 200, and the reception unit 324 receives the key information P2 transmitted from the distributed ledger 200 (S326). The collation unit 325 collates the public key P2 read from the storage unit 321 with the key information P2 received from the distributed ledger 200 (S327). If it is determined that the public key P2 has not been tampered with (S328: YES), the data is encrypted and transmitted using the public key P2 (S329). If it is determined that the public key P2 has been tampered with (S328: NO), the data is not encrypted and transmitted (S330). Also, if the electronic certificate is not valid (S324: NO), the data is not encrypted and transmitted (S330). Furthermore, if it is not determined that the specified timing has arrived (S325: NO), the data is encrypted and transmitted using the public key P2 (S329).

[0114] The operation of verifying the public key P2 and decrypting the electronic signature in the ECU 31 according to the modified example of this embodiment will be described with reference to the flowchart of FIG.

[0115] First, the operation of the ECU 32. The control unit 322 of the ECU 32 generates the public key P1 using the private key S1 (S311). The transmission unit 323 transmits the generated public key P1 and a request for issuing a digital certificate to the certificate authority 300 (S312). The receiving unit 324 receives the electronic certificate issued by the certificate authority 300 (S313). Then, the transmission unit 323 transmits the public key P1 and the electronic certificate to the ECU 31 (S314).

[0116] Next, the operation of the ECU 31. The receiver 314 of the ECU 31 receives the public key P1 and the electronic certificate, and stores them in the storage unit 311 as the public key P2 and the electronic certificate (S321). Thereafter, at any timing, the receiving unit 314 of the ECU 31 receives the encrypted data (S322). For example, the receiving unit 314 of the ECU 31 receives the digital signature generated by the ECU 32 using the private key S1 and the data. The validity checking unit 316 judges whether it is time to check the validity of the electronic certificate (S323). If it is time to check the validity of the electronic certificate (S323: YES), the validity checking unit 316 transmits a confirmation signal to the certificate authority 300 inquiring about the validity of the electronic certificate, and receives the authentication result from the certificate authority 300 (S324). If it is not time to check the validity (S323: NO), the unit 316 proceeds to judge whether it is a predetermined time (S326). If the electronic certificate is valid (S325: YES), the collation unit 315 judges whether it is the specified timing (S326). If it is judged that it is the specified timing (S326: YES), the transmission unit 313 transmits a request for key information to the distributed ledger 200, and the reception unit 314 receives the key information P2 transmitted from the distributed ledger 200 (S327). The collation unit 315 collates the public key P2 read from the storage unit 311 with the key information P2 received from the distributed ledger 200 (S328). If it is determined that the public key P2 has not been tampered with (S329: YES), the collation unit 315 uses the public key P2 to decrypt the data and electronic signature (S330). If it is determined that the public key P2 has been tampered with (S329: NO), the collation unit 315 does not decrypt the data and electronic signature (S331). Also, if the electronic certificate is invalid (S325: NO), the collation unit 315 does not decrypt the data and electronic signature (S331). Furthermore, if it is not determined that the specified timing has arrived (S326: NO), the collation unit 315 uses the public key P2 to decrypt the data and electronic signature (S330).

[0117] (4)Other Although both this embodiment and the modified example of this embodiment have been described focusing on the two ECUs of the electronic control system 100, that is, the data sender and the data receiver, the same applies to other ECUs included in the electronic control system 100. In this case, the distributed ledger and certificate authority used by the other ECUs may be different from the distributed ledger 200 and the certificate authority 300. In other words, when the electronic control system 100 includes a mixture of ECUs manufactured by multiple manufacturers or ECUs provided for individual services, for example, a distributed ledger and certificate authority managed by the manufacturer of each ECU or the service provider may be used.

[0118] (5) Summary In this embodiment, in addition to the effects of the first or second embodiment, a validity checking unit is provided, so that the security of the public key P2 can be further ensured by the electronic certificate issued by the certificate authority. Furthermore, by setting the frequency of validation by the validity checking section to be lower than the frequency of the predetermined timing required for collation, the security of public key P2 can be increased while appropriately suppressing the traffic on the communication line.

[0119] 5. Embodiment 4 In the first to third embodiments, it is assumed that the distributed ledger 200 is provided outside the vehicle. In the present embodiment, the distributed ledger 200 is provided inside the vehicle, that is, in other ECUs included in the electronic control system 100 mounted on the vehicle.

[0120] The present embodiment will be outlined with reference to FIG. 14A shows the counterparts of the matching and validation check in embodiment 3. In embodiment 3, the matching unit 325 of the ECU 32 matches the distributed ledger 200, and the validity check unit 326 checks the certificate authority 300. 14(b) and 14(c) show the counterparts of the verification and validation check in this embodiment. In this embodiment, the verification unit 425 of the ECU 42 checks against the distributed ledger set in the storage unit 411 of the integrated ECU, and the validity check unit 426 checks against the certificate authority 300. Furthermore, in Fig. 14(c), the collation unit 415 of the integrated ECU checks against the distributed ledger 200. The case of Fig. 14(c) will be described below.

[0121] The configurations of the ECU 42 and the integrated ECU in this embodiment will be described with reference to FIG.

[0122] The ECU 41 and the ECU 42 may be any combination of the ECUs shown in FIG. 2, but in this embodiment, the ECU 41 is an integrated ECU, and the ECU 42 is an individual ECU. The ECU 41 (integrated ECU) (corresponding to the “second electronic control device”) has a storage unit 411, a control unit 412, a transmission unit 413, and a reception unit 414. The control unit 412 also includes a collation unit 415. The ECU 42 (corresponding to the “first electronic control unit”) has a storage unit 421, a control unit 422, a transmission unit 423, and a reception unit 424. The control unit 422 further includes a collation unit 425 and a validity confirmation unit 426. Hereinafter, only the parts different from the third embodiment will be explained, and the explanation of the third embodiment will be quoted for the parts that are the same as the third embodiment.

[0123] In this embodiment, the function of the distributed ledger from the ECU 42's perspective is performed by the storage unit 411 of the ECU 41 (integrated ECU). That is, the public key P1 generated from the private key S1 is stored in a distributed ledger (corresponding to a "first distributed ledger") set in the storage unit 411.

[0124] Then, the matching unit 425 of ECU42 (corresponding to the "first matching unit") matches, at a predetermined timing (corresponding to the "first predetermined timing"), the public key P2 stored in its own memory unit 421 with the public key P1 stored in the distributed ledger set in the memory unit 411 of ECU41 (integrated ECU) rather than the distributed ledger 200. In this example, what is stored in the distributed ledger set in the storage unit 411 is the public key P1 itself, but it may also be arranged to store the key information P1 of the public key P1. It should be noted that it is not necessary to set up a distributed ledger in the storage unit 411, and it is sufficient that the storage unit 411 stores the public key P1 or the key information P1.

[0125] Furthermore, the collation unit 415 (corresponding to a "second collation unit") of the ECU 41 (integrated ECU) collates the public key P1 stored in the memory unit 411 with the key information P2 stored in the distributed ledger 200 (corresponding to a "second distributed ledger") at a predetermined timing (corresponding to a "second predetermined timing"). The configuration and operation of the ECU 41 (integrated ECU) are the same as those of the second and third embodiments.

[0126] When comparing the frequency of a predetermined timing in matching the ECU 41 (integrated ECU) with the frequency of a predetermined timing in matching the ECU 42, it is desirable that the former is lower than the latter. Since it is relatively rare for the keys of multiple ECUs included in the electronic control system 100 to be tampered with simultaneously, it is usually possible to check for tampering by checking with the public key P1 of the integrated ECU. In addition, in preparation for simultaneous tampering, it is also possible to access the distributed ledger 200 outside the vehicle to check for tampering. This makes it possible to reduce the frequency of communication with the outside world without reducing the frequency of matching the public key P1, thereby enabling efficient use of communication line resources.

[0127] Although this embodiment has a configuration corresponding to that of FIG. 10 of the third embodiment, it may have a configuration corresponding to that of FIG. 11 of the third embodiment.

[0128] 6. Other embodiments The examples of the first to fourth embodiments may be applied to the entire electronic control system 100 mounted on a vehicle, or may be applied to only a part of the electronic control system 100. For example, they may be applied only between ECUs that control a camera, a radar, and a LiDAR, or between an ECU integrated with these.

[0129] 7. Summary The features of the electronic control device, the distributed ledger, the certificate authority, and the like in each embodiment of the present invention have been described above.

[0130] The terms used in each embodiment are merely examples and may be replaced with synonymous terms or terms having the same functions.

[0131] The block diagrams used to explain the embodiments classify and organize the configuration of the device by function. The blocks showing the respective functions are realized by any combination of hardware or software. In addition, since the block diagrams show the functions, they can also be understood as disclosures of a method invention and a program invention that realizes the method.

[0132] The order of the functional blocks that can be understood as the processes, flows, and methods described in each embodiment may be changed as long as there are no constraints such as a relationship in which one step utilizes the results of another step prior to it.

[0133] The terms first, second, through Nth (N is an integer) used in each embodiment and in the claims are used to distinguish two or more configurations or methods of the same type, and do not limit the order or superiority or inferiority.

[0134] In each embodiment, the electronic control device disclosed in each embodiment has been described on the assumption that it is mounted on a vehicle, but it may also be carried by a pedestrian.

[0135] Furthermore, examples of the form of the electronic control device, distributed ledger, and certificate authority of the present invention are as follows. Examples of the component form include a semiconductor element, an electronic circuit, a module, and a microcomputer. Examples of semi-finished products include electronic control units (ECUs (Electric Control Units)) and system boards. Examples of finished products include mobile phones, smartphones, tablets, personal computers (PCs), workstations, servers, and cloud servers. Other examples include devices with communication functions, such as video cameras, still cameras, and car navigation systems.

[0136] Additionally, necessary functions, such as an antenna or a communication interface, may be added to the electronic control device, distributed ledger, and certificate authority.

[0137] It is assumed that the distributed ledger and the certificate authority of the present invention will be used for the purpose of providing various services. In providing such services, the distributed ledger and the certificate authority of the present invention will be used, the method of the present invention will be used, and / or the program of the present invention will be executed.

[0138] In addition, the present invention can be realized not only by dedicated hardware having the configuration and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as a memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory capable of executing the program.

[0139] A program stored in a non-transient physical recording medium (for example, an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, ROM, etc.)) of dedicated or general-purpose hardware can be provided to the dedicated or general-purpose hardware via a recording medium, or via a communication line from a server without using a recording medium. This makes it possible to always provide the latest functions through program upgrades. [Industrial Applicability]

[0140] The electronic control device of the present invention has been described as an electronic control device for vehicles that is primarily mounted on automobiles, but it can also be applied to all moving objects, including motorcycles, motorized bicycles, and trains, as well as pedestrians, ships, and aircraft. [Explanation of symbols]

[0141] 11, 12, 21, 22, 31, 32, 41, 42 ECU 111, 121, 211, 221, 311, 321, 411, 421 Storage section 112, 122, 212, 222, 312, 322, 412, 422 Control unit 113, 123, 213, 223, 313, 323, 413, 423 Transmitter 114, 124, 214, 224, 314, 324, 414, 424 Receiver 115, 125, 215, 225, 315, 325, 415, 425 Collation section 316, 326, 426 Validation Section 200 Distributed Ledgers 300 Certificate Authority

Claims

1. An electronic control device mounted on a vehicle, a storage unit (111, 121, 211, 221, 311, 321, 411, 421) for storing keys; a collation unit (115, 125, 215, 225, 315, 325, 415, 425) that collates the keys stored in the storage unit with key information, which is information regarding the keys stored in a distributed ledger (200) provided outside the vehicle, at each predetermined time; The electronic control device (11, 12, 21, 22, 31, 32, 41, 42).

2. The electronic control device further includes a reception unit (314, 324) that receives an electronic certificate of the key; and a validity confirmation unit (316, 326) that confirms the validity of the electronic certificate with a certification authority (300). The electronic control device according to claim 1.

3. The frequency of validity confirmation by the validity confirmation unit is lower than the frequency at each predetermined time. The electronic control device according to claim 2.

4. The storage unit stores the collation result by the collation unit, and determines whether to use the key based on the collation result when using the key. The electronic control device according to claim 1.

5. In addition to the second distributed ledger, a first distributed ledger is provided in the vehicle. The electronic control device according to claim 1.

6. Each of the predetermined times is during traveling of the vehicle, when the vehicle can communicate with the outside, every first predetermined time. The electronic control device according to any one of claims 1 to 5.

7. The first predetermined time is determined according to the speed of the vehicle. The electronic control device according to claim 6.

8. Each of the predetermined times is When the vehicle is parked and communication between the vehicle and the outside is possible, it is every fourth predetermined time. The electronic control device according to any one of claims 1 to 5.

9. Each of the predetermined times is When the vehicle is running and communication between the vehicle and the outside is possible, it is every first predetermined time, When the vehicle is parked and communication between the vehicle and the outside is possible, it is every fourth predetermined time, The fourth predetermined time is longer than the first predetermined time. The electronic control device according to claim 8.

10. A key verification method executed in an electronic control device mounted on a vehicle, Storing a key in a storage unit (S111, S121, S321), Every predetermined time, comparing the key stored in the storage unit with key information which is information about the key stored in a distributed ledger provided outside the vehicle (S116, S125, S327, S328), Key verification method.

11. A key verification program executable in an electronic control device mounted on a vehicle, The key verification program is Storing a key in a storage unit (S111, S121, S321), Every predetermined time, causing the electronic control device to execute a process including comparing the key stored in the storage unit with key information which is information about the key stored in a distributed ledger provided outside the vehicle (S116, S125, S327, S328). Key verification program.

12. An electronic control system comprising a plurality of electronic control devices mounted on a vehicle, Each of the plurality of the electronic control devices includes a storage unit that stores a key; and a collation unit that collates the key stored in the storage unit with key information which is information regarding the key stored in the distributed ledger at predetermined intervals. An electronic control system (100).

13. When the plurality of the electronic control devices are a first electronic control device and a second electronic control device, the predetermined intervals in the first electronic control device are different from the predetermined intervals in the second electronic control device. The electronic control system according to claim 12.

14. A key management system including an electronic control device mounted on a vehicle and a distributed ledger (200) provided outside the vehicle, wherein the electronic control device includes a storage unit that stores a key; and a collation unit that collates the key stored in the storage unit with key information which is information regarding the key stored in the distributed ledger at predetermined intervals. A key management system.

15. A key management system including an electronic control device mounted on a vehicle, a distributed ledger (200) provided outside the vehicle, and a certification authority (300), wherein the electronic control device includes a storage unit that stores a key; and a collation unit that collates the key stored in the storage unit with key information which is information regarding the key stored in the distributed ledger at predetermined intervals; and an effectiveness confirmation unit that confirms the effectiveness of an electronic certificate regarding the key to the certification authority. A key management system.

16. A key management system including an electronic control system including a first electronic control device and a second electronic control device mounted on a vehicle, wherein the first electronic control device A first storage unit that stores a key, a first collation unit that collates the key stored in the first storage unit with first key information, which is information regarding the key stored in the second electronic control device, every first predetermined time, wherein the second electronic control device includes a second storage unit that stores the key, and a second collation unit that collates the key stored in the second storage unit with second key information, which is information regarding the key stored in a distributed ledger provided outside the vehicle, every second predetermined time, a key management system.

17. The frequency per second predetermined time is lower than the frequency per first predetermined time, The key management system according to claim 16.