On-vehicle device, program, and information processing method

JP2025000329A5Pending Publication Date: 2025-12-19AUTONETWORKS TECH LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023100128
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-06-19
Publication Date
2025-12-19

AI Technical Summary

Technical Problem

Existing in-vehicle ECUs do not efficiently handle authentication processes for connected external devices, such as USB devices, lacking support for device authentication and security validation.

Method used

An in-vehicle device with a connection port and processing unit that acquires device definition information from external devices, performs authentication based on device classes, and executes authentication programs to ensure secure communication and functional restrictions.

Benefits of technology

Enables efficient and secure authentication of external devices, ensuring a reliable and secure in-vehicle communication environment by validating device authenticity and applying appropriate functional restrictions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide an on-vehicle device, etc. which efficiently perform processing related to authentication of an external device connected to the device.SOLUTION: An on-vehicle device is mounted on a vehicle and includes: a connection port to which an external device is connected; and a processing part which performs processing related to the external device connected to the connection port. The processing part acquires device definition information from the external device connected to the connection port and executes an authentication program corresponding to an authentication device class when the authentication device class is included in the acquired device definition information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an in-vehicle device, a program, and an information processing method. [Background technology]

[0002] A vehicle is equipped with a body ECU, which is an on-board ECU that controls body-related devices such as a wiper drive device, interior and exterior lighting devices, door lock devices, and power windows (see, for example, Patent Document 1). The wiper drive device of Patent Document 1 includes an on-board ECU (body ECU) and is driven by a control program applied to the on-board ECU. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] JP 2017-224926 A Summary of the Invention [Problem to be solved by the invention]

[0004] It is assumed that external devices such as USB devices will be connected to such an in-vehicle ECU, but the in-vehicle ECU of Patent Document 1 does not take into consideration how to efficiently perform authentication processing for the connected external device.

[0005] An object of the present disclosure is to provide an in-vehicle device or the like that can efficiently perform authentication processing for a connected external device. [Means for solving the problem]

[0006] An in-vehicle device according to one embodiment of the present disclosure is an in-vehicle device mounted on a vehicle and including a connection port to which an external device is connected, and a processing unit that performs processing related to the external device connected to the connection port, wherein the processing unit acquires device definition information from the external device connected to the connection port, and if the acquired device definition information includes an authentication device class, executes an authentication program corresponding to the authentication device class. Effect of the Invention

[0007] According to one aspect of the present disclosure, it is possible to provide an in-vehicle device or the like that efficiently performs processing related to authentication of a connected external device. [Brief description of the drawings]

[0008] [Figure 1] 1 is a schematic diagram illustrating a configuration of an in-vehicle system including an in-vehicle device according to a first embodiment. [Diagram 2] 2 is a block diagram illustrating an example of an internal configuration of an in-vehicle device; [Diagram 3] FIG. 2 is an explanatory diagram (sequence diagram) illustrating one mode of each process by an in-vehicle device or the like. [Figure 4] 4 is a flowchart illustrating a process of a processing unit of an in-vehicle device. [Diagram 5] 10 is a flowchart illustrating a process of a processing unit of an in-vehicle device according to the second embodiment (single device definition information). [Figure 6] 13 is a flowchart illustrating the processing of a processing unit of an in-vehicle device according to the third embodiment (state of the vehicle). DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0009] [Description of the embodiment of the present invention] First, embodiments of the present disclosure will be listed and described. In addition, at least some of the embodiments described below may be arbitrarily combined.

[0010] (1) An in-vehicle device according to one embodiment of the present disclosure is mounted on a vehicle and includes a connection port to which an external device is connected and a processing unit that performs processing related to the external device connected to the connection port, wherein the processing unit acquires device definition information from the external device connected to the connection port, and, if the acquired device definition information includes an authentication device class, executes an authentication program corresponding to the authentication device class.

[0011] In this embodiment, the in-vehicle device includes a connection port such as a USB port. When an external device such as a USB device is connected to the connection port, the processing unit of the in-vehicle device detects the connection. The processing unit of the in-vehicle device requests the external device (USB device) whose connection has been detected to transmit device definition information (descriptor information). In response to the request, the external device (USB device) transmits the device definition information (descriptor information) to the in-vehicle device. The processing unit of the in-vehicle device determines whether the device definition information (descriptor information) includes an authentication device class, and executes an authentication program corresponding to the authentication device class if the authentication device class is included. The authentication program is stored in a storage area accessible by the processing unit of the in-vehicle device, such as a storage unit of the in-vehicle device, and the storage unit or the like further stores a correspondence relationship between the authentication device class and the authentication program. The processing unit of the in-vehicle device starts an authentication process for the connected external device by executing the authentication program stored in the storage unit or the like. The authentication process may be a single or combination of various authentication processes, such as a process based on a digital certificate by a CA (Certificate Authority), a Challenge Handshake Authentication Protocol (CHAP) authentication, a process based on a Message Authentication Code (MAC), and authentication using an encryption key, a private key, or a public key. In this way, when the processing unit of the in-vehicle device detects a connection of an external device to a connection port, the processing unit of the in-vehicle device executes an authentication program according to an authentication device class in the device definition information (descriptor information) transmitted from the external device, so that the security legitimacy of the connected external device can be guaranteed. That is, even if such an external device is connected by plug and play and communication is performed by the external device via the in-vehicle network to which the in-vehicle device or the like is connected, the security legitimacy of the external device can be guaranteed, and a secure in-vehicle communication environment can be constructed.

[0012] (2) In the in-car device according to one aspect of the present disclosure, the external device is a USB device, the connection port is a USB port, and the USB device and the USB port are compliant with USB 2.0 or USB 1.1.

[0013] In this embodiment, the external device is a USB device, and the connection port is a USB port. The USB device (external device) complies with the USB 2.0 or USB 1.1 standard. In the USB 2.0 standard, authentication of the USB device is not supported (not included), but the processing unit of the in-vehicle device performs processing corresponding to the authentication device class included in the device definition information (descriptor information) in a sequence (USB device recognition processing) performed when the connection of the USB device is detected. Therefore, the processing unit of the in-vehicle device can execute an authentication program corresponding to the authentication device class before performing processing for actually operating the USB device (external device) as a storage device or actuator, while following a standard sequence (descriptor request and acquisition) when detecting a USB device (external device). In this way, even if the authentication processing is not defined in the standard such as the USB 2.0 standard, the authentication processing for the USB device (external device) can be executed according to a standard sequence when detecting the USB device (external device). In particular, USB ports used by on-board devices such as ECUs installed in vehicles (USB ports associated with microcontrollers installed in on-board devices) are generally based on the USB 2.0 standard, and under such conditions, authentication of USB devices (external equipment) can be achieved even with on-board devices and the USB 2.0 standard.

[0014] (3) In an in-vehicle device according to one embodiment of the present disclosure, when an execution result of an authentication program corresponding to the authentication device class is a positive authentication result, the processing unit executes processing corresponding to the application device class included in the device definition information acquired from the external device without imposing functional restrictions, and when an execution result of an authentication program corresponding to the authentication device class is a negative authentication result, the processing unit executes processing corresponding to the application device class included in the device definition information acquired from the external device with functional restrictions.

[0015] In this embodiment, the processing unit of the in-vehicle device varies the functional restrictions when operating the external device according to the execution result (authentication result) of the authentication program executed according to the authentication device class. After executing the authentication program according to the authentication device class, the processing unit of the in-vehicle device specifies (extracts) the application device class included in the device definition information acquired from the external device. The processing unit of the in-vehicle device executes an application corresponding to the application device class. In the storage unit of the in-vehicle device, applications corresponding to various application device classes are defined as common class specifications in the USB 2.0 standard, for example. The application corresponding to the application device class includes, for example, a device driver for operating the external device, or various software corresponding to the hardware specifications of the external device. When the execution result of the authentication program is a positive authentication result (authentication success), the processing unit of the in-vehicle device executes a process corresponding to the application device class without imposing functional restrictions. When the execution result of the authentication program is a positive authentication result (authentication success), the security legitimacy of the external device is guaranteed, so that the application is executed without imposing functional restrictions when operating the external device. The processing unit of the in-vehicle device may apply a function restriction as an initial state when the connection of the USB device is detected, and release the function restriction when a positive authentication result (authentication success) is triggered. In this way, when the external device is, for example, a USB light, a USB camera, a wireless client, various sensors such as a temperature sensor, or an installation device for an update program (reproduction device), the external device can be operated by exerting the functions that the external device has in the product specifications. When the execution result of the authentication program is a negative authentication result (authentication failure), the processing unit of the in-vehicle device executes a process corresponding to the device class for the application with the function restriction. When the execution result of the authentication program is a negative authentication result (authentication failure), the external device is operated with the function restriction applied, since the security legitimacy of the external device is not guaranteed. The processing unit of the in-vehicle device may apply a function restriction as an initial state when the connection of the USB device is detected, and maintain the function restriction when a negative authentication result (authentication failure) is triggered.The functional restriction includes, for example, an operational restriction to only supply power to the USB device, or an operational restriction to limit communication to non-secure information such as media data. Alternatively, the processing unit of the in-vehicle device may cut off power and communication to the USB device as a functional restriction for the USB device for which a negative authentication result (authentication failure) has been obtained. In this way, the processing unit of the in-vehicle device can ensure a secure in-vehicle communication environment by providing a functional restriction on operating an external device when a negative authentication result (authentication failure) has been obtained.

[0016] (4) In an in-vehicle device according to one embodiment of the present disclosure, the processing unit stores equipment definition information including the authentication device class when the execution result of an authentication program corresponding to the authentication device class results in a negative authentication result.

[0017] In this embodiment, when the execution result of the authentication program for the connected USB device (external device) is a negative authentication result (authentication failure), the processing unit of the in-vehicle device stores the device definition information (descriptor information) acquired from the USB device (external device) by, for example, storing the information in a storage unit of the in-vehicle device. When storing the device definition information (descriptor information), the processing unit of the in-vehicle device may store (store) the device definition information in association with the date and time when the device definition information was acquired from the USB device (external device). There is a concern that a USB device (external device) that has thus resulted in a negative authentication result (authentication failure) may be an unauthorized device. Therefore, by storing the device definition information (descriptor information) transmitted from the USB device (external device) as, for example, log information, the device definition information (descriptor information) can be used as original data for analyzing attack patterns by unauthorized devices.

[0018] (5) In an in-vehicle device according to one embodiment of the present disclosure, when the processing unit detects that the external device is connected to the connection port, the processing unit performs processing on the external device related to device definition information that includes the authentication device class, and then performs processing on the device definition information that includes the application device class.

[0019] In this embodiment, when the processing unit of the in-vehicle device detects that an external device is connected to a connection port, the processing unit of the in-vehicle device first requests the external device for device definition information (descriptor information) including the authentication device class. After the processing unit of the in-vehicle device requests the device definition information (descriptor information) including the authentication device class, the processing unit of the in-vehicle device requests the external device for device definition information (descriptor information) including the application device class. In this manner, the processing unit of the in-vehicle device communicates with the external device regarding the authentication device class, and then communicates with the application device class. Therefore, in the sequence between the in-vehicle device and the external device, processing for the authentication device class is performed in the first half, and processing for the application device class is performed in the second half, and the device class can be switched during the execution of the sequence. The device class is used as a control factor (element) for identifying and operating the type of the USB device when the USB device is connected to the USB port. By switching the device class in this manner, it is possible to efficiently transition from authentication processing by the authentication program to operation processing by executing an application.

[0020] (6) In an in-vehicle device according to one embodiment of the present disclosure, if the device definition information acquired when detecting that the external device is connected to the connection port does not include the authentication device class, the processing unit determines that the external device is an unauthenticated device and executes, with functional restrictions, processing corresponding to the app device class included in the device definition information acquired from the external device.

[0021] In this embodiment, when detecting that an external device (USB device) is connected to a connection port, if the initial device definition information (descriptor information) acquired from the external device does not include an authentication device class, the processing unit of the in-vehicle device determines that the external device (USB device) is an unauthenticated device that does not correspond to the authentication device class. In this case, the processing unit of the in-vehicle device imposes a function restriction when operating the external device determined to be an unauthenticated device. The external device (USB device) determined to be an unauthenticated device outputs (transmits) to the in-vehicle device device definition information (descriptor information) that does not include an authentication device class but includes an application device class. The processing unit of the in-vehicle device imposes a function restriction when operating the external device (USB device) when executing an application corresponding to the application device class included in the device definition information (descriptor information). In this way, even if the connected external device (USB device) is an unauthenticated device, the processing unit of the in-vehicle device operates the external device by applying function restrictions, so that compatibility or versatility can be ensured for USB devices conforming to standards such as USB 2.0. Furthermore, if the connected external device (USB device) is an unauthenticated device, the processing unit of the in-vehicle device operates the external device by applying function restrictions, so that a secure in-vehicle communication environment can be ensured. When setting the function restrictions, the processing unit of the in-vehicle device may set different function restrictions for an external device determined to be an unauthenticated device and different function restrictions for an external device for which the execution result of the authentication program is a negative authentication result (authentication failure). By setting different function restrictions according to the type of the determination result, flexible response according to the connected external device (USB device) can be achieved, and the availability of the in-vehicle system can be improved.

[0022] (7) In one embodiment of the in-vehicle device of the present disclosure, the processing unit acquires status information regarding the state of the vehicle, and when the status information indicates a driving state, suspends at least a portion of the processing related to the device definition information transmitted from the external device.

[0023] In this embodiment, the processing unit of the in-vehicle device reserves at least a part of the processing corresponding to the device definition information (descriptor information) acquired from the external device (USB device) whose connection has been detected, according to the acquired state information. The state information is information about the state of the vehicle, and indicates, for example, a running state and a stopped state indicating a state other than the running state. The processing unit of the in-vehicle device may, for example, acquire a signal from a power switch or an IG switch that controls starting or stopping the vehicle, and derive whether the state of the vehicle is a running state or a stopped state based on the signal. Alternatively, the processing unit of the in-vehicle device may, for example, acquire an output value (sensor value) from a vehicle speed sensor, an engine or motor revolution sensor, or the like, and derive whether the state of the vehicle is a running state or a stopped state based on the output value (sensor value). When the state information indicates a running state (the vehicle is running), the processing unit of the in-vehicle device may, upon detecting that an external device has been connected to the connection port, perform only the processing for the authentication device class, which is the first half, in the sequence between the in-vehicle device and the external device, and reserve (stop the sequence) the processing for the application device class, which is the second half. The processing unit of the in-vehicle device may execute (resume the sequence) the process for the application device class that was put on hold when the state information transitions from the running state to the stopped state. It is assumed that the execution of an application corresponding to the application device class and the start of an operation for an external device (USB device) causes the external device to be driven or functioned, which starts the transmission of communication data from the external device to the in-vehicle network, causing a change in the in-vehicle communication environment. In response to this, while the vehicle is running (state information is the running state), the process for the application device class is put on hold, thereby mitigating the impact of a newly connected external device (USB device) on the in-vehicle network.

[0024] (8) A program according to one embodiment of the present disclosure causes a computer having a connection port to which an external device mounted on a vehicle is connected to acquire device definition information from the external device connected to the connection port, and, if the acquired device definition information includes an authentication device class, executes a process to execute an authentication program corresponding to the authentication device class.

[0025] In this aspect, it is possible to provide a program that causes a computer to function as an in-vehicle device that efficiently performs processes related to authentication of a connected external device.

[0026] (9) An information processing method according to one aspect of the present disclosure includes causing a computer having a connection port to which an external device mounted on a vehicle is connected to acquire device definition information from the external device connected to the connection port, and, if the acquired device definition information includes an authentication device class, executing an authentication program corresponding to the authentication device class.

[0027] According to this aspect, it is possible to provide an information processing method that causes a computer to function as an in-vehicle device that efficiently performs processing related to authentication of a connected external device.

[0028] [Details of the embodiment of the present disclosure] The present disclosure will be specifically described based on the drawings showing the embodiments. An in-vehicle device 1 according to an embodiment of the present disclosure will be described below with reference to the drawings. Note that the present disclosure is not limited to these examples, but is indicated by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims.

[0029] (Embodiment 1) Hereinafter, an embodiment will be described with reference to the drawings. FIG. 1 is a schematic diagram illustrating the configuration of an in-vehicle system S including an in-vehicle device 1 according to the first embodiment. FIG. 2 is a block diagram illustrating the internal configuration of the in-vehicle device 1. The in-vehicle system S is configured with an in-vehicle device 1 mounted on a vehicle C as a main device, and the in-vehicle device 1 is configured so that an external device 141 can be additionally connected (retrofitted). The in-vehicle device 1 is communicatively connected to a plurality of in-vehicle ECUs 2 via an in-vehicle network 3 formed of a communication line 31, and performs various processes in response to messages transmitted from the in-vehicle ECUs 2 or output signals from various sensors, etc.

[0030] An external device 141 is connected to the in-vehicle device 1. The external device 141 is, for example, a Universal Serial Bus (USB) device conforming to a standard such as USB 2.0. The in-vehicle device 1 has a connection port 14 (USB port) to which the external device 141 (USB device) is connected, and functions as a USB host. When the in-vehicle device 1 detects that the external device 141 (USB device) is connected to the connection port 14 (USB port), the in-vehicle device 1 performs communication conforming to a standard such as USB 2.0 with the external device 141 (USB device), and requests and acquires device definition information (descriptor information).

[0031] The vehicle C is equipped with a power supply device 5 configured with a lead battery, an alternator, a secondary battery, or the like. The power supply device 5 and the in-vehicle device 1 are connected by a power line 51. The power supply device 5 and the in-vehicle device 1 are not limited to being directly connected by the power line 51, and may be indirectly connected with an electric box (junction box) such as a relay box or a fuse box interposed between the power supply device 5 and the in-vehicle device 1.

[0032] The in-vehicle device 1 may be a relay device (CAN gateway, Ether switch) having a relay function such as a CAN gateway. Alternatively, the in-vehicle device 1 may be an integrated ECU (vehicle computer) that controls the entire vehicle C in an integrated manner and has a relay function. Alternatively, the in-vehicle device 1 may be an individual ECU that is connected under the control of the integrated ECU and is arranged in each area of ​​the vehicle C. Alternatively, the in-vehicle device 1 may be configured as a body ECU that controls body actuators of the vehicle C. Alternatively, the in-vehicle device 1 may be a PLB (Power Lan Box) that functions as a power distribution device that distributes and relays power output from a power supply device 5 such as a secondary battery and supplies power to in-vehicle devices such as actuators, in addition to relaying communication. Alternatively, the in-vehicle device 1 may be an information terminal device that connects to the in-vehicle network 3 by wireless communication.

[0033] The in-vehicle device 1 includes a processing unit 11, a storage unit 12, a communication unit 13, and a connection port 14, which may be configured as a package using, for example, a microcomputer, etc. The processing unit 11 is configured with a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), etc., and is configured to read out and execute a control program P (program product) and data previously stored in the storage unit 12, thereby performing various control processes and arithmetic processes, etc.

[0034] The storage unit 12 is configured by a volatile memory element such as a RAM (Random Access Memory), or a non-volatile memory element such as a ROM (Read Only Memory), an EEPROM (Electrically Erasable Programmable ROM), or a flash memory, or a combination of these storage devices, and stores a control program P (program product) and data to be referenced during processing in advance. The control program P (program product) stored in the storage unit 12 may be a control program P (program product) read from a recording medium M readable by the in-vehicle device 1. Alternatively, the control program P (program product) may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 12.

[0035] The communication unit 13 is an input / output interface using a communication protocol such as CAN, CAN-FD, or Ethernet (registered trademark), and the processing unit 11 communicates with the in-vehicle ECU 2 connected to the in-vehicle network 3 via the communication unit 13. In the in-vehicle device 1, a plurality of communication units 13 may be provided.

[0036] The connection port 14 is, for example, a USB port conforming to the USB 2.0 or USB 1.1 standard, and functions as an input / output interface for a connected external device 141 (USB device). The in-vehicle device 1 includes one or more (three in the figure) connection ports 14 (USB ports).

[0037] 3 is an explanatory diagram (sequence diagram) illustrating one mode of each process by the in-vehicle device 1 etc. The in-vehicle device 1 (USB host) and an external device 141 (USB device) connected to a connection port 14 (USB port) of the in-vehicle device 1 (USB host) perform serial communication conforming to the USB 2.0 standard, for example, and perform the following sequence process.

[0038] The in-vehicle device 1 detects the external device 141 connected to the connection port 14 (S01). The in-vehicle device 1 requests (descriptor request) the external device 141 to transmit device definition information (descriptor information) (S02). The in-vehicle device 1 constantly performs a process of detecting whether or not the external device 141 is connected to the connection port 14. When the external device 141 is connected to the connection port 14, the in-vehicle device 1 requests (descriptor request) the external device 141 to transmit device definition information (descriptor information). The device definition information is called descriptor information in the USB 2.0 standard, and the descriptor information includes, for example, a device class indicating the type of the external device 141, which is a USB device, as well as identifiers such as a vendor ID, a product ID, and a serial ID, power supply information, and information regarding an end point, etc.

[0039] When connection of the external device 141 to the connection port 14 is detected, the device definition information (descriptor information) that the in-vehicle device 1 first requests from the external device 141 is descriptor information including a device class for authentication. The in-vehicle device 1 may explicitly request the external device 141 to transmit device definition information (descriptor information) including a device class for authentication. When connection of the external device 141 is detected, the in-vehicle device 1 may set (initial setting) a function restriction (device restriction release) for the external device 141.

[0040] The external device 141 (USB device) transmits (descriptor transmission) device definition information (descriptor information) to the in-vehicle device 1 (S03). In response to a descriptor request (a request to transmit descriptor information including an authentication device class) from the in-vehicle device 1, the external device 141 transmits the device definition information (descriptor information) including the authentication device class to the in-vehicle device 1.

[0041] The in-vehicle device 1 acquires the device definition information (descriptor information) and detects (extracts) the authentication device class (S04). The in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 and detects (extracts) the authentication device class included in the device definition information.

[0042] The in-vehicle device 1 executes an authentication program corresponding to the authentication device class (S05). The in-vehicle device 1 identifies an authentication program corresponding to the detected authentication device class and executes the authentication program. The in-vehicle device 1 executes the authentication program to communicate with the external device 141 and performs various authentication processes, either alone or in combination, such as a process based on a digital certificate by a CA (Certificate Authority), a Challenge Handshake Authentication Protocol (CHAP) authentication, a process based on a Message Authentication Code (MAC), and authentication using an encryption key, a private key, or a public key. As a result of executing the authentication program, the in-vehicle device 1 acquires (derives) a positive authentication result indicating that authentication has been successful (authentication successful) or a negative authentication result indicating that authentication has failed (authentication failed).

[0043] When the execution result of the authentication program corresponding to the authentication device class is a positive authentication result (authentication success), the in-vehicle device 1 releases the function restriction (device restriction release) set as the initial state when the connection of the USB device is detected (S06). The in-vehicle device 1 sets the function restriction (device restriction) for the external device 141 as the initial setting when the connection of the external device 141 is detected. When the execution result of the authentication program is a positive authentication result (authentication success), the in-vehicle device 1 can release the function restriction (device restriction) so that the external device 141 can perform all the functions that it has in the product specifications. When the execution result of the authentication program corresponding to the authentication device class is a negative authentication result (authentication failure), the in-vehicle device 1 may maintain the function restriction set as the initial state when the connection of the USB device is detected. In this sequence diagram, the subsequent processing will be described in the case of a positive authentication result (authentication success).

[0044] After the authentication program corresponding to the authentication device class is executed, the applied device class is switched (device class switching) in the sequence between the in-car device 1 and the external device 141. That is, the external device 141 switches its own device class from the authentication device class to the application device class before and after the execution of the authentication program. Therefore, in the sequence between the in-car device 1 and the external device 141, processing for the authentication device class is performed in the first half, and processing for the application device class is performed in the second half.

[0045] The in-vehicle device 1 detects the external device 141 connected to the connection port 14 in a state where the function restriction is released (S07). The in-vehicle device 1 requests (descriptor request) the external device 141 to transmit device definition information (descriptor information) (S08). The in-vehicle device 1 and the external device 141 switch the target device class from the authentication device class to the application device class, and then perform S07 to S08 as in the processes S01 to S2. When the connection of the external device 141 to the connection port 14 is detected, the device definition information (descriptor information) that the in-vehicle device 1 requests the external device 141 for the second time is the descriptor information including the application device class. The in-vehicle device 1 may explicitly request the external device 141 to transmit device definition information (descriptor information) including the application device class. In other words, when making a request for transmitting device definition information (descriptor information) to the external device 141, the in-car device 1 may output different transmission request data (signals) to the external device 141 for the request for transmitting device definition information (descriptor information) including a device class for authentication and the request for transmitting device definition information (descriptor information) including a device class for an application.

[0046] The external device 141 (USB device) transmits device definition information (descriptor information) to the in-car device 1 (descriptor transmission) (S09). The device class of the external device 141 (USB device) is switched from the authentication device class to the application device class, triggered by the approval process by the in-car device 1. In response to a descriptor request (a request to transmit descriptor information including the application device class) from the in-car device 1, the external device 141 transmits device definition information (descriptor information) including the application device class to the in-car device 1.

[0047] The in-car device 1 acquires device definition information (descriptor information) and detects (extracts) an application device class (S10). The in-car device 1 acquires device definition information (descriptor information) from the external device 141 and detects (extracts) an application device class included in the device definition information.

[0048] The in-car device 1 executes an application corresponding to the application device class (S11). The in-car device 1 identifies an application corresponding to the detected application device class and executes the application. The application corresponding to the application device class includes, for example, a device driver for operating the external device 141 or various software corresponding to the hardware specifications of the external device 141, which are stored in the storage unit 12. As a result, the in-car device 1 (USB host) and the external device 141 (USB device) perform functions corresponding to the executed application (start USB communication), and the external device 141 (USB device) can start operation processing based on the product specifications.

[0049] For example, when the external device 141 (USB device) is an external USB camera, the function of the automatic driving or the drive recorder can be updated. When the external device 141 (USB device) is a USB memory, an update program such as firmware can be downloaded to the USB memory for a vehicle C that does not have an external communication device that performs wireless communication with an external server such as an OTA server, and software can be updated (reprogrammed) via the connected USB memory. When the external device 141 (USB device) is a USB wireless device having a wireless function such as 4G or 5G, a wireless communication function with an external server such as an OTA server can be added to a vehicle C that does not have an external communication device as standard equipment by connecting (retrofitting) the USB wireless device.

[0050] 4 is a flowchart illustrating the processing of the processing unit 11 of the in-vehicle device 1. The processing unit 11 of the in-vehicle device 1 constantly performs the following processing, for example, while the vehicle C is running or stopped.

[0051] The processing unit 11 of the in-vehicle device 1 determines whether or not an external device 141 (USB device) is connected to the connection port 14 (USB port) (S101). The connection port 14 is, for example, a USB port that complies with the USB 2.0 standard, and the processing unit 11 of the in-vehicle device 1 routinely or continuously performs a process of determining whether or not an external device 141 (USB device) is connected to the connection port 14 (USB port). If the external device 141 is not connected to the connection port 14 (S101: NO), the processing unit 11 of the in-vehicle device 1 performs a loop process to execute the process of S101 again.

[0052] When the external device 141 is connected to the connection port 14 (S101: YES), the processing unit 11 of the in-vehicle device 1 requests (descriptor request) the external device 141 to transmit device definition information (descriptor information) (S102). The processing unit 11 of the in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 (S103). Immediately after detecting the connection of the external device 141 to the connection port 14, the processing unit 11 of the in-vehicle device 1 requests the external device 141 to transmit descriptor information including an authentication device class. In response to the request from the processing unit 11 of the in-vehicle device 1, the external device 141 transmits (outputs) the device definition information (descriptor information) to the in-vehicle device 1. The processing unit 11 of the in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 and stores it in the storage unit 12.

[0053] The processing unit 11 of the in-vehicle device 1 determines whether the acquired device definition information (descriptor information) includes an authentication device class (S104). The external device 141 (USB device) includes an authentication-enabled device that supports the authentication device class and an authentication-unenabled device that does not support the authentication device class.

[0054] When the external device 141 (USB device) is an authentication-compatible device, in response to the first (first since connection detection at the connection port 14) descriptor request from the in-car device 1, the external device 141 (USB device) transmits (outputs) to the in-car device 1 device definition information (descriptor information) including a device class for authentication. When the external device 141 (USB device) is an authentication-incompatible device, in response to the first (first since connection detection at the connection port 14) descriptor request from the in-car device 1, the external device 141 (USB device) transmits (outputs) to the in-car device 1 device definition information (descriptor information) including a device class for application but not including a device class for authentication. The processing unit 11 of the in-car device 1 can determine whether the external device 141 (USB device) connected to the connection port 14 (USB port) is an authentication-compatible device or an authentication-incompatible device, depending on whether the acquired device definition information (descriptor information) includes a device class for authentication.

[0055] If the authentication device class is included (S104: YES), the processing unit 11 of the in-vehicle device 1 executes an authentication program corresponding to the authentication device class (S105). If the acquired device definition information (descriptor information) includes an authentication device class, the processing unit 11 of the in-vehicle device 1 identifies an authentication program corresponding to the authentication device class. The authentication program may be stored in the storage unit 12 of the in-vehicle device 1, and the processing unit 11 of the in-vehicle device 1 may identify the authentication program by referring to the storage. If a plurality of authentication device classes are defined in advance, each authentication device class and each authentication program corresponding to the authentication device class are defined, for example, in a table format (authentication device class table) and stored in the storage unit 12. The processing unit 11 of the in-vehicle device 1 may identify the authentication program by referring to the authentication device class table.

[0056] The processing unit 11 of the in-vehicle device 1 executes the specified authentication program to perform communication with the external device 141 according to various authentication processes. The authentication processes may be, for example, a process based on a digital certificate by a CA (Certificate Authority), a Challenge Handshake Authentication Protocol (CHAP) authentication, a process based on a Message Authentication Code (MAC), and authentication using an encryption key, a private key, or a public key, either singly or in combination. In this way, by employing an authentication method using an encryption key or the like in the authentication process, it is possible to effectively defend against attacks such as spoofing.

[0057] The processing unit 11 of the in-vehicle device 1 judges whether the execution result of the authentication program is a positive authentication result (authentication success) or not (S106). The processing unit 11 of the in-vehicle device 1 acquires (derives) the execution result of the authentication program (determination result of the authentication process). The determination result of the authentication process indicates a positive authentication result (authentication success) indicating that the authentication has been successful, or a negative authentication result (authentication failure) indicating that the authentication has failed.

[0058] If the execution result of the authentication program is a positive authentication result (authentication successful) (S106: YES), the processing unit 11 of the in-vehicle device 1 releases the function restriction on the external device 141 (releases device restriction) (S107). If the execution result of the authentication program is a positive authentication result (authentication successful), the processing unit 11 of the in-vehicle device 1 releases the function restriction on the external device 141 that was applied as the initial setting (releases device restriction). After executing the authentication program, the processing unit 11 of the in-vehicle device 1 switches the device class in the sequence between the in-vehicle device 1 (USB host) and the external device 141 (USB device) from the authentication device class to the application device class.

[0059] The processing unit 11 of the in-car device 1 requests (descriptor request) the external device 141 to transmit device definition information (descriptor information) (S108). When executing a second descriptor request, the processing unit 11 of the in-car device 1 may perform a process of detecting the external device 141 again at the connection port 14. The processing unit 11 of the in-car device 1 requests (descriptor request) the external device 141 to transmit the second device definition information (descriptor information). In the second descriptor request, the processing unit 11 of the in-car device 1 requests the external device 141 to transmit descriptor information including a device class for an application.

[0060] The processing unit 11 of the in-car device 1 acquires device definition information (descriptor information) from the external device 141 (S109). In response to a request from the processing unit 11 of the in-car device 1, the external device 141 transmits (outputs) the device definition information (descriptor information) including the application device class to the in-car device 1. The processing unit 11 of the in-car device 1 acquires the device definition information (descriptor information) from the external device 141 and stores it in the storage unit 12.

[0061] The processing unit 11 of the in-car device 1 detects (extracts) an application device class included in the device definition information (descriptor information) (S110). The processing unit 11 of the in-car device 1 identifies an application corresponding to the application device class included in the device definition information (descriptor information) (S111). The processing unit 11 of the in-car device 1 identifies the application based on the application device class detected (extracted) from the device definition information (descriptor information). The correspondence between each application device class and each application is defined, for example, in a table format (application device class table) and stored in the storage unit 12. The processing unit 11 of the in-car device 1 may identify the application by referring to the application device class table.

[0062] The processing unit 11 of the in-car device 1 executes the identified application (S112). By executing the identified application, the processing unit 11 of the in-car device 1 can realize all functions that the external device 141 has in the product specifications. This process is performed when the authentication result is positive (authentication is successful), and the function restriction (device restriction) on the external device 141 is lifted. Therefore, the in-car device 1 (USB host) and the external device 141 (USB device) can realize the function according to the executed application (start USB communication), and the external device 141 (USB device) can operate according to the product specifications.

[0063] If the execution result of the authentication program is not a positive authentication result (authentication success) (S106: NO), the function restriction on the external device 141 is maintained (device restriction maintenance) (S1061). If the execution result of the authentication program is not a positive authentication result (authentication success), i.e., if the execution result is a negative authentication result (authentication failure), the processing unit 11 of the in-vehicle device 1 maintains the function restriction on the external device 141 that was initially set when the connection was detected at the connection port 14 (device restriction maintenance). The processing unit 11 of the in-vehicle device 1 may store device definition information (descriptor information) in the case of a negative authentication result (authentication failure) in the storage unit 12 as an unauthorized device detection result for the connected external device 141 (USB device).

[0064] The processing unit 11 of the in-vehicle device 1 requests the external device 141 to transmit device definition information (descriptor information) (descriptor request) (S1062). The processing unit 11 of the in-vehicle device 1 acquires the device definition information (descriptor information) from the external device 141 (S1063). When executing another descriptor request or the like, the processing unit 11 of the in-vehicle device 1 may perform a process of detecting the external device 141 again at the connection port 14. The processing unit 11 of the in-vehicle device 1 detects (extracts) an application device class included in the device definition information (descriptor information) (S1064). The processing unit 11 of the in-vehicle device 1 identifies an application corresponding to the application device class included in the device definition information (descriptor information) (S1065). The processing unit 11 of the in-vehicle device 1 performs the processes of S1062 to S1065 in the same manner as the processes of S108 to S111.

[0065] The processing unit 11 of the in-vehicle device 1 executes the specified application (S1066). This process is performed when the authentication result is negative (authentication failure), and the function restriction (device restriction) for the external device 141 is maintained. The function restriction (device restriction) includes, for example, an operation restriction to only supply power to the USB device, or an operation restriction to perform communication limited to non-secure information such as media data. The processing unit 11 of the in-vehicle device 1 applies such a function restriction (device restriction) and then executes an application corresponding to the device class for the application, so that the external device 141 (USB device) can perform only limited operation processing. Alternatively, the processing unit 11 of the in-vehicle device 1 may block the power supply and communication for the USB device as the function restriction (device restriction). In this way, when the authentication result is negative (authentication failure), the processing unit 11 of the in-vehicle device 1 applies a function restriction to operate the external device 141, thereby ensuring a secure in-vehicle communication environment.

[0066] If the authentication device class is not included (S104: NO), the processing unit 11 of the in-vehicle device 1 maintains the function restriction on the external device 141 (maintain device restriction) (S1041). If the device definition information (descriptor information) does not include the authentication device class, the processing unit 11 of the in-vehicle device 1 determines that the external device 141 connected to the connection port 14 is an unauthenticated device. Then, the processing unit 11 of the in-vehicle device 1 performs S1041 in the same manner as processing S1061.

[0067] The processing unit 11 of the in-vehicle device 1 detects (extracts) the device class for the application included in the device definition information (descriptor information) acquired first (in the process of S103) (S1042). The processing unit 11 of the in-vehicle device 1 identifies an application corresponding to the device class for the application included in the device definition information (descriptor information) (S1043). The processing unit 11 of the in-vehicle device 1 executes the identified application (S1044). The processing unit 11 of the in-vehicle device 1 executes S1042 to S1044 in the same manner as the process of S1064 to S1066. This process is executed when the authentication result is negative (authentication failure), and the function restriction (device restriction) for the external device 141 is maintained. The function restriction (device restriction) may be the same type of restriction as the function restriction (device restriction) when the execution result of the authentication program is negative authentication result (authentication failure), or may be a different type of restriction.

[0068] (Embodiment 2) 5 is a flowchart illustrating the processing of the processing unit 11 of the in-vehicle device 1 according to the second embodiment (single device definition information). The processing unit 11 of the in-vehicle device 1 performs the following processing at all times, for example, while the vehicle C is running or stopped. The processing unit 11 of the in-vehicle device 1 performs the processing from S201 to S202 in the same manner as S101 to S102 in the embodiment.

[0069] The processing unit 11 of the in-vehicle device 1 acquires device definition information (descriptor information) from the external device 141 (S203). The external device 141 connected to the connection port 14 is assumed to be an authentication-enabled device that supports the authentication device class, or an authentication-incompatible device that does not support the authentication device class. The device definition information (descriptor information) from the external device 141 that is an authentication-enabled device includes both the authentication device class and the application device class as device classes. The device definition information (descriptor information) from the external device 141 that is an authentication-incompatible device includes only the application device class as device class.

[0070] The processing unit 11 of the in-vehicle device 1 determines whether the acquired device definition information (descriptor information) includes an authentication device class (S204). The device class included in the device definition information (descriptor information) differs depending on whether the external device 141 connected to the connection port 14 is an authentication-enabled device or an authentication-incompatible device. The processing unit 11 of the in-vehicle device 1 can determine whether the external device 141 is an authentication-enabled device or an authentication-incompatible device depending on whether the device definition information (descriptor information) includes an authentication device class.

[0071] The processing unit 11 of the in-vehicle device 1 performs processes from S205 to S207 similar to S105 to S107 in the embodiment. Furthermore, the processing unit 11 of the in-vehicle device 1 performs processes from S208 to S210 similar to S110 to S112 in the embodiment. Furthermore, the processing unit 11 of the in-vehicle device 1 performs processes from S2061 and S2062 to S2064 similar to S1061 and S1064 to S1066 in the embodiment. Furthermore, the processing unit 11 of the in-vehicle device 1 performs processes from S2041 to S2044 similar to S1041 to S1044 in the embodiment.

[0072] In this embodiment, the device definition information (descriptor information) from the external device 141, which is an authentication-compatible device, includes an authentication device class and an application device class. Therefore, a descriptor request can be made only once between the in-car device 1 and the external device 141, and the time required for sequence processing by the in-car device 1 and the external device 141 can be shortened.

[0073] (Embodiment 3) 6 is a flowchart illustrating the processing of the processing unit 11 of the in-vehicle device 1 according to the third embodiment (state of the vehicle C). The processing unit 11 of the in-vehicle device 1 performs the following processing at all times, for example, while the vehicle C is running or stopped. The processing unit 11 of the in-vehicle device 1 performs the processing of S301 similarly to S101 in the embodiment.

[0074] The processing unit 11 of the in-vehicle device 1 judges whether the vehicle C is in a running state (S302). The processing unit 11 of the in-vehicle device 1 acquires state information on the state of the vehicle C from the in-vehicle ECU 2 communicably connected via the in-vehicle network 3, for example, and judges whether the vehicle C is in a running state based on the state information. The state information is information on the state of the vehicle C, and indicates, for example, a running state and a stopped state indicating a state other than a running state. The processing unit 11 of the in-vehicle device 1 may acquire, for example, a signal from a power switch or an IG switch that controls the start or stop of the vehicle C, and derive whether the state of the vehicle C is in a running state or a stopped state based on the signal. Alternatively, the processing unit 11 of the in-vehicle device 1 may acquire, for example, output values ​​(sensor values) of actuators of a vehicle speed sensor, an engine, or a drive motor from the in-vehicle ECU 2 that controls these actuators, and derive whether the state of the vehicle C is in a running state or a stopped state based on the output values ​​(sensor values).

[0075] If the vehicle C is in a traveling state (S302: YES), the processing unit 11 of the in-vehicle device 1 performs a loop process to execute the process of S302 again. As a result, the processing unit 11 of the in-vehicle device 1 performs a standby process until the vehicle C is no longer in a traveling state, that is, until the vehicle C is in a stopped state. By performing the standby process in this manner, even if it is detected that an external device 141 (USB device) is connected to the connection port 14 (USB port) while the vehicle C is traveling, it is possible to suspend a series of processes for the external device 141. Then, when the vehicle C transitions from a traveling state to a stopped state, it is possible to resume the suspended processes and execute authentication processes, operation processes, and the like for the external device 141.

[0076] If the vehicle C is not in a traveling state (S302: NO), the processing unit 11 of the in-vehicle device 1 requests (descriptor request) the external device 141 to transmit device definition information (descriptor information) (S303). The processing unit 11 of the in-vehicle device 1 performs the processes of S303 to S313, S3054, and S3076, similar to S102 to S112, S1044, and S1066 in the first embodiment.

[0077] In the present embodiment, when the vehicle C is in a running state (when the state information indicates a running state), the processing from S302, i.e., the processing related to the request and acquisition of the descriptor information including the authentication device class, is suspended, but this is not limited thereto. When the vehicle C is in a running state (when the state information indicates a running state), the processing unit 11 of the in-vehicle device 1 may suspend the processing from S308, i.e., the processing after the device class is switched from the authentication device class to the application device class. Alternatively, the storage unit 12 of the in-vehicle device 1 may store suspension definition information that defines the processing (e.g., step number in a flowchart) to be suspended when the vehicle C is in a running state, and the processing unit 11 of the in-vehicle device 1 may determine the processing to be suspended when the vehicle C is in a running state according to the suspension definition information.

[0078] The embodiments disclosed herein are illustrative in all respects and should not be considered as limiting. The scope of the present invention is defined by the claims, not by the above meaning, and is intended to include all modifications within the scope and meaning equivalent to the claims.

[0079] The claims may be combined with each other regardless of the form of reference. The claims may contain multiple dependent claims depending on multiple claims. Multiple dependent claims may be contained depending on multiple dependent claims. If multiple dependent claims are not contained depending on a multiple dependent claim, this does not limit the number of dependent claims depending on a multiple dependent claim. [Explanation of symbols]

[0080] C Vehicle S In-vehicle system 1. Vehicle-mounted device (USB host) 11 Processing section 12 Storage section M Recording medium P Control program (program product) 13. Communications Department 14 Connection port (USB port) 141 External device (USB device) 2 In-vehicle ECU 3. In-vehicle network 31 Communication Line 5 Power supply 51 Power Lines

Claims

1. a connection port mounted in the vehicle and to which an external device is connected; a processing unit that processes the external device connected to the connection port, The processing unit includes: Acquires device definition information from the external device connected to the connection port; If the acquired device definition information includes an authentication device class, an authentication program corresponding to the authentication device class is executed. In-vehicle device.

2. the external device is a USB device, the connection port is a USB port, The USB device and the USB port are USB 2.0 or USB 1.1 compliant. The in-vehicle device according to claim 1 .

3. The processing unit includes: When an execution result of an authentication program corresponding to the authentication device class is a positive authentication result, a process corresponding to an application device class included in device definition information acquired from the external device is executed without imposing any functional restrictions; When the execution result of the authentication program corresponding to the authentication device class is a negative authentication result, a process corresponding to the application device class included in the device definition information acquired from the external device is executed with a function restriction. The vehicle-mounted device according to claim 2 .

4. The processing unit stores device definition information including the authentication device class when an execution result of an authentication program corresponding to the authentication device class results in a negative authentication result. The vehicle-mounted device according to claim 3.

5. When the processing unit detects that the external device is connected to the connection port, the processing unit executes a process related to device definition information including the authentication device class for the external device, and then executes a process related to device definition information including the application device class for the external device. The vehicle-mounted device according to claim 3.

6. When the processing unit detects that the external device is connected to the connection port, the device definition information acquired does not include the authentication device class. The external device is determined to be an unauthenticated device, The process corresponding to the device class for the application included in the device definition information acquired from the external device is executed with functional restrictions. The vehicle-mounted device according to claim 3.

7. The processing unit includes: obtaining status information relating to a status of the vehicle; When the state information indicates a traveling state, at least a part of the processing related to the device definition information transmitted from the external device is suspended. The vehicle-mounted device according to claim 3.

8. A computer having a connection port to which an external device mounted on a vehicle is connected, Acquires device definition information from the external device connected to the connection port; If the acquired device definition information includes an authentication device class, an authentication program corresponding to the authentication device class is executed. A program that executes a process.

9. A computer having a connection port to which an external device mounted on a vehicle is connected, Acquires device definition information from the external device connected to the connection port; If the acquired device definition information includes an authentication device class, an authentication program corresponding to the authentication device class is executed. An information processing method for executing a process.