Relay device, vehicle communication method, and vehicle communication program
The relay device improves in-vehicle network security by continuously authenticating and relaying data within the network, even when communication with external devices is poor, addressing the challenges of adding new units and expired authentication information.
Patent Information
- Application Number
- JP2025033007
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2019-07-05
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2040-06-11
AI Technical Summary
Existing in-vehicle network systems lack effective security measures to ensure secure communication and authentication of functional units, particularly when new units are added or when authentication information expires.
A relay device mounted on a vehicle with an authentication processing unit that acquires and updates authentication information from an external device, and a relay processing unit that relays information based on authentication results, ensuring continuous security even when communication with the external device is poor.
The solution enhances the security of in-vehicle networks by ensuring continuous authentication and data relay, even in challenging driving environments, thereby maintaining network stability and security.
Smart Images

Figure 2025081735000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a relay device and a vehicle communication method. This application claims priority based on Japanese Patent Application No. 2019-126255 filed on Jul. 5, 2019, and incorporates all of the disclosure thereof herein.
Background Art
[0002] Patent Document 1 (Japanese Unexamined Patent Application Publication No. 2013-193598) discloses a vehicle authentication device as follows. That is, the vehicle authentication device is mounted on a vehicle and is a vehicle authentication device (11) provided in an electronic control device (1) connected via an in-vehicle network to an in-vehicle communication device (2) capable of communicating at least wirelessly with an external device (3) outside the vehicle using the Internet protocol. When information including identification information for identifying the external device is transmitted from the external device to the communication device, identification information acquisition means (11, S1) for acquiring the identification information, state determination means (11, S5) for determining whether or not the state of the vehicle corresponds to a security ensured state indicating that a legitimate user permitted to operate the vehicle has operated or has operated on the vehicle, registration means (11, S7) for registering the identification information acquired by the identification information acquisition means in a storage device (12) mounted on the vehicle when it is determined by the state determination means that the security ensured state is satisfied, and not registering the identification information in the storage device when it is determined that the security ensured state is not satisfied, registration determination means (11, S2) for determining whether or not the identification information is registered in the storage device when the identification information acquisition means acquires the identification information, and authentication means (11, S3, S6) for permitting information exchange between the external device identified by the identification information and the electronic control device when it is determined by the registration determination means that the identification information is registered in the storage device, and prohibiting information exchange between the external device identified by the identification information and the electronic control device based on the determination by the registration determination means that the identification information is not registered in the storage device.
Prior Art Documents
Patent Document
[0003]
Patent Document 1
Summary of the Invention
[0004] The relay device of the present disclosure is a relay device mounted on a vehicle including a plurality of functional units, and includes an authentication processing unit that acquires authentication information of the functional units from an external device outside the vehicle and performs authentication processing of the functional units using the acquired authentication information, and a relay processing unit that relays information between the functional units and other functional units based on the result of the authentication processing by the authentication processing unit. When the expiration date of the authentication information has expired, the authentication processing unit acquires new authentication information from the external device.
[0005] The vehicle communication method of the present disclosure is a vehicle communication method in a relay device mounted on a vehicle including a plurality of functional units, and includes steps of acquiring authentication information of the functional units from an external device outside the vehicle, performing authentication processing of the functional units using the acquired authentication information, relaying information between the functional units and other functional units based on the result of the authentication processing, and acquiring new authentication information from the external device when the expiration date of the authentication information has expired.
[0006] One aspect of the present disclosure can be realized as a semiconductor integrated circuit that realizes part or all of the relay device, or can be realized as a system including the relay device. Also, one aspect of the present disclosure can be realized as a program for causing a computer to execute processing steps in the relay device.
Brief Description of the Drawings
[0007]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
[0008] Conventionally, in-vehicle network systems have been developed to improve security in in-vehicle networks.
[0009] [Problems to be Solved by the Present Disclosure] Beyond the technology described in Patent Document 1, a technology capable of improving security in in-vehicle networks is desired.
[0010] The present disclosure has been made to solve the above problems, and an object thereof is to provide a relay device and a vehicle communication method capable of improving security in in-vehicle networks.
[0011] [Effects of the Present Disclosure] According to the present disclosure, the security in an in-vehicle network can be improved.
[0012] [Description of Embodiments of the Present Disclosure] First, the contents of the embodiments of the present disclosure will be listed and described.
[0013] (1) The relay device according to an embodiment of the present disclosure is a relay device mounted on a vehicle including a plurality of functional units, and includes an authentication processing unit that acquires authentication information of the functional units from an external device outside the vehicle and performs authentication processing of the functional units using the acquired authentication information, and a relay processing unit that relays information between the functional unit and other functional units based on a result of the authentication processing by the authentication processing unit. When the expiration date of the authentication information has passed, the authentication processing unit acquires new authentication information from the external device.
[0014] In this way, even when a new unknown functional unit is added to the in-vehicle network, the authentication information of the functional unit can be acquired by the configuration of acquiring the authentication information of the functional unit from an external device outside the vehicle. Further, when the expiration date has passed, new authentication information is acquired, authentication processing of the functional unit using the acquired authentication information is performed, and based on the result of the authentication processing, the information between the functional units is relayed, so that the security of the in-vehicle network can be guaranteed, and even in a situation where the communication environment between the relay device and the external device is poor due to the driving environment of the vehicle and it is difficult to acquire new authentication information from the external device, the authentication processing of the functional unit can be continuously performed using the authentication information. Therefore, the security in the in-vehicle network can be improved.
[0015] (2) Preferably, when the expiration date of the authentication information has passed and the relay device cannot communicate with the external device, the authentication processing unit performs an extension process of maintaining the validity of the authentication information, and performs authentication processing of the functional unit corresponding to the authentication information using extension authentication information that is the authentication information whose validity has been maintained.
[0016] With such a configuration, when the expiration date of the authentication information has passed and the communication environment between the relay device and the external device is poor due to the driving environment of the vehicle and it is impossible to obtain new authentication information, the authentication process can be performed and the relay of information between functional units based on the authentication result can be continued. Thereby, for example, in a configuration in which security is improved by updating the content of the authentication information outside the vehicle, stable communication in the in-vehicle network can be managed regardless of the driving environment of the vehicle.
[0017] (3) Preferably, the relay processing unit determines the content of the information to be relayed when the authentication process using the extended authentication information by the authentication processing unit is successful, according to the type of the functional unit.
[0018] With such a configuration, according to the type of the functional unit, a part of the information to be relayed when the extension process is performed can be restricted. Therefore, for example, while continuing the relay of information between functional units that affect the driving of the vehicle, by stopping the relay of information between functional units that do not affect the driving of the vehicle, it is possible to suppress a decrease in security in the in-vehicle network while maintaining good driving of the vehicle.
[0019] (4) Preferably, the relay processing unit determines whether to perform the relay when the authentication process using the extended authentication information by the authentication processing unit is successful, according to the type of the information received from the functional unit.
[0020] With such a configuration, according to the type of the information received from the functional unit, a part of the information to be relayed when the extension process is performed can be restricted. Therefore, for example, while continuing the relay of information that affects the driving of the vehicle, by stopping the relay of information that does not affect the driving of the vehicle, it is possible to suppress a decrease in security in the in-vehicle network while maintaining good driving of the vehicle.
[0021] (5) Preferably, the authentication processing unit obtains the authentication information having different content from the external device every time the authentication information is obtained.
[0022] With such a configuration, every time the expiration date is reached, new authentication information can be obtained, and the authentication process of the functional unit can be performed using the authentication information, so that the security in the in-vehicle network can be further improved.
[0023] (6) Preferably, when the vehicle is running in a state where the authentication processing unit can communicate between the relay device and the external device and the expiration date of the authentication information has expired, an extension process is performed to maintain the validity of the authentication information without obtaining new authentication information from the external device.
[0024] With such a configuration, for example, by performing an authentication process using new authentication information, an authentication error may occur, and it is possible to avoid stopping the relay of part or all of the information between the functional units during the running of the vehicle, and maintain the good running of the vehicle.
[0025] (7) The vehicle communication method according to the embodiment of the present disclosure is a vehicle communication method in a relay device mounted on a vehicle including a plurality of functional units, including steps of obtaining authentication information of the functional unit from an external device outside the vehicle, performing an authentication process of the functional unit using the obtained authentication information, relaying information between the functional unit and other functional units based on the result of the authentication process, and obtaining new authentication information from the external device when the expiration date of the authentication information has expired.
[0026] In this way, even when a new unknown functional unit is added to the in-vehicle network, the authentication information of the functional unit can be obtained by the method of obtaining the authentication information of the functional unit from an external device outside the vehicle. Further, when the expiration date has passed, new authentication information is obtained, the authentication process of the functional unit using the obtained authentication information is performed, and based on the result of the authentication process, the information between the functional units is relayed, so that the security of the in-vehicle network can be guaranteed. Also, even in a situation where the communication environment between the relay device and the external device is poor due to the driving environment of the vehicle and it is difficult to obtain new authentication information from the external device, the authentication process of the functional unit can be continuously performed using the authentication information. Therefore, the security in the in-vehicle network can be improved.
[0027] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals and their description will not be repeated. Also, at least a part of the embodiments described below may be arbitrarily combined.
[0028] [Communication System] FIG. 1 is a diagram showing the configuration of a communication system according to an embodiment of the present disclosure.
[0029] Referring to FIG. 1, the communication system 401 includes a server 181 and an in-vehicle communication system 301. The in-vehicle communication system 301 is mounted on the vehicle 1.
[0030] FIG. 2 is a diagram showing the configuration of an in-vehicle communication system according to an embodiment of the present invention.
[0031] Referring to FIG. 2, the in-vehicle communication system 301 includes in-vehicle ECUs (Electronic Control Units) 200A to 200D and a relay device 100.
[0032] Hereinafter, each of the in-vehicle ECUs 200A to 200D will also be referred to as the in-vehicle ECU 200. The in-vehicle ECU 200 and the relay device 100 are examples of in-vehicle devices.
[0033] Note that the in-vehicle communication system 301 is not limited to a configuration including four in-vehicle ECUs 200, and may have a configuration including three or fewer or five or more in-vehicle ECUs 200. Also, the in-vehicle communication system 301 is not limited to a configuration including one relay device 100, and may have a configuration including two or more relay devices 100.
[0034] The in-vehicle ECU 200 and the relay device 100 constitute the in-vehicle network 12. The in-vehicle ECU 200 is an example of a functional unit in the in-vehicle network 12.
[0035] In the in-vehicle network 12, the in-vehicle ECU 200 is connected to the relay device 100 via, for example, an Ethernet (registered trademark) cable 13.
[0036] The relay device 100 is, for example, a switch device and can relay information between a plurality of in-vehicle ECUs 200 connected to itself. More specifically, the relay device 100 can perform relay processing according to, for example, layer 2 and layer 3 above layer 2.
[0037] The in-vehicle ECU 200A is, for example, a TCU (Telematics Communication Unit). Hereinafter, the in-vehicle ECU 200A is also referred to as the TCU 200A.
[0038] The in-vehicle ECUs 200B to 200D are, for example, an automatic driving ECU (Electronic Control Unit), sensors, a navigation device, an accelerator control ECU, a brake control ECU, a steering control ECU, and a human machine interface, etc.
[0039] For example, the in-vehicle ECU 200D is not connected to the relay device 100 in the initial state. The in-vehicle ECU 200D is installed in the vehicle 1 at, for example, any one of a manufacturing factory of the vehicle 1, a dealer of the vehicle 1, and a sales store of after-parts of the vehicle 1, and is connected to the relay device 100 via an Ethernet cable.
[0040] The relay device 100 performs the relay process of Ethernet frames according to the Ethernet communication standard. Specifically, the relay device 100 relays, for example, the Ethernet frames exchanged between in-vehicle ECUs 200. An IP packet is stored in the Ethernet frame.
[0041] Note that in the in-vehicle communication system 301, the configuration is not limited to relaying Ethernet frames according to the Ethernet communication standard. For example, a configuration in which data is relayed according to communication standards such as CAN (Controller Area Network) (registered trademark), FlexRay (registered trademark), MOST (Media Oriented Systems Transport) (registered trademark), and LIN (Local Interconnect Network) may also be used.
[0042] Referring to FIGS. 1 and 2, the TCU 200A can communicate with the server 181 outside the vehicle 1. Specifically, the TCU 200A can communicate with the server 181 via the radio base station device 161 using, for example, IP packets.
[0043] More specifically, the TCU 200A can perform wireless communication with the radio base station device 161 outside the vehicle 1 according to a communication standard such as LTE (Long Term Evolution) or 3G.
[0044] Specifically, when the radio base station device 161 receives an IP packet from the server 181 outside the vehicle 1 via the external network 11, it includes the received IP packet in a wireless signal and transmits it to the TCU 200A.
[0045] When the TCU 200A receives, for example, a wireless signal including an IP packet from the server 181 from the radio base station device 161, it acquires the IP packet from the received wireless signal, stores the acquired IP packet in an Ethernet frame, and transmits it to the relay device 100.
[0046] When the TCU200A receives an Ethernet frame from the relay device 100, it acquires an IP packet from the received Ethernet frame and includes the acquired IP packet in a wireless signal and transmits the wireless signal to the wireless base station device 161.
[0047] When the wireless base station device 161 receives a wireless signal from the TCU200A, it acquires an IP packet from the received wireless signal and transmits the acquired IP packet to the server 181 via the external network 11.
[0048] [In-vehicle ECU] FIG. 3 is a diagram showing the configuration of the in-vehicle ECU according to an embodiment of the present disclosure.
[0049] Referring to FIG. 3, the in-vehicle ECU 200 includes a communication unit 210, a processing unit 220, an authentication request unit 230, and a storage unit 240. The storage unit 240 is, for example, a flash memory.
[0050] When the communication unit 210 receives an Ethernet frame from the relay device 100 via the corresponding Ethernet cable 13, it outputs the received Ethernet frame to the processing unit 220.
[0051] The processing unit 220 acquires information included in the Ethernet frame received from the communication unit 210 and performs predetermined processing using the acquired information.
[0052] Further, the processing unit 220 generates an Ethernet frame addressed to another in-vehicle ECU 200 and outputs the generated Ethernet frame to the communication unit 210.
[0053] When the communication unit 210 receives an Ethernet frame from the processing unit 220, it transmits the received Ethernet frame to the relay device 100 via the corresponding Ethernet cable 13.
[0054] Further, when the processing unit 220 acquires a common key, which will be described later, from the Ethernet frame received from the communication unit 210, it outputs the acquired common key to the authentication request unit 230.
[0055] When the authentication request unit 230 receives the common key from the processing unit 220, it stores the received common key in the storage unit 240.
[0056] In addition, when the in-vehicle ECU 200 of itself is connected to the relay device 100 via the Ethernet cable 13, the authentication request unit 230 generates an Ethernet frame in which authentication request information including its own ID, for example, the MAC address, is stored, and transmits the generated Ethernet frame to the relay device 100 via the communication unit 210.
[0057] [Relay device] FIG. 4 is a diagram showing the configuration of the relay device according to an embodiment of the present disclosure.
[0058] Referring to FIG. 4, the relay device 100 includes communication ports 52A, 52B, 52C, 52D, a communication unit 110, a relay processing unit 120, a detection unit 130, an authentication processing unit 140, a storage unit 150, and a timer 160. The storage unit 150 is, for example, a flash memory.
[0059] For example, the relay device 100 includes a number of timers 160 corresponding to the communication ports 52A, 52B, 52C, 52D. Specifically, the relay device 100 includes timers 160A, 160B, 160C, 160D as the timer 160.
[0060] Hereinafter, each of the communication ports 52A, 52B, 52C, 52D is also referred to as a communication port 52. The communication port 52 is, for example, a terminal to which an Ethernet cable can be connected.
[0061] In this example, the communication ports 52A, 52B, 52C are connected to the TCU 200A, the in-vehicle ECU 200B, and the in-vehicle ECU 200C, respectively.
[0062] When the communication unit 110 receives an Ethernet frame from a certain in-vehicle ECU 200 via the corresponding communication port 52, it outputs the received Ethernet frame to the relay processing unit 120.
[0063] In addition, when the communication unit 110 receives an Ethernet frame addressed to a certain in-vehicle ECU 200 from the relay processing unit 120, it transmits the received Ethernet frame to the in-vehicle ECU 200 via the corresponding communication port 52.
[0064] The relay processing unit 120 performs relay processing of Ethernet frames between in-vehicle ECUs 200. Specifically, for example, when the relay processing unit 120 receives an Ethernet frame from the communication unit 110, it performs layer 2 relay processing and layer 3 relay processing on the received Ethernet frame.
[0065] In addition, when the relay processing unit 120 receives an Ethernet frame storing authentication request information from an in-vehicle ECU 200 newly added to the in-vehicle network 12, it acquires the authentication request information from the received Ethernet frame and outputs the acquired authentication request information to the detection unit 130.
[0066] [Detection Unit] The detection unit 130 detects a newly added new function unit in the in-vehicle network 12. For example, the detection unit 130 detects an in-vehicle ECU 200D newly added to the in-vehicle network 12 as a new function unit.
[0067] Referring to FIGS. 2 and 4, the in-vehicle ECU 200D is connected to the communication port 52D in the relay device 100 via the Ethernet cable 13.
[0068] The detection unit 130 in the relay device 100 detects the addition of the in-vehicle ECU 200D to the in-vehicle network 12 by receiving the authentication request information from the in-vehicle ECU 200D via the relay processing unit 120.
[0069] The detection unit 130 outputs the authentication request information received from the relay processing unit 120 to the authentication processing unit 140.
[0070] [Authentication Processing Unit] The authentication processing unit 140 acquires the authentication information of the in-vehicle ECU 200 from an external device outside the vehicle 1.
[0071] More specifically, when the authentication processing unit 140 receives the authentication request information from the detection unit 130, it obtains, for example, in accordance with the procedure compliant with IEEE802.1X, the authentication information of the in-vehicle ECU 200D, which is the new functional unit indicated by the authentication request information, from the server 181.
[0072] The server 181 generates the authentication information of the in-vehicle ECU 200 by performing the authentication process of the in-vehicle ECU 200 using an authentication protocol, for example, in accordance with the procedure compliant with IEEE802.1X. Hereinafter, the authentication process of the in-vehicle ECU 200 by the server 181 is also referred to as an off-vehicle authentication process.
[0073] Here, as the authentication method in the off-vehicle authentication process by the server 181, depending on the authentication protocol used in the authentication process, for example, there are EAP (Extended Authentication Protocol)-MD (Messege Digest algorithm) 5, EAP-TLS (Transport Layer Security), PEAP (Protected EAP), LEAP (Lightweight EAP), and EAP-TTLS (EAP-Tunneled Transport Layer Security), etc.
[0074] For example, the storage unit 150 stores the authentication method in the off-vehicle authentication process by the server 181.
[0075] When the authentication processing unit 140 receives the authentication request information from the detection unit 130, it obtains the authentication method in the off-vehicle authentication process by the server 181 from the storage unit 150, and transmits the authentication method information indicating the obtained authentication method to the in-vehicle ECU 200D, which is the new functional unit indicated by the authentication request information, via the relay processing unit 120 and the communication unit 110.
[0076] The in-vehicle ECU 200D and the server 181 perform an exchange of EAP messages including information necessary for the off-vehicle authentication process via the relay device 100.
[0077] The authentication processing unit 140 in the relay device 100 relays EAP messages and the like exchanged between the server 181 and the in-vehicle ECU 200D.
[0078] More specifically, when the authentication processing unit 140 receives an Ethernet frame storing an EAP message from the in-vehicle ECU 200D via the communication unit 110 and the relay processing unit 120, it converts the received Ethernet frame into a RADIUS (Remote Authentication Dial In User Service) frame, and transmits the converted RADIUS frame to the server 181 via the communication unit 110 and the TCU 200A.
[0079] Also, when the authentication processing unit 140 receives a RADIUS frame from the server 181 via the TCU 200A, the communication unit 110, and the relay processing unit 120, it converts the received RADIUS frame into an Ethernet frame, and transmits the converted Ethernet frame to the in-vehicle ECU 200D via the communication unit 110.
[0080] The server 181 performs an out-vehicle authentication process for the in-vehicle ECU 200D using the EAP message received from the in-vehicle ECU 200 via the relay device 100. When the server 181 succeeds in authenticating the in-vehicle ECU 200D through the out-vehicle authentication process, it generates authentication information indicating authentication success, and transmits the generated authentication information to the relay device 100 via the radio base station device 161 and the TCU 200A.
[0081] On the other hand, when the server 181 fails to authenticate the in-vehicle ECU 200D, it generates authentication information indicating authentication failure, and transmits the generated authentication information to the relay device 100 via the radio base station device 161 and the TCU 200A.
[0082] When the authentication processing unit 140 receives authentication information indicating authentication success from the server 181 via the TCU 200A, the communication unit 110, and the relay processing unit 120, it generates out-vehicle authentication success information indicating that the out-vehicle authentication process has succeeded, and outputs the generated out-vehicle authentication success information to the relay processing unit 120.
[0083] When the relay processing unit 120 receives the vehicle exterior authentication success information from the authentication processing unit 140, it transmits the received vehicle exterior authentication success information to the in-vehicle ECU 200D via the communication unit 110.
[0084] Here, when the authentication processing unit 140 receives the authentication information indicating authentication success from the server 181 via the communication unit 110 and the relay processing unit 120, it sets the valid time of the authentication information in the timer 160 for each in-vehicle ECU 200.
[0085] For example, the authentication processing unit 140 sets the valid time of the authentication information of the TCU 200A connected to the communication port 52A in the timer 160A, sets the valid time of the authentication information of the in-vehicle ECU 200B connected to the communication port 52A in the timer 160B, sets the valid time of the authentication information of the in-vehicle ECU 200C connected to the communication port 52C in the timer 160C, and sets the valid time of the authentication information of the in-vehicle ECU 200D connected to the communication port 52D in the timer 160D.
[0086] On the other hand, when the authentication processing unit 140 receives the authentication information indicating authentication failure from the server 181 via the TCU 200A, the communication unit 110, and the relay processing unit 120, it outputs connection not permitted information to the relay processing unit 120.
[0087] When the relay processing unit 120 receives the connection not permitted information from the authentication processing unit 140, it transmits the received connection not permitted information to the in-vehicle ECU 200D via the communication unit 110.
[0088] The authentication processing unit 140 performs the authentication process of the in-vehicle ECU 200 using the authentication information indicating authentication success acquired from the server 181. Hereinafter, the authentication process of the in-vehicle ECU 200 by the authentication processing unit 140 is also referred to as the in-vehicle authentication process.
[0089] The relay processing unit 120 relays the information between the in-vehicle ECUs 200 based on the result of the in-vehicle authentication process by the authentication processing unit 140.
[0090] (Authentication Example 1) For example, the authentication information indicating authentication success that the authentication processing unit 140 receives from the server 181 includes a common key.
[0091] When the authentication processing unit 140 receives the authentication information of the in-vehicle ECU 200 from the server 181 via the TCU 200A, the communication unit 110, and the relay processing unit 120, the authentication processing unit 140 sets a predetermined valid time of the received authentication information in the corresponding timer 160.
[0092] Then, the authentication processing unit 140 acquires the common key from the received authentication information, associates the acquired common key with the in-vehicle ECU 200, and stores it in the storage unit 150. For example, the authentication processing unit 140 associates the acquired common key with the communication port 52 and stores it in the storage unit 150.
[0093] In addition, the authentication processing unit 140 generates out-of-vehicle authentication success information including the common key, and transmits the generated out-of-vehicle authentication success information to the corresponding in-vehicle ECU 200 via the communication unit 110.
[0094] Referring to FIG. 3 again, when the authentication request unit 230 in the in-vehicle ECU 200 receives the out-of-vehicle authentication success information from the authentication processing unit 140 in the relay device 100 via the communication unit 210, the authentication request unit 230 acquires the common key from the received out-of-vehicle authentication success information, and stores the acquired common key in the storage unit 240.
[0095] The authentication processing unit 140 in the relay device 100 performs in-vehicle authentication processing for each in-vehicle ECU 200 using the common key in the storage unit 150, for example, periodically or irregularly.
[0096] Specifically, the authentication processing unit 140 generates a random number, for example, and transmits the generated random number to the corresponding in-vehicle ECU 200 via the communication unit 110. In addition, the authentication processing unit 140 generates encrypted data by encrypting the generated random number using the common key.
[0097] When the authentication request unit 230 in the in-vehicle ECU 200 receives the random number, it generates encrypted data by encrypting the received random number using the common key in the storage unit 240. The in-vehicle ECU 200 transmits the generated encrypted data to the relay device 100.
[0098] When the authentication processing unit 140 in the relay device 100 receives the encrypted data from the in-vehicle ECU 200 via the communication unit 110, it collates the received encrypted data with the encrypted data generated by itself.
[0099] When the encrypted data received from the in-vehicle ECU 200 matches the encrypted data generated by itself, the authentication processing unit 140 determines that the in-vehicle authentication processing of the in-vehicle ECU 200 has succeeded. Then, the authentication processing unit 140 outputs in-vehicle authentication success information indicating that the authentication of the in-vehicle ECU 200 has succeeded to the relay processing unit 120.
[0100] When the relay processing unit 120 receives the in-vehicle authentication success information from the authentication processing unit 140, it starts or continues relaying information between the in-vehicle ECU 200 and other in-vehicle ECUs 200.
[0101] More specifically, when the relay processing unit 120 receives the in-vehicle authentication success information from the authentication processing unit 140, it starts or continues relaying Ethernet frames between the in-vehicle ECU 200 and other in-vehicle ECUs 200.
[0102] On the other hand, when the encrypted data received from the in-vehicle ECU 200 does not match the encrypted data generated by itself, the authentication processing unit 140 determines that the in-vehicle authentication processing of the in-vehicle ECU 200 has failed. Then, the authentication processing unit 140 outputs in-vehicle authentication failure information indicating that the authentication of the in-vehicle ECU 200 has failed to the relay processing unit 120.
[0103] When the relay processing unit 120 receives the in-vehicle authentication failure information from the authentication processing unit 140, it stops relaying information between the in-vehicle ECU 200 and other in-vehicle ECUs 200.
[0104] More specifically, when the relay processing unit 120 receives in-vehicle authentication failure information from the authentication processing unit 140, it starts discarding the Ethernet frame received from the in-vehicle ECU 200 and the Ethernet frame addressed to the in-vehicle ECU 200 received from other in-vehicle ECUs 200.
[0105] Also, when the authentication processing unit 140 fails in the in-vehicle authentication process of the in-vehicle ECU 200, for example, according to the procedure compliant with IEEE802.1X, it acquires new authentication information of the in-vehicle ECU 200 from the server 181.
[0106] When the authentication processing unit 140 receives, from the server 181, authentication information indicating authentication success as new authentication information, it stores the common key included in the received authentication information in the storage unit 150 and sets a predetermined valid time of the new authentication information in the timer 160. Also, the authentication processing unit 140 transmits the common key to the in-vehicle ECU 200 via the relay processing unit 120 and the communication unit 110.
[0107] Then, the authentication processing unit 140 performs the in-vehicle authentication process of the in-vehicle ECU 200 again using the common key. Specifically, the authentication processing unit 140 performs generation of random numbers and encrypted data, transmission of the generated encrypted data to the in-vehicle ECU 200, and collation between the encrypted data received from the in-vehicle ECU 200 and the encrypted data generated by itself.
[0108] On the other hand, when the authentication processing unit 140 receives, from the server 181, authentication information indicating authentication failure as new authentication information, it outputs connection-disallowed information to the relay processing unit 120.
[0109] (Authentication Example 2) For example, the authentication information received by the authentication processing unit 140 from the server 181 includes the MAC address of the in-vehicle ECU 200 that has been authenticated at the server 181. Hereinafter, the MAC address of the in-vehicle ECU 200 that has been authenticated is also referred to as the authenticated MAC address.
[0110] When the authentication processing unit 140 receives the authentication information of the in-vehicle ECU 200 from the server 181 via the TCU 200A, the communication unit 110, and the relay processing unit 120, the authentication processing unit 140 sets the predetermined valid time of the received authentication information in the corresponding timer 160.
[0111] Then, the authentication processing unit 140 acquires the authenticated MAC address from the received authentication information, associates the acquired authenticated MAC address with the in-vehicle ECU 200, and stores it in the storage unit 150. For example, the authentication processing unit 140 associates the acquired authenticated MAC address with the communication port 52 and stores it in the storage unit 150.
[0112] In addition, the authentication processing unit 140 transmits the out-of-vehicle authentication success information to the corresponding in-vehicle ECU 200 via the communication unit 110.
[0113] The authentication processing unit 140 performs the authentication process of each in-vehicle ECU 200 using the authenticated MAC address in the storage unit 150, for example, periodically or irregularly.
[0114] For example, the authentication processing unit 140 acquires the source MAC address included in the Ethernet frame received by the communication unit 110 from the corresponding in-vehicle ECU 200 via the communication port 52, and collates the acquired source MAC address with the authenticated MAC address associated with the communication port 52.
[0115] When the acquired source MAC address matches the authenticated MAC address, the authentication processing unit 140 outputs in-vehicle authentication success information indicating that the authentication of the in-vehicle ECU 200 has succeeded to the relay processing unit 120.
[0116] When the relay processing unit 120 receives the in-vehicle authentication success information from the authentication processing unit 140, the relay processing unit 120 starts or continues the relay of information between the in-vehicle ECU 200 and other in-vehicle ECUs 200.
[0117] On the other hand, when the acquired source MAC address does not match the authenticated MAC address, the authentication processing unit 140 outputs in-vehicle authentication failure information indicating that the authentication of the in-vehicle ECU 200 has failed to the relay processing unit 120.
[0118] When the relay processing unit 120 receives the in-vehicle authentication failure information from the authentication processing unit 140, it starts discarding the Ethernet frame received from the in-vehicle ECU 200 and the Ethernet frame addressed to the in-vehicle ECU 200 received from another in-vehicle ECU 200.
[0119] Also, when the authentication processing unit 140 fails in the in-vehicle authentication process of the in-vehicle ECU 200, for example, according to the procedure compliant with IEEE 802.1X, it acquires new authentication information of the in-vehicle ECU 200 connected to the communication port 52 from the server 181.
[0120] When the authentication processing unit 140 receives authentication information indicating authentication success as new authentication information from the server 181, it stores the authenticated MAC address included in the received authentication information in the storage unit 150 and sets a predetermined valid time of the new authentication information in the timer 160.
[0121] Then, the authentication processing unit 140 performs the authentication process of the in-vehicle ECU 200 again using the authenticated MAC address. Specifically, the authentication processing unit 140 acquires the source MAC address included in the Ethernet frame received by the communication unit 110 via the communication port 52, and collates the acquired source MAC address with the authenticated MAC address associated with the communication port 52.
[0122] On the other hand, when the authentication processing unit 140 receives authentication information indicating authentication failure as new authentication information from the server 181, it outputs connection permission denied information to the relay processing unit 120.
[0123] [Update of Authentication Information] When the expiration date of the authentication information of a certain in-vehicle ECU 200 has expired, the authentication processing unit 140 acquires new authentication information of the in-vehicle ECU 200 from the server 181.
[0124] More specifically, when the timer 160 of the corresponding in-vehicle ECU 200 expires, the authentication processing unit 140 discards the common key or the authenticated MAC address in the storage unit 150.
[0125] Then, the authentication processing unit 140 acquires new authentication information of the in-vehicle ECU 200 from the server 181 according to procedures conforming to, for example, IEEE 802.1X.
[0126] For example, each time the server 181 performs an out-of-vehicle authentication process and succeeds in authentication, it generates authentication information with different contents. More specifically, each time the server 181 performs an out-of-vehicle authentication process and succeeds in authentication, it generates authentication information including different common keys.
[0127] That is, each time the authentication processing unit 140 acquires authentication information, the authentication information with different contents is acquired from the server 181. More specifically, the authentication processing unit 140 acquires authentication information whose common key is updated each time it is acquired from the server 181.
[0128] When the authentication processing unit 140 receives new authentication information from the server 181, it stores the common key included in the received authentication information in the storage unit 150, and sets a predetermined valid time of the authentication information in the timer 160. In addition, the authentication processing unit 140 transmits the common key to the in-vehicle ECU 200 via the relay processing unit 120 and the communication unit 110.
[0129] [Extension process] When the expiration date of the authentication information has passed and the relay device 100 cannot communicate with the server 181, the authentication processing unit 140 performs an extension process to maintain the validity of the authentication information.
[0130] For example, when the timer 160 expires, the authentication processing unit 140 transmits a communication confirmation request to the server 181 via the communication unit 110 and the TCU 200A to confirm whether the communication with the server 181 is possible.
[0131] When the server 181 receives the communication confirmation request, as a response to the communication confirmation request, it transmits communication availability information to the relay device 100 via the radio base station device 161 and the TCU 200A.
[0132] When the authentication processing unit 140 receives communication availability information from the server 181 via the communication unit 110 and the relay processing unit 120, it deletes the common key or the authenticated MAC address of the corresponding in-vehicle ECU 200 in the storage unit 150.
[0133] Then, the authentication processing unit 140 acquires new authentication information of the in-vehicle ECU 200 from the server 181 according to a procedure compliant with, for example, IEEE 802.1X.
[0134] On the other hand, when the authentication processing unit 140 cannot receive communication availability information within a predetermined period after transmitting the communication confirmation request, it determines that the relay device 100 and the server 181 are in a state where they cannot communicate, and performs an extension process to maintain the validity of the authentication information.
[0135] More specifically, the authentication processing unit 140 sets a predetermined extension time of the authentication information in the timer 160 without discarding the common key or the authenticated MAC address of the corresponding in-vehicle ECU 200 in the storage unit 150.
[0136] Alternatively, for example, when the vehicle 1 is running in a state where the relay device 100 and the server 181 can communicate and the validity period of the authentication information has expired, the authentication processing unit 140 performs an extension process without acquiring new authentication information from the server 181.
[0137] For example, the authentication processing unit 140 acquires information indicating whether the vehicle 1 is running from the in-vehicle ECU 200 such as the autonomous driving ECU via the communication unit 110 and the relay processing unit 120.
[0138] Even when the authentication processing unit 140 receives communication enablement information from the server 181 via the communication unit 110 and the relay processing unit 120, if the vehicle 1 is in motion, it sets a predetermined extension time of the authentication information in the timer 160 without discarding the common key or the authenticated MAC address of the corresponding in-vehicle ECU 200 in the storage unit 150.
[0139] After the extension process, the authentication processing unit 140 performs an in-vehicle authentication process for the corresponding in-vehicle ECU 200 using the extended authentication information, which is the authentication information that has maintained its validity. Specifically, it performs the authentication process for the in-vehicle ECU 200 using the common key or the authenticated MAC address in the storage unit 150 corresponding to the extended authentication information.
[0140] If the authentication process for the in-vehicle ECU 200 is successful as a result of the authentication processing unit 140 performing the authentication process for the in-vehicle ECU 200 using the extended authentication information, the authentication processing unit 140 outputs extended authentication success information to the relay processing unit 120.
[0141] When the relay processing unit 120 receives the extended authentication success information from the authentication processing unit 140, it continues to relay information between the in-vehicle ECU 200 and other in-vehicle ECUs 200.
[0142] After performing the extension process, the authentication processing unit 140 periodically or aperiodically transmits a communication confirmation request to the server 181 and attempts to acquire new authentication information.
[0143] Until new authentication information is acquired, the authentication processing unit 140 performs the authentication process for the in-vehicle ECU 200 using the extended authentication information.
[0144] [Relay Processing Based on Extended Authentication Information] The relay processing unit 120 determines the content of the information to be relayed when the authentication process using the extended authentication information by the authentication processing unit 140 is successful according to the type of the in-vehicle ECU 200.
[0145] Alternatively, the relay processing unit 120 determines whether to perform relay when the authentication process using the extended authentication information by the authentication processing unit 140 is successful according to the type of information received from the in-vehicle ECU 200.
[0146] The relay processing unit 120 determines the content of the information to be relayed when receiving the extended authentication success information from the authentication processing unit 140 among the information received from the in-vehicle ECU 200 and the information addressed to the in-vehicle ECU 200.
[0147] For example, the authentication information received by the authentication processing unit 140 from the server 181 includes the MAC address, IP address, and port number of the in-vehicle ECU 200 that is the communication target of the corresponding in-vehicle ECU 200, as well as the port number of the corresponding in-vehicle ECU 200, etc.
[0148] When the authentication processing unit 140 acquires these pieces of information from the authentication information, it outputs the acquired information to the relay processing unit 120.
[0149] The relay processing unit 120 determines the content of the information to be relayed when receiving the extended authentication success information from the authentication processing unit 140 based on the information received from the authentication processing unit 140.
[0150] For example, the relay processing unit 120 relays all the information between the in-vehicle ECU 200 that affects the driving status of the vehicle 1, such as the automatic driving ECU, and other in-vehicle ECUs. On the other hand, the relay processing unit 120 stops relaying the information between the in-vehicle ECU 200 that does not affect the driving status of the vehicle 1 and other in-vehicle ECUs.
[0151] Also, for example, the relay processing unit 120 discriminates the information that affects the driving status of the vehicle 1 based on the port number of the information from the corresponding in-vehicle ECU 200 and the port number of the information from the in-vehicle ECU 200 that is the communication target of the corresponding in-vehicle ECU 200, and relays all the information that affects the driving status of the vehicle 1 among the information between the in-vehicle ECU 200 and other in-vehicle ECUs.
[0152] Note that the relay processing unit 120 may be configured to determine whether to relay some or all of the information when the authentication process using the extended authentication information by the authentication processing unit 140 is successful, according to both the type of the in-vehicle ECU 200 and the type of the information received from the in-vehicle ECU 200.
[0153] [Operation flow] Each device in the communication system according to the embodiment of the present disclosure includes a computer including a memory, and an arithmetic processing unit such as a CPU in the computer reads and executes a program including some or all of the steps of the following flowcharts and sequences from the memory. The programs of these multiple devices can each be installed from the outside. The programs of these multiple devices are each distributed in a state stored in a recording medium.
[0154] FIG. 5 is a flowchart defining the operation procedure when the relay device in the communication system according to the embodiment of the present disclosure relays information between in-vehicle ECUs based on the result of the authentication process.
[0155] Referring to FIG. 5, first, the relay device 100 waits for the addition of a new functional unit to the in-vehicle network 12 (NO in step S102). When detecting the addition of the in-vehicle ECU 200D to the in-vehicle network 12 (YES in step S102), the relay device 100 acquires the authentication information of the detected in-vehicle ECU 200D from the server 181 (step S104).
[0156] Next, when the relay device 100 acquires authentication information indicating authentication failure from the server 181 (NO in step S106), the relay device 100 transmits connection-disallowed information to the in-vehicle ECU 200D (step S108).
[0157] Next, the relay device 100 waits for the addition of a new new functional unit to the in-vehicle network 12 (NO in step S102).
[0158] On the one hand, when the relay device 100 acquires authentication information indicating successful authentication from the server 181 (YES in step S106), it transmits the vehicle exterior authentication success information to the corresponding in-vehicle ECU 200D (step S110).
[0159] Next, the relay device 100 performs in-vehicle authentication processing of the in-vehicle ECU 200D using the authentication information acquired from the server 181 (step S112).
[0160] Next, when the in-vehicle authentication processing of the in-vehicle ECU 200D fails (YES in step S114), the relay device 100 stops relaying information between the in-vehicle ECU 200D and other in-vehicle ECUs 200 (step S116).
[0161] Next, the relay device 100 acquires new authentication information of the in-vehicle ECU 200D from the server 181 (step S104).
[0162] On the one hand, when the in-vehicle authentication processing of the in-vehicle ECU 200D is successful (NO in step S114), the relay device 100 starts or continues relaying information between the in-vehicle ECU 200D and other in-vehicle ECUs 200 (step S118).
[0163] Next, when the expiration date of the authentication information of the in-vehicle ECU 200D has not expired (NO in step S120), the relay device 100 performs in-vehicle authentication processing of the in-vehicle ECU 200D using the authentication information at the timing of the next in-vehicle authentication processing (step S112).
[0164] On the one hand, when the expiration date of the authentication information of the in-vehicle ECU 200D expires (YES in step S120), the relay device 100 checks whether the communication with the server 181 is possible (step S122).
[0165] Next, when the communication with the server 181 is possible (YES in step S122) and the vehicle 1 is not in motion (YES in step S124), the relay device 100 acquires new authentication information of the in-vehicle ECU 200D from the server 181 (step S104).
[0166] On the other hand, when the relay device 100 is not in a situation where communication with the server 181 is possible (NO in step S122), or when communication with the server 181 is possible (YES in step S122) and the vehicle 1 is not running (NO in step S124), extension processing is performed (step S126).
[0167] Next, at the timing of the next in-vehicle authentication process, the relay device 100 performs the in-vehicle authentication process of the in-vehicle ECU 200D using the extended authentication information, which is the authentication information whose validity is maintained by the extension process (step S112).
[0168] FIG. 6 is a diagram showing an example of a sequence of an out-vehicle authentication process in a communication system according to an embodiment of the present disclosure.
[0169] Referring to FIG. 6, first, when the in-vehicle ECU 200D, which is a new functional unit newly added to the in-vehicle network 12, is connected to the relay device 100, it transmits authentication request information including its own MAC address to the relay device 100 (step S202).
[0170] Next, when the relay device 100 receives the authentication request information from the in-vehicle ECU 200D, it transmits authentication method information indicating the authentication method in the out-vehicle authentication process to the in-vehicle ECU 200D (step S204).
[0171] Next, the in-vehicle ECU 200D and the server 181 exchange EAP messages including information necessary for the out-vehicle authentication process via the relay device 100 (step S206).
[0172] Next, the server 181 performs the out-vehicle authentication process of the in-vehicle ECU 200D using the EAP message received from the in-vehicle ECU 200 via the relay device 100 (step S208).
[0173] Next, when the server 181 succeeds in authenticating the in-vehicle ECU 200D through the off-vehicle authentication process, it generates authentication information indicating successful authentication and transmits the generated authentication information to the relay device 100 (step S210).
[0174] Next, when the relay device 100 receives the authentication information from the server 181, it transmits off-vehicle authentication success information to the in-vehicle ECU 200D (step S212).
[0175] FIG. 7 is a diagram showing an example of a sequence of off-vehicle authentication processing and in-vehicle authentication processing in the communication system according to the embodiment of the present disclosure.
[0176] Referring to FIG. 7, first, the relay device 100 relays information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the result of the in-vehicle authentication process using the common key. That is, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the result of the in-vehicle authentication process by the relay device 100 (step S302).
[0177] Next, when the expiration date of the authentication information of the in-vehicle ECU 200D expires, the relay device 100 transmits a communication confirmation request to the server 181 (step S304).
[0178] Next, if the relay device 100 fails to receive communicable information from the server 181 within a predetermined time after transmitting the communication confirmation request, it determines that the relay device 100 and the server 181 are in a state where they cannot communicate, and performs an extension process to maintain the validity of the authentication information including the common key (step S306).
[0179] Next, the relay device 100 continues to relay information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the result of the in-vehicle authentication process using the common key. Then, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the result of the in-vehicle authentication process by the relay device 100 (step S308).
[0180] Next, the relay device 100 transmits a communication confirmation request to the server 181 again (step S310).
[0181] Next, when the server 181 receives the communication confirmation request, it transmits communication enable information to the relay device 100 as a response to the communication confirmation request (step S312).
[0182] Next, the in-vehicle ECU 200D and the server 181 exchange EAP messages including information necessary for the off-vehicle authentication process via the relay device 100. Then, the server 181 performs off-vehicle authentication processing of the in-vehicle ECU 200D using the EAP message received from the in-vehicle ECU 200 via the relay device 100 (step S314).
[0183] Next, when the server 181 successfully authenticates the in-vehicle ECU 200D through the off-vehicle authentication process, it generates authentication information including a new common key and transmits the generated authentication information to the relay device 100 (step S316).
[0184] Next, when the relay device 100 receives the authentication information including the new common key from the server 181, it transmits off-vehicle authentication success information including the new common key to the in-vehicle ECU 200D (step S318).
[0185] Next, the relay device 100 starts relaying information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the result of the in-vehicle authentication process using the new common key. Then, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the result of the in-vehicle authentication process by the relay device 100 (step S320).
[0186] FIG. 8 is a diagram showing an example of a sequence of in-vehicle authentication processing in the communication system according to the embodiment of the present disclosure. FIG. 8 shows details of the processing in steps S302, S308, and S320 in FIG. 7.
[0187] Referring to FIG. 8, first, the relay device 100 generates a random number (step S402).
[0188] Next, the relay device 100 transmits the generated random number to the in-vehicle ECU 200D that is the target of the in-vehicle authentication process (step S404).
[0189] Next, the relay device 100 generates encrypted data by encrypting the generated random number using a common key (step S406).
[0190] Also, the in-vehicle ECU 200D generates encrypted data by encrypting the random number received from the relay device 100 using a common key (step S408).
[0191] Next, the in-vehicle ECU 200D transmits the generated encrypted data to the relay device 100 (step S410).
[0192] When the relay device 100 receives the encrypted data from the in-vehicle ECU 200D, it collates the received encrypted data with the encrypted data it generated itself (step S412).
[0193] Next, when the encrypted data received from the in-vehicle ECU 200D matches the encrypted data it generated itself, the relay device 100 determines that the in-vehicle authentication process of the in-vehicle ECU 200D has succeeded, and starts or continues relaying information between the in-vehicle ECU 200D and other in-vehicle ECUs 200 (step S414).
[0194] FIG. 9 is a diagram showing another example of the sequence of the off-vehicle authentication process and the in-vehicle authentication process in the communication system according to the embodiment of the present disclosure.
[0195] Referring to FIG. 9, first, the relay device 100 relays information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the result of the in-vehicle authentication process using the authenticated MAC address. That is, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the result of the in-vehicle authentication process by the relay device 100 (step S502).
[0196] Next, when the expiration date of the authentication information of in-vehicle ECU 200D expires, relay device 100 transmits a communication confirmation request to server 181 (step S504).
[0197] Next, if relay device 100 cannot receive communication enable information from server 181 within a predetermined time after transmitting the communication confirmation request, relay device 100 determines that it is in a state where it cannot communicate with server 181, and performs an extension process to maintain the validity of the authentication information including the authenticated MAC address (step S506).
[0198] Next, relay device 100 continues to relay information between in-vehicle ECU 200C and in-vehicle ECU 200D based on the result of the in-vehicle authentication process using the authenticated MAC address. Then, in-vehicle ECU 200C and in-vehicle ECU 200D communicate via relay device 100 based on the result of the in-vehicle authentication process by relay device 100 (step S508).
[0199] Next, relay device 100 transmits a communication confirmation request to server 181 again (step S510).
[0200] Next, when server 181 receives the communication confirmation request, as a response to the communication confirmation request, server 181 transmits communication enable information to relay device 100 (step S512).
[0201] Next, in-vehicle ECU 200D and server 181 exchange EAP messages including information necessary for the off-vehicle authentication process via relay device 100. Then, server 181 performs an off-vehicle authentication process for in-vehicle ECU 200D using the EAP message received from in-vehicle ECU 200 via relay device 100 (step S514).
[0202] Next, when server 181 successfully authenticates in-vehicle ECU 200D through the off-vehicle authentication process, server 181 transmits new authentication information including the authenticated MAC address to relay device 100 (step S516).
[0203] Next, when the relay device 100 receives new authentication information from the server 181, it transmits vehicle exterior authentication success information including the authenticated MAC address corresponding to the received authentication information to the in-vehicle ECU 200D (step S518).
[0204] Next, the relay device 100 starts relaying information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the result of the in-vehicle authentication process using the new authenticated MAC address. Then, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the result of the in-vehicle authentication process by the relay device 100 (step S520).
[0205] Note that in the relay device 100 according to the embodiment of the present disclosure, when the expiration date of the authentication information has expired and the relay device 100 cannot communicate with the server 181, the authentication processing unit 140 performs an extension process to maintain the validity of the authentication information, and uses the extended authentication information, which is the authentication information with the validity maintained, to perform the in-vehicle authentication process for the corresponding in-vehicle ECU 200. However, the present disclosure is not limited to this. The authentication processing unit 140 may be configured to stop the in-vehicle authentication process until new authentication information is acquired without performing the extension process when the expiration date of the authentication information has expired and the relay device 100 cannot communicate with the server 181. Further, the relay processing unit 120 may be configured to stop relaying information between the in-vehicle ECUs 200 until the authentication processing unit 140 acquires new authentication information and performs the in-vehicle authentication process using the acquired new authentication information.
[0206] Also, in the relay device 100 according to the embodiment of the present disclosure, the relay processing unit 120 is configured to determine the content of the information to be relayed when the authentication process using the extended authentication information by the authentication processing unit 140 is successful according to the type of the in-vehicle ECU 200. However, the present disclosure is not limited to this. The relay processing unit 120 may be configured to relay all information including various contents between the in-vehicle ECU 200 and other in-vehicle ECUs 200 when the authentication process using the extended authentication information by the authentication processing unit 140 is successful regardless of the type of the in-vehicle ECU 200.
[0207] Further, in the relay device 100 according to the embodiment of the present disclosure, although the relay processing unit 120 is configured to determine whether to perform relay when the authentication process using the extended authentication information by the authentication processing unit 140 is successful according to the type of information received from the in-vehicle ECU 200, the present disclosure is not limited thereto. The relay processing unit 120 may be configured to relay all information addressed to other in-vehicle ECUs 200 received from the in-vehicle ECU 200 when the authentication process using the extended authentication information by the authentication processing unit 140 is successful, regardless of the type of information received from the in-vehicle ECU 200.
[0208] Further, in the relay device 100 according to the embodiment of the present disclosure, although the authentication processing unit 140 is configured to obtain authentication information whose common key is updated every time it is obtained from the server 181, the present disclosure is not limited thereto. The server 181 may be configured to generate authentication information including the same common key for each corresponding authentication every time it performs an off-vehicle authentication process and succeeds in the authentication, and transmit the generated authentication information to the relay device 100.
[0209] Further, in the relay device 100 according to the embodiment of the present disclosure, although the authentication processing unit 140 is configured to perform an extension process to maintain the validity of the authentication information without obtaining new authentication information from the server 181 when the vehicle 1 is running in a state where communication between the relay device 100 and the server 181 is possible and the expiration date of the authentication information has passed, the present disclosure is not limited thereto. The authentication processing unit 140 may be configured to obtain new authentication information from the server 181 regardless of whether the vehicle 1 is running in a state where communication between the relay device 100 and the server 181 is possible and the expiration date of the authentication information has passed.
[0210] By the way, a technology capable of improving the security in the in-vehicle network is desired.
[0211] Specifically, for example, when a new in-vehicle network is configured by attaching a new in-vehicle ECU to an existing in-vehicle network, a technology capable of improving the security of the new in-vehicle network is desired.
[0212] In contrast, the relay device 100 according to an embodiment of the present disclosure is mounted on a vehicle 1 including a plurality of in-vehicle ECUs 200. The authentication processing unit 140 acquires authentication information of the in-vehicle ECU 200 from a server 181 outside the vehicle 1, and performs authentication processing of the in-vehicle ECU 200 using the acquired authentication information. The relay processing unit 120 relays information between the in-vehicle ECU 200 and other in-vehicle ECUs 200 based on the result of the authentication processing by the authentication processing unit 140. When the expiration date of the authentication information has passed, the authentication processing unit 140 acquires new authentication information from the server 181.
[0213] As described above, with the configuration of acquiring the authentication information of the in-vehicle ECU 200 from the server 181 outside the vehicle 1, even when a new unknown in-vehicle ECU 200 is added to the in-vehicle network, the authentication information of the in-vehicle ECU can be acquired. Further, when the expiration date has passed, new authentication information is acquired, the authentication processing of the in-vehicle ECU 200 is performed using the acquired authentication information, and based on the result of the authentication processing, information between the in-vehicle ECU 200 and other in-vehicle ECUs 200 is relayed, thereby ensuring the security of the in-vehicle network and enabling continuous authentication processing of the in-vehicle ECU 200 using the authentication information even in a situation where it is difficult to acquire new authentication information from the server 181 depending on the driving environment of the vehicle 1.
[0214] Therefore, in the relay device 100 according to the embodiment of the present disclosure, the security in the in-vehicle network can be improved.
[0215] Further, in the relay device 100 according to the embodiment of the present disclosure, when the expiration date of the authentication information has passed and the relay device 100 cannot communicate with the server 181, the authentication processing unit 140 performs an extension process to maintain the validity of the authentication information, and uses the extended authentication information, which is the authentication information with the validity maintained, to perform the authentication process of the in-vehicle ECU 200 corresponding to the authentication information.
[0216] With such a configuration, when the expiration date of the authentication information has passed, even if the communication environment between the relay device 100 and the server 181 deteriorates due to the driving environment of the vehicle 1 and new authentication information cannot be obtained, the authentication process can be performed, and the relay of information between the in-vehicle ECUs 200 based on the authentication result can be continued. Thereby, for example, in a configuration in which security is improved by updating the content of the authentication information outside the vehicle 1, stable communication in the in-vehicle network can be managed regardless of the driving environment of the vehicle 1.
[0217] Further, in the relay device 100 according to the embodiment of the present disclosure, when the authentication process using the extended authentication information by the authentication processing unit 140 is successful, the relay processing unit 120 determines the content of the information to be relayed according to the type of the in-vehicle ECU 200.
[0218] With such a configuration, since a part of the information to be relayed when the extension process is performed can be limited according to the type of the in-vehicle ECU 200, for example, while continuing the relay of information between the in-vehicle ECUs 200 that affect the driving of the vehicle 1, by stopping the relay of information between the in-vehicle ECUs 200 that do not affect the driving of the vehicle 1, it is possible to suppress a decrease in security in the in-vehicle network while maintaining good driving of the vehicle 1.
[0219] Further, in the relay device 100 according to the embodiment of the present disclosure, when the authentication process using the extended authentication information by the authentication processing unit 140 is successful, the relay processing unit 120 determines whether to perform the relay according to the type of the information received from the in-vehicle ECU 200.
[0220] With such a configuration, depending on the type of information received from the in-vehicle ECU 200, it is possible to limit a part of the information to be relayed when extension processing is performed. For example, while continuing to relay information that affects the running of Vehicle 1, by stopping the relay of information that does not affect the running of Vehicle 1, it is possible to suppress a decrease in security in the in-vehicle network while maintaining the good running of Vehicle 1.
[0221] Also, in the relay device 100 according to the embodiment of the present disclosure, the authentication processing unit 140 acquires authentication information having different contents from the server 181 each time it acquires authentication information.
[0222] With such a configuration, it is possible to acquire new authentication information each time the expiration date is reached and perform authentication processing of the in-vehicle ECU 200 using the authentication information, so that the security in the in-vehicle network can be further improved.
[0223] Also, in the relay device 100 according to the embodiment of the present disclosure, the authentication processing unit 140 can communicate between the relay device 100 and the server 181, and when the vehicle 1 is running in a state where the expiration date of the authentication information has expired, it performs an extension process to maintain the validity of the authentication information without acquiring new authentication information from the server 181.
[0224] With such a configuration, for example, by performing authentication processing using new authentication information, an authentication error occurs, and it is possible to avoid stopping the relay of part or all of the information between the in-vehicle ECUs 200 during the running of the vehicle 1 and maintain the good running of the vehicle 1.
[0225] Also, the vehicle communication method according to the embodiment of the present disclosure is a vehicle communication method in a relay device 100 mounted on a vehicle 1 including a plurality of in-vehicle ECUs 200. In this vehicle communication method, first, authentication information of the in-vehicle ECU 200 is acquired from an external device outside the vehicle 1. Next, authentication processing of the in-vehicle ECU 200 is performed using the acquired authentication information. Next, based on the result of the authentication processing, information of the in-vehicle ECU 200 and other in-vehicle ECUs 200 is relayed. Next, when the expiration date of the authentication information has passed, new authentication information is acquired from the server 181.
[0226] In this way, by the method of acquiring the authentication information of the in-vehicle ECU 200 from the server 181 outside the vehicle 1, even when a new unknown in-vehicle ECU 200 is added to the in-vehicle network, the authentication information of the in-vehicle ECU can be acquired. Further, when the expiration date has passed, new authentication information is acquired, authentication processing of the in-vehicle ECU 200 is performed using the acquired authentication information, and based on the result of the authentication processing, information between the in-vehicle ECU 200 and other in-vehicle ECUs 200 is relayed. In this way, the security of the in-vehicle network can be guaranteed, and even in a situation where it is difficult to acquire new authentication information from the server 181 depending on the driving environment of the vehicle 1, authentication processing of the in-vehicle ECU 200 can be continuously performed using the authentication information.
[0227] Therefore, in the vehicle communication method according to the embodiment of the present disclosure, the security in the in-vehicle network can be improved.
[0228] The above embodiment should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is shown by the scope of claims rather than the above description, and it is intended that all modifications within the meaning and scope equivalent to the scope of claims are included.
[0229] The above description includes the features appended below. [Appendix 1] A relay device mounted on a vehicle including a plurality of functional units, An authentication processing unit that acquires authentication information of the functional unit from an external device outside the vehicle and performs authentication processing of the functional unit using the acquired authentication information; A relay processing unit that relays information between the functional unit and other functional units based on the result of the authentication processing by the authentication processing unit. When the expiration date of the authentication information has passed, the authentication processing unit acquires new authentication information from the external device. The authentication processing unit acquires the authentication information including a different common key from the external device every time the authentication information is acquired, and performs authentication processing of the functional unit using the common key included in the acquired authentication information. A relay device.
Explanation of Signs
[0230] 1 Vehicle 11 External Network 12 In-vehicle Network 13 Ethernet Cable 52 Communication Port 100 Relay Device 110 Communication Unit 120 Relay Processing Unit 130 Detection Unit 140 Authentication Processing Unit 150 Storage Unit 160 Timer 161 Wireless Base Station Device 181 Server 200 In-vehicle ECU 210 Communication Unit 220 Processing Unit 230 Authentication Request Unit 240 Storage Unit 301 In-vehicle Communication System 401 Communication System
Claims
1. A relay device mounted on a vehicle having a plurality of functional units, an authentication processing unit that acquires authentication information of the functional unit from an external device outside the vehicle and performs an in-vehicle authentication process, which is an authentication process of the functional unit, using the acquired authentication information; a relay processing unit that relays information between the functional unit and another functional unit based on a result of the in-vehicle authentication process, the authentication processing unit acquires new authentication information from the external device when the authentication information has expired; the relay device is used in an outside-vehicle authentication process, which is an authentication process of the functional unit by the external device, and relays information exchanged between the external device and the functional unit; The authentication processing unit performs the in-vehicle authentication process using the authentication information when the external device succeeds in the outside-vehicle authentication process.
2. The relay device according to claim 1 , wherein the authentication processing unit acquires the authentication information from the external device, the authentication information having different contents each time the authentication information is acquired.
3. A vehicle communication method in a relay device mounted on a vehicle having a plurality of functional units, comprising: acquiring authentication information of the functional unit from an external device outside the vehicle; performing an in-vehicle authentication process, which is an authentication process of the functional unit, using the acquired authentication information; relaying information between the functional unit and another functional unit based on a result of the in-vehicle authentication process; When the authentication information has expired, acquiring new authentication information from the external device; The vehicle communication method further includes: a step of relaying information used in an outside-vehicle authentication process, which is an authentication process of the functional unit by the external device, and exchanged between the external device and the functional unit; In the step of performing the in-vehicle authentication process, if the external device succeeds in the outside-vehicle authentication process, the in-vehicle authentication process is performed using the authentication information.
4. A vehicle communication program in a relay device mounted on a vehicle having a plurality of functional units, On the computer, acquiring authentication information of the functional unit from an external device outside the vehicle; performing an in-vehicle authentication process, which is an authentication process of the functional unit, using the acquired authentication information; relaying information between the functional unit and another functional unit based on a result of the in-vehicle authentication process; and if the authentication information has expired, acquiring new authentication information from the external device. The vehicle communication program further includes: The computer includes: a program for executing a step of relaying information exchanged between the external device and the functional unit, the program being used in an outside-vehicle authentication process that is an authentication process of the functional unit by the external device, The vehicle communication program includes a step of performing the in-vehicle authentication process by using the authentication information when the external device succeeds in the outside-vehicle authentication process.
Citation Information
Patent Citations
Authentication system, wireless communication terminal, authentication server, authentication method and program
JP2010134493A
Hybrid authentication of vehicle devices and / or mobile user devices
US20190159026A1
Network system, communication control method, and storage medium
WO2015194323A1
Key management method, vehicle-mounted network system and key management device
WO2016075869A1
Vehicle authentication device, and vehicle authentication system
JP2013193598A