Electronic information storage medium, key management method, program for electronic information storage medium, and key management system

The key management system addresses improper digital key updates in ECUs by using an update information acquisition and verification process, ensuring secure and correct key updates in ECUs.

JP2025115098APending Publication Date: 2025-08-06DAI NIPPON PRINTING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024009444
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-25
Publication Date
2025-08-06

AI Technical Summary

Technical Problem

Existing electronic control units (ECUs) face issues with improper digital key updates, leading to incorrect authentication and reprogramming, compromising security.

Method used

A key management system that includes an update information acquisition means, verification data calculation means, and verification means to ensure proper digital key updates by acquiring and verifying update information using encryption and shared keys.

Benefits of technology

Ensures correct digital key updates, enhancing security by verifying the correspondence between verification data and update information, thereby preventing incorrect authentication and reprogramming.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025115098000001_ABST
    Figure 2025115098000001_ABST
Patent Text Reader

Abstract

To provide an electronic information storage medium, a key management method, a program for the electronic information storage medium, and a key management system that causes verification to be performed on whether or not a digital key has been properly updated.SOLUTION: An ECU 12 of an electronic information storage medium: acquires update information, which has a key value for updating a digital key and includes data for checking, from a key management server device 20 that manages the digital key (S6); calculates verification data from the data for checking using the key value for updating; and outputs the verification data to verification means that verifies the verification data in accordance with a predetermined correspondence between the verification data and the data for checking (S7, S8).SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to the technical fields of an electronic information storage medium, a key management method, a program for an electronic information storage medium, and a key management system. [Background technology]

[0002] To electronically control a vehicle, an ECU (Electronic Control Unit) is installed in each of the engine / brake driving control devices, vehicle body devices such as lights and doors, collision prevention safety control devices, navigation devices, etc. For example, Patent Document 1 discloses a seat adjustment ECU that acquires a user's seat setting data from a mobile terminal, calculates the change time for each adjustment target, and first drives the seat motor corresponding to the adjustment target with the longest change time among multiple seat motors. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2013-246672 Summary of the Invention [Problem to be solved by the invention]

[0004] ECUs have digital keys that are used for authentication and reprogramming. To improve security, digital keys are updated. However, if the digital key is not updated correctly, an incorrect digital key may be used, preventing proper authentication and reprogramming.

[0005] Therefore, the present invention has been made in consideration of the above problems, and aims to provide an electronic information storage medium, a key management method, a program for an electronic information storage medium, and a key management system that verify whether a digital key has been properly updated. [Means for solving the problem]

[0006] In order to solve the above problem, the invention described in claim 1 is characterized by comprising: an update information acquisition means for acquiring update information having a key value for updating the digital key and including verification data from a key management server device that manages the digital key; a verification data calculation means for calculating verification data from the verification data using the update key value; and a verification data output means for outputting the verification data to a verification means that verifies the verification data in accordance with a predetermined correspondence between the verification data and the verification data.

[0007] The invention described in claim 2 is characterized in that, in the electronic information storage medium described in claim 1, the verification data calculation means encrypts the verification data with the update key value to calculate the verification data, and the verification means compares the verification data with a value obtained by encrypting the verification data in the key management server device to verify the verification data.

[0008] The invention described in claim 3 is characterized in that, in the electronic information storage medium described in claim 1 or claim 2, the verification data includes the update key value, the verification data calculation means encrypts the verification data using a shared key shared between the key management server device and the electronic information storage medium to calculate the verification data, and the verification means verifies the verification data by comparing the verification data with a value obtained by encrypting the verification data using the shared key in the key management server device.

[0009] The invention as set forth in claim 4 is the electronic information storage medium as set forth in claim 2, wherein the verification data is a random number.

[0010] The invention described in claim 5 is characterized in that, in the electronic information storage medium described in claim 3, the update key value is written based on the verification result obtained by comparing the verification data with the value obtained by encrypting the verification data with the shared key in the key management server device.

[0011] The invention described in claim 6 is characterized in that, in the electronic information storage medium described in claim 1 or claim 2, if the specified correspondence is not established between the verification data and the verification data, the update information acquisition means re-acquires the update information from the key management server device.

[0012] The invention described in claim 7 is characterized in that it includes an update information acquisition step in which an update information acquisition means acquires update information having a key value for updating the digital key and including verification data from a key management server device that manages digital keys; a verification data calculation step in which a verification data calculation means calculates verification data from the verification data using the update key value; and a verification data output step in which a verification data output means outputs the verification data to a verification means that verifies the verification data in accordance with a predetermined correspondence between the verification data and the verification data.

[0013] The invention described in claim 8 is characterized in that a computer is made to function as an update information acquisition means for acquiring update information having a key value for updating the digital key and including verification data from a key management server device that manages digital keys, a verification data calculation means for calculating verification data from the verification data using the update key value, and a verification means for verifying the verification data in accordance with a predetermined correspondence between the verification data and the verification data, and a verification data output means for outputting the verification data.

[0014] The invention described in claim 9 is a key management system comprising an electronic information storage medium for storing a digital key and a key management server device for managing the digital key, wherein the key management server device has an update information sending means for sending update information containing verification data to the electronic information storage medium, the update information sending means having a key value for updating the digital key, and the electronic information storage medium having a verification data calculation means for calculating verification data from the verification data using the update key value, a verification means for verifying the verification data in accordance with a predetermined correspondence between the verification data and the verification data, and a determination means for determining whether or not to resend the update information to the electronic information storage medium in accordance with the verification result.

[0015] The invention described in claim 10 is characterized in that, in the key management system described in claim 9, it further comprises an intermediary electronic information storage medium that distributes the update information sent from the key management server device to a plurality of the electronic information storage media, and a determination means determines whether or not to re-send the update information to the electronic information storage medium depending on the result of the intermediary electronic information storage medium determining whether or not there is an electronic information storage medium to be updated based on the update information.

[0016] The invention described in claim 11 is characterized in that, in the key management system described in claim 10, after starting a secure session between the intermediary electronic information storage medium and the key management server device, the update information transmission means transmits the update information to the electronic information storage medium. [Effects of the Invention]

[0017] According to the present invention, update information having a key value for updating the digital key and including verification data is obtained from a key management server device that manages the digital key, and verification data is calculated from the verification data using the update key value, and the verification data is output to a verification means that verifies the verification data in accordance with a predetermined correspondence between the verification data and the verification data, thereby checking whether the correspondence between the verification data and the verification data is correct and verifying whether the digital key has been properly updated. [Brief explanation of the drawings]

[0018] [Figure 1] 1 is a diagram illustrating an example of a schematic configuration of a key management system according to an embodiment of the present invention; [Figure 2] FIG. 1 is a diagram illustrating an example of a schematic configuration of an in-vehicle electronic device. [Figure 3] FIG. 1 is a diagram illustrating an example of a schematic configuration of a CGW. [Figure 4] FIG. 2 is a diagram illustrating an example of a schematic configuration of an ECU. [Figure 5] FIG. 2 is a diagram illustrating an example of a schematic configuration of a key management server device. [Figure 6] FIG. 6 is a diagram illustrating an example of a database of the management server device of FIG. 5. [Figure 7] 1 is a flowchart showing a first embodiment of the operation of a key management system. [Figure 8] 10 is a flowchart showing a second embodiment of the operation of the key management system. [Figure 9] 10 is a flowchart showing a third embodiment of the operation of the key management system. [Figure 10] 10 is a flowchart showing a fourth embodiment of the operation of the key management system. DETAILED DESCRIPTION OF THE INVENTION

[0019] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings. The preferred embodiments described below are embodiments in which the present invention is applied to an ECU, which is an example of an electronic information storage medium.

[0020] [1. Configuration and functions of the key management system S and each device] (1.1 Overview of Key Management System S) First, a schematic configuration of a key management system S according to this embodiment will be described with reference to Fig. 1 etc. Fig. 1 is a diagram showing an example of the schematic configuration of the key management system S according to this embodiment.

[0021] 1, the key management system S includes an on-board electronic device 10 mounted on a vehicle 5, a key management server device 20 that manages digital keys and the like used in the on-board electronic device 10, and a diagnostic device 30 that is directly connected to the on-board electronic device 10 and diagnoses various electronic systems of the on-board electronic device 10. The vehicle 5 is an example of a moving body, such as a two-wheeled automobile, a four-wheeled automobile, or a bicycle.

[0022] The in-vehicle electronic device 10 is, for example, a device having a control device such as an ECU (Electronic Control Unit) and an eSE (Embedded Secure Element) provided in the vehicle 5. The in-vehicle electronic device 10 controls driving control devices such as the engine and brakes of the vehicle 5, body devices of the vehicle 5 such as lights and doors, safety control devices for collision prevention, navigation devices, electronic devices such as a drive recorder, etc. The in-vehicle electronic device 10 may also include devices provided in the vehicle 5 that provide various services such as a payment service.

[0023] The key management server device 20 is a server for managing specific applications, data, etc. that can be provided to specific devices such as the on-board electronic device 10 mounted on the vehicle 5. When providing applications, data, etc. to the specific devices such as the on-board electronic device 10, a digital key is used.

[0024] The in-vehicle electronic device 10 and the key management server device 20 are connected to a network 3 configured, for example, by the Internet. The key management server device 20 and the in-vehicle electronic device 10 are capable of wireless communication via the network 3 and a wireless base station. The network 3 may be connected to a public key infrastructure (PKI).

[0025] Here, examples of electronic device data provided by the key management server device 20 to the in-vehicle electronic device 10 include digital key data such as encryption keys stored in the ECU, electronic certificate data, map data for navigation, control data for the ECU, etc. Furthermore, examples of applications (one example of electronic device data) provided by the key management server device 20 to the in-vehicle electronic device 10 include ECU control programs, navigation programs, software required for using various services such as payment services, etc.

[0026] The diagnostic device 30 is, for example, a portable computer that diagnoses the electronic system of the vehicle 5 when inspecting the vehicle 5. The diagnostic device 30 can be directly connected to the on-board electronic device 10 of the vehicle 5 via a vehicle diagnostic port (for example, OBD (On Board Diagnostics)-II) or the like. The diagnostic device 30 is an example of a relay device that can be directly connected to the on-board electronic device 10.

[0027] The key management server device 20 and the diagnostic device 30 are connected via a local area network or the like. The diagnostic device 30 may be connected to the network 3 to send and receive data with the key management server device 20. A diagnostic device 30 may be provided for each business that inspects vehicles 5 or for each repair technician.

[0028] (1.2 Configuration and Function of the In-Vehicle Electronic Device 10) Next, an example of the schematic configuration of the in-vehicle electronic device 10 will be described with reference to the drawings. Fig. 2 is a diagram showing an example of the schematic configuration of the in-vehicle electronic device 10. Fig. 3 is a diagram showing an example of the schematic configuration of the CGW. Fig. 4 is a diagram showing an example of the schematic configuration of the ECU.

[0029] As shown in FIG. 2, the in-vehicle electronic device 10 includes a CGW (Central GateWay) 11, a plurality of ECUs 12, a TCU (Telematics Control Unit) 13, and a DLC (Data link Connector) .

[0030] As shown in FIG. 3, the CGW 11, which is an example of an intermediary electronic information storage medium, is configured to include a communication unit 11a, a storage unit 11b, and a control unit 11c.

[0031] The communication unit 11a is connected to each ECU 12 and communicates with the ECUs 12. The communication unit 11a communicates with the key management server device 20 via the TCU 13. The communication unit 11a communicates with the diagnostic device 30 via the DLC 14.

[0032] The storage unit 11b is, for example, a nonvolatile memory (NVM (Nonvolatile Memory)). The storage unit 11b stores digital keys, electronic certificate data, control data for the CGW, and the like. The storage unit 11b stores an operating system (OS) and applications. The applications include a mutual authentication processing program, and the like.

[0033] The storage unit 11b also stores authentication data used in mutual authentication processing for establishing a secure channel with the key management server device 20. The authentication data is, for example, a digital key set including a secure channel encryption key, a secure channel MAC (Message Authentication Code) key, and a data encryption key. The storage unit 11b also stores information (public key, private key, etc.) of an electronic signature assigned to data. The data stored in the storage unit 11b may be stored in a secure area built into the ECU 12 or an externally attached eSE, etc.

[0034] The storage unit 11b also stores a CGW-ID, which is a unique ID for identifying the CGW 11 itself, and an ECU-ID of each ECU 12 belonging to the CGW 11. The CGW-ID and ECU-ID may be, for example, a chip ID of each ECU. The CGW-ID may be a device address or a Media Access Control (MAC) address of the in-vehicle electronic device 10.

[0035] The control unit 11c includes a central processing unit (CPU), a random access memory (RAM), a read only memory (ROM), and the like.

[0036] The CGW 11 performs authentication with the key management server device 20, the diagnostic device 30, etc., using the control unit 11c in accordance with a mutual authentication processing program. After authentication, the CGW 11 transmits update information for the digital key received from the key management server device 20 to the corresponding ECU 12, and transmits verification data of the verification result in the ECU 12 to the key management server device 20 via the TCU 13. The CGW 11 distributes the update information transmitted from the key management server device 20 to the multiple ECUs 12.

[0037] As shown in FIG. 4, the ECU 12, which is an example of an electronic information storage medium, is configured to include a communication unit 12a, a storage unit 12b, and a control unit 12c.

[0038] The communication unit 12 a is connected to the CGW 11 and communicates with the CGW 11 .

[0039] The storage unit 12b is, for example, a non-volatile memory. The storage unit 12b stores digital keys, electronic certificate data, control data for ECUs, data on agreements such as verification methods shared with the key management server device 20, and the like. The storage unit 12b also stores an OS and application programs. The applications include a program for verifying digital key updates, a mutual authentication processing program, and the like.

[0040] The storage unit 12b also stores various digital keys associated with key IDs. For example, these include digital keys for various authentications such as mutual authentication processing for establishing a secure channel, digital keys for executing programs in the ECU 12, digital keys used for reprogramming the programs in the ECU 12, shared keys for MAC with the key management server device 20, etc., data encryption keys, and information on electronic signatures assigned to data (public keys, private keys, etc.). The data stored in the storage unit 12b may be saved in a secure area such as an external eSE.

[0041] The storage unit 12b also stores an ECU-ID, which is a unique ID for identifying the ECU 12, a CGW-ID of the CGW 11 to which the ECU 12 belongs, and the like.

[0042] The control unit 12c is configured to include a CPU, RAM, ROM, etc. The control unit 12c performs checks for updating the digital key using the programs stored in the storage unit 12b.

[0043] The TCU 13 is a communication unit for wireless communication between the vehicle 5 and the outside. In response to a request from the CGW 11 or the ECU 12, the TCU 13 connects to the network 3 and communicates with the key management server device 20.

[0044] The DLC 14 is a connector for vehicle diagnosis. The diagnostic device 30 is connected to the in-vehicle electronic device 10 via the DLC 14. The diagnostic device 30 and the in-vehicle electronic device 10 may be connected directly via short-range wireless communication via the TCU 13, in addition to being connected by wire. For short-range wireless communication, technologies such as NFC (Near Field Communication), Bluetooth (registered trademark), or UWB (Ultra Wide Band) are used.

[0045] The TCU 13 and DLC 14 are connected to each ECU 12 via the CGW 11 .

[0046] (1.3 Configuration and Function of Key Management Server Device 20) Next, an example of the schematic configuration of the key management server device 20 will be described with reference to the drawings. Fig. 5 is a diagram showing an example of the schematic configuration of the key management server device 20. Fig. 6 is a diagram showing an example of the database of the key management server device 20.

[0047] 5, the key management server device 20 includes a communication unit 21, a storage unit 22, a display unit 23, an operation unit 24, a system control unit 25, and an input / output interface unit 26. The system control unit 25 and the input / output interface unit 26 are connected via a system bus 27.

[0048] The communication unit 21 connects to the network 3 to control the state of communication with the in-vehicle electronic device 10 and the like, and connects to a local area network to send and receive data to and from the diagnostic device 30 and the like.

[0049] The storage unit 22 is configured with, for example, a hard disk drive, a solid state drive, etc. As shown in Fig. 6, the storage unit 22 has a database in which a CGW-ID for identifying the CGW 11 of the on-board electronic device 10 of each vehicle 5, an ECU-ID for identifying each ECU 12 of the on-board electronic device 10, a key ID for identifying each digital key of the ECU 12, a key value set corresponding to the key ID, verification data for verification by the ECU 12, verification-related data for verifying key update, and the update time of the digital key are associated with each other.

[0050] Examples of verification data for the ECU 12 include a verification random number and a check code such as a MAC. Multiple pieces of verification data may be provided. Examples of data related to verification include information about a verification method for performing verification on the verification data. Examples include a verification method in which the verification random number of the verification data is encrypted with an updated digital key, a verification method in which the check code of the verification data is encrypted with a key shared between the ECU 12 and the key management server device 20, and a verification method in which the verification data is a value obtained by concatenating the CGW-ID and the ECU-ID, and a verification method in which the value obtained by concatenating the CGW-ID and the ECU-ID is encrypted with a key shared between the ECU 12 and the key management server device 20. The verification data and verification method are not limited to those described above, and any verification method may be used as long as the ECU 12 can output verification data from verification data that can be shared with the key management server device 20 using the verification method shared with the key management server device 20.

[0051] The ECU 12 may have the program for the calculation verification method stored in advance, or may receive the program for the calculation verification method from the key management server device 20 when the digital key is updated or at a predetermined time, or the program for the calculation verification method may be updated periodically, separately from updating the digital key. Also, instead of the CGW-ID, an electronic device ID assigned to each on-board electronic device 10 or a vehicle ID assigned to each vehicle 5 may be used. The CGW-ID, vehicle ID, electronic device ID, and vehicle ID are stored in association with each other in the storage unit 22.

[0052] The storage unit 22 may also store a data ID identifying data or applications that need to be updated, version information of the data or applications included in the in-vehicle electronic device 10, the latest version information, and the information associated with a CGW-ID, an electronic device ID, or a vehicle ID. The storage unit 22 may also store information about an electronic signature (such as a private key or a public key) to be assigned to data to be changed. The storage unit 22 may also store information about commands that can be executed by the CGW 11 and ECU 12 of each in-vehicle electronic device 10, associated with a CGW-ID, etc.

[0053] The storage unit 22 stores an operating system and applications. The applications include a mutual authentication processing program, etc. The storage unit 22 also stores authentication data (e.g., a key set including a secure channel encryption key, a secure channel MAC key, and a data encryption key) used in mutual authentication processing for establishing a secure channel with the on-board electronic device 10, the diagnostic device 30, etc.

[0054] The storage unit 22 stores the network address of the in-vehicle electronic device 10 for connection via the network 3, etc., in association with the CGW-ID, etc.

[0055] The display unit 23 is configured, for example, by a liquid crystal display element or an organic EL (Electro Luminescence) element, etc. The operation unit 24 is configured, for example, by a keyboard, a mouse, etc.

[0056] The system control unit 25 has, for example, a CPU, RAM, and ROM. In the system control unit 25, the CPU reads and executes various programs stored in the ROM, RAM, and storage unit 22. For example, the system control unit 25 executes mutual authentication processing for establishing a secure session with the in-vehicle electronic device 10 in accordance with a mutual authentication processing program. After authentication, the system control unit 25 transmits data for changes such as updating the digital key to the in-vehicle electronic device 10. The system control unit 25 generates verification random numbers such as pseudo-random numbers.

[0057] The input / output interface unit 26 is an interface between the communication unit 21, the storage unit 22, etc. and the system control unit 25.

[0058] [2. Operation of Key Management System S] (2.1 First Example of Key Management System S) Next, a first embodiment of the operation of the key management system S will be described with reference to Fig. 7. Fig. 7 is a flowchart showing the first embodiment of the operation of the key management system S.

[0059] First, the key management server device 20 of the key management system S refers to the database in the memory unit 22 to identify the key ID of the digital key that needs to be updated (for example, a digital key for reprogramming the ECU 12), and then identifies the ECU-ID of the ECU 12 to which this identified digital key belongs and the CGW-ID of the CGW 11 that includes this ECU 12.

[0060] The key management server device 20 broadcasts, via the network 3, the CGW-ID of the identified CGW 11 to establish a secure session with the CGW 11 of the in-vehicle electronic device 10 having the identified CGW 11. The TCU 13 of the in-vehicle electronic device 10 having the identified CGW 11 responds. The key management server device 20 performs TLS (Transport Layer Security) communication with the TCU 13 of the in-vehicle electronic device 10, and executes mutual authentication processing to establish a secure session with the CGW 11 of the in-vehicle electronic device 10 according to a mutual authentication processing program.

[0061] 7, the key management system S starts a session between the key management server device 20 and the CGW 11 (step S1). Specifically, after establishing a secure session, the key management server device 20 starts a session with the CGW 11.

[0062] Next, the key management system S transmits information necessary for updating the digital key (step S2). Specifically, the key management server device 20 transmits update information including the key ID of the digital key that needs to be updated, the key value for updating the digital key, the ECU-ID of the identified ECU 12, the CGW-ID of the identified CGW 11, and the generated verification random number to the CGW 11 with which the session has been established. The key management server device 20 stores the generated verification random number in the storage unit 22 in association with the CGW-ID of the identified CGW 11, the ECU-ID of the identified ECU 12, and the key ID of the digital key that needs to be updated. Here, the generated verification random number is an example of verification data.

[0063] Next, the key management system S determines whether or not the target ECU 12 exists (step S3). Specifically, the CGW 11 of the in-vehicle electronic device 10 that received the update information determines whether or not the CGW-ID included in the update information is its own CGW-ID. If it is its own CGW-ID, the CGW 11 determines whether or not the ECU-ID included in the update information is its own ECU-ID.

[0064] If the target ECU 12 is not found (step S3; NO), the key management system S performs error response processing (step S4). Specifically, the CGW 11 of the in-vehicle electronic device 10 requests the key management server device 20 to update the digital key again based on its own CGW-ID and the ECU-ID and key ID included in the update information. Note that if the CGW-ID included in the update information is not its own CGW-ID, the CGW 11 may return information to the key management server device 20 as an error response indicating that the CGW-ID was not its own CGW-ID.

[0065] Next, the key management system S updates the digital key again (step S5). Specifically, the key management server device 20 again transmits update information to the CGW 11, as in step S2.

[0066] If a target ECU 12 is found (step S3; YES), the key management system S transmits information required for digital key update to the ECU 12 (step S6). Specifically, the CGW 11 transmits the key ID of the digital key that needs to be updated, a key value for updating the digital key, and a verification random number that is an example of verification data to the target ECU 12 that corresponds to the ECU-ID in the update information. Next, the ECU 12 acquires the key ID of the digital key that needs to be updated, the key value for updating the digital key, and the verification random number that is the verification data from the CGW 11. In this way, the ECU 12 functions as an example of update information acquisition means that acquires update information that has the key value for updating the digital key and includes verification data from a key management server device that manages digital keys.

[0067] Next, the key management system S performs key writing and verification processing in the ECU 12 and transmits it to the CGW 11 (step S7). Specifically, the target ECU 12 writes an update key value to the storage unit 12b based on the key ID. The target ECU 12 performs verification by encrypting the acquired verification random number with the update key value, thereby generating verification data as the verification result. In this way, the ECU 12 functions as an example of a verification data calculation means that calculates verification data from the verification data using the update key value. The ECU 12 functions as an example of a verification data calculation means that encrypts the verification data with the update key value to calculate the verification data.

[0068] Next, the target ECU 12 outputs the generated verification data to the CGW 11 together with the key ID and its own ECU-ID.

[0069] Next, the key management system S transmits the verification result and the CGW-ID to the key management server device 20 (step S8). Specifically, the CGW 11 transmits the ECU-ID, key ID, and verification data acquired from the target ECU 12 together with its own CGW-ID to the key management server device 20. In this way, the ECU 12 or the CGW 11 functions as an example of a verification data output means that outputs the verification data to a verification means that verifies the verification data in accordance with a predetermined correspondence between the verification data and the verification data.

[0070] Next, the key management system S determines whether the verification result is correct (step S9). Specifically, based on the acquired CGW-ID, ECU-ID, and key ID, the key management server device 20 references the database in the storage unit 22, reads the key value of the key ID and the verification random number of the verification data, and generates correct data by encrypting the verification random number with an update key value. The key management server device 20 compares the correct data with the received verification data and determines whether they match. Here, encrypting the verification random number, which is an example of verification data, with an update key value to generate verification data is an example of a predetermined association between the verification data and the verification data. In this way, the key management server device 20 functions as an example of a verification means that verifies the verification data in accordance with the predetermined association between the verification data and the verification data. The key management server device 20 functions as an example of a verification means that verifies the verification data by comparing the verification data with a value obtained by encrypting the verification data in the key management server device.

[0071] If the verification result is correct (step S9; YES), the key management system S ends the key update. The key management server device 20 stores the update completion in the database of the storage unit 22 based on the received CGW-ID, ECU-ID, and key ID.

[0072] If the verification result is incorrect (step S9; NO), the key management system S performs digital key update again in step S5. Specifically, the key management server device 20 again transmits update information to the CGW 11, as in step S2. The key management system S repeats the process until the update is complete.

[0073] After the digital key has been updated, the key management server device 20 performs processing such as reprogramming based on the updated digital key.

[0074] (2.2 Second Example of Key Management System S) Next, a second embodiment of the operation of the key management system S will be described with reference to Fig. 8. Note that the same reference numerals will be used for parts that are the same as or correspond to those in the first embodiment, and only different configurations and operations will be described. The same applies to other embodiments and modifications.

[0075] FIG. 8 is a flowchart showing a second embodiment of the operation of the key management system S.

[0076] As in the first embodiment, first, the key management server device 20 of the key management system S refers to the database in the memory unit 22 to identify the key ID, ECU-ID, and CGW-ID of the digital key that needs to be updated, and then performs mutual authentication processing to establish a secure session with the CGW 11 of the in-vehicle electronic device 10.

[0077] As shown in FIG. 8, after establishing a secure session as in step S1, the key management system S starts a session between the key management server device 20 and the CGW 11 (step S10).

[0078] Next, the key management system S transmits information necessary for updating the digital key (step S11). Specifically, the key management server device 20 transmits update information to the CGW 11 with which the session has been established, the update information including the key ID of the digital key that needs to be updated, a key value for updating the digital key, the ECU-ID of the identified ECU 12, the CGW-ID of the identified CGW 11, and a generated check code such as a MAC. Here, the key value and CGW-ID included in the update information are examples of verification data. Furthermore, the generated check code such as a MAC is an example of correct answer data.

[0079] The key management server device 20 associates the generated MAC with the CGW-ID of the identified CGW 11, the ECU-ID of the identified ECU 12, and the key ID of the digital key that needs to be updated, and stores the MAC in the storage unit 22. Here, the MAC is, for example, data generated by linking the CGW-ID and a key value and encrypting the linked data with a key shared between the key management server device 20 and the ECU 12. A verification method for the MAC generation method and the like is determined between the key management server device 20 and the ECU 12. The verification method may be shared between the key management server device 20 and the ECU 12 in advance, or the key management server device 20 may transmit a program for the MAC generation method to the ECU 12 at a predetermined timing. Furthermore, this information may be shared between the key management server device 20 and the CGW 11. Furthermore, the shared key may be a common key in a common key cryptosystem or a private key or public key in a public key cryptosystem.

[0080] Next, the key management system S determines whether or not there is a target ECU 12, as in step S3 (step S12).

[0081] If the target ECU 12 is not present (step S12; NO), the key management system S performs an error response process (step S13) as in step S4.

[0082] Next, the key management system S performs the digital key update again, as in step S5 (step S14).

[0083] If a target ECU 12 is found (step S12; YES), the key management system S transmits information required for digital key update to the ECU (step S15). Specifically, the CGW 11 transmits the key ID of the digital key that needs to be updated, the key value for updating the digital key, the CGW-ID of the CGW 11, and a MAC (check code) to the target ECU 12 corresponding to the ECU-ID included in the update information. The ECU 12 acquires the key ID of the digital key that needs to be updated, the key value for updating the digital key, and the check code from the CGW 11. Here, the key value for updating and / or the CGW-ID are examples of verification data. Note that if the ECU 12 holds the CGW-ID, the CGW 11 does not need to transmit the CGW-ID. In this way, the ECU 12 functions as an example of an update information acquisition means that acquires update information that has the key value for updating the digital key and includes verification data from a key management server device that manages digital keys.

[0084] Next, the key management system S determines whether the MAC is correct (step S16). Specifically, the ECU 12 uses its verification data calculation function to encrypt data (an example of verification data) that combines the acquired update key value and the CGW-ID with a key shared with the key management server device 20 to generate verification data. Here, the update key value is used for the verification data. In this way, the ECU 12 functions as an example of a verification data calculation means that calculates verification data from the verification data using the update key value. The ECU 12 functions as an example of a verification data calculation means that encrypts the verification data with a shared key shared between the key management server device and the electronic information storage medium to calculate verification data.

[0085] Next, ECU 12 determines whether the verification data of this encrypted value matches the acquired check code. More specifically, ECU 12 outputs the generated verification data to its verification function, which determines whether the verification data matches the acquired check code. In this way, ECU 12 functions as an example of a verification means that verifies the verification data in accordance with a predetermined correspondence between the verification data and the verification data. ECU 12 functions as an example of a verification means that verifies the verification data by comparing the verification data with a value obtained by encrypting the verification data with the shared key in the key management server device.

[0086] Here, generating verification data by encrypting data obtained by linking an update key value, which is an example of verification data, with the CGW-ID using a shared key with the key management server device 20 is an example of a predetermined correspondence between the verification data and the verification data. Also, ECU 12 functions as an example of a verification data output means that outputs the verification data to a verification means that verifies the verification data in accordance with the predetermined correspondence between the verification data and the verification data.

[0087] If the MAC is incorrect (step S16; NO), the digital key is not updated, and the ECU 12 transmits information indicating that the MAC is incorrect (MAC has failed) together with the key ID and its own ECU-ID to the CGW 11. In step S13, the CGW 11 again requests the key management server device 20 to update the digital key.

[0088] If the MAC is correct (step S16; YES), the key management system S writes the key in the ECU 12 and transmits the update result to the CGW 11 (step S17). Specifically, the target ECU 12 determines whether the CGW-ID and ECU-ID are correct, and if they are correct, writes the key value for update to the storage unit 12b based on the key ID. Note that the determination whether the CGW-ID and ECU-ID are correct may be made before determining whether the MAC is correct. The target ECU 12 transmits the update result to the CGW 11 together with the key ID and its own ECU-ID. Here, if the CGW-ID or ECU-ID is incorrect, or if an error occurs during writing of the key value, the update result is information indicating that the update was unsuccessful.

[0089] Next, the key management system S transmits the update result and the CGW-ID to the key management server device 20 (step S18). Specifically, the CGW 11 transmits the ECU-ID, key ID, and update result acquired from the target ECU 12 together with its own CGW-ID to the key management server device 20.

[0090] Next, the key management system S determines whether the update result is correct (step S19). Specifically, the key management server device 20 determines whether the update was successful or not based on the contents of the received update result.

[0091] If the update result is correct (step S19; YES), the key management system S ends the key update.

[0092] If the update result is incorrect (step S19; NO), the key management system S performs digital key update again in step S14. Specifically, the key management server device 20 again transmits update information to the CGW 11 as in step 11. The key management system S repeats the process until the update is complete.

[0093] (2.3 Third Example of Operation of Key Management System S) Next, a third embodiment of the operation of the key management system S will be described with reference to Fig. 9. Fig. 9 is a flowchart showing the third embodiment of the operation of the key management system S.

[0094] As in the first embodiment, first, the key management server device 20 of the key management system S refers to the database in the memory unit 22 to identify the key ID, ECU-ID, and CGW-ID of the digital key that needs to be updated, and then performs mutual authentication processing to establish a secure session with the CGW 11 of the in-vehicle electronic device 10.

[0095] As shown in FIG. 8, after establishing a secure session as in step S1, the key management system S starts a session between the key management server device 20 and the CGW 11 (step S20).

[0096] Next, the key management system S transmits information necessary for updating the digital key (step S21). Specifically, the key management server device 20 transmits update information containing the key ID of the digital key that needs to be updated, the key value for updating the digital key, the ECU-ID of the identified ECU 12, and the CGW-ID of the identified CGW 11 to the CGW 11 with which the session has been established.

[0097] The key management server device 20 generates a check code such as a MAC by linking the CGW-ID of the identified CGW 11 and the key value of the digital key that needs to be updated, and encrypting the linked check code with a key shared between the key management server device 20 and the ECU 12 as the correct answer data. The check code is stored in the storage unit 22 in association with the CGW-ID of the identified CGW 11, the ECU-ID of the identified ECU 12, and the key ID of the digital key that needs to be updated. Note that instead of the generated check code such as a MAC, a verification method for the generation method of the check code such as a MAC may be used as the correct answer data. The method for sharing the verification method for the generation method of the check code such as a MAC between the key management server device 20 and the ECU 12 may be the same as that described in the second embodiment.

[0098] Next, the key management system S determines whether or not there is a target ECU 12, as in step S3 (step S22).

[0099] If the target ECU 12 does not exist (step S22; NO), the key management system S performs the error response process as in step S4 (step S23).

[0100] Next, the key management system S performs the digital key update again, as in step S5 (step S24).

[0101] If a target ECU 12 is found (step S22; YES), the key management system S transmits information required for digital key update to the ECU 12 (step S25). Specifically, the CGW 11 transmits the key ID of the digital key that needs to be updated, a key value for updating the digital key, and the CGW-ID of the CGW 11 to the target ECU 12 corresponding to the ECU-ID included in the update information. The ECU 12 acquires the key ID of the digital key that needs to be updated, the key value for updating the digital key, and the CGW-ID from the CGW 11. Here, the key value and / or the CGW-ID are examples of verification data. In this way, the ECU 12 functions as an example of update information acquisition means that acquires update information that has the key value for updating the digital key and includes verification data from a key management server device that manages digital keys.

[0102] Next, the key management system S writes the key in the ECU 12 (step S26). Specifically, the target ECU 12 writes the key value for update to the storage unit 12b based on the key ID.

[0103] Next, the key management system S calculates a MAC in the ECU 12 and transmits the verification result to the CGW 11 (step S27). Specifically, the ECU 12 uses its verification data calculation function to encrypt the verification data, which is a combination of the acquired key value and the CGW-ID, with a key shared with the key management server device 20, to generate verification data as the verification result. In this way, the ECU 12 functions as an example of a verification data calculation means that calculates verification data from the verification data using the update key value. The ECU 12 functions as an example of a verification data calculation means that encrypts the verification data with a shared key shared between the key management server device and the electronic information storage medium to calculate verification data.

[0104] Next, the target ECU 12 outputs the generated verification data to the CGW 11 together with the key ID and its own ECU-ID.

[0105] Next, the key management system S transmits the verification result and the CGW-ID to the key management server device 20 (step S28). Specifically, the CGW 11 transmits the ECU-ID, key ID, and verification data acquired from the target ECU 12 together with its own CGW-ID to the key management server device 20. In this way, the ECU 12 or the CGW 11 functions as an example of a verification data output means that outputs the verification data to a verification means that verifies the verification data in accordance with a predetermined correspondence between the verification data and the verification data.

[0106] Next, the key management system S determines whether the MAC is correct (step S29). Specifically, the key management server device 20 refers to the database in the storage unit 22 based on the received CGW-ID, ECU-ID, and key ID, reads a check code such as a MAC of the correct data, and compares the correct data with the received verification data to determine whether they match. Note that the key management server device 20 may read a key value based on the received key ID in accordance with a generation method stored in the storage unit 22, concatenate the received CGW-ID and key value, and encrypt the concatenated value with a key shared between the key management server device 20 and the ECU 12 to generate a check code such as a MAC of the correct data. Here, generating verification data by encrypting data obtained by concatenating an update key value, which is an example of verification data, with a CGW-ID using a shared key with management server device 20 is an example of a predetermined association between the verification data and the verification data. In this way, key management server device 20 functions as an example of a verification means that verifies the verification data in accordance with the predetermined association between the verification data and the verification data.

[0107] If the MAC is correct (step S29; YES), the key management system S ends the key update. The key management server device 20 stores the update completion in the database of the storage unit 22 based on the received CGW-ID, ECU-ID, and key ID.

[0108] If the MAC is incorrect (step S29; NO), the key management system S performs digital key update again in step S24. Specifically, the key management server device 20 again transmits update information to the CGW 11 as in step S21. The key management system S repeats the process until the update is completed.

[0109] After the digital key has been updated, the key management server device 20 performs processing such as reprogramming based on the updated digital key.

[0110] (2.4 Fourth Example of Key Management System S) Next, a fourth embodiment of the operation of the key management system S will be described with reference to Fig. 10. Fig. 10 is a flowchart showing the fourth embodiment of the operation of the key management system S.

[0111] As in the first embodiment, first, the key management server device 20 of the key management system S refers to the database in the memory unit 22 to identify the key ID, ECU-ID, and CGW-ID of the digital key that needs to be updated, and then performs mutual authentication processing to establish a secure session with the CGW 11 of the in-vehicle electronic device 10.

[0112] Next, as in step S1, after establishing a secure session, the key management system S starts a session between the key management server device 20 and the CGW 11 (step S30). Specifically, the key management server device 20 transmits update information to the CGW 11 with which the session has been established, the update information including the key ID of the digital key that needs to be updated, a key value for updating the digital key, the ECU-ID of the identified ECU 12, the CGW-ID of the identified CGW 11, the generated verification random number, and the generated check code such as a MAC. Here, the generated verification random number is an example of verification data. The key value and CGW-ID included in the update information are also examples of verification data. The generated check code such as a MAC is also an example of correct answer data.

[0113] The key management server device 20 stores the generated verification random number and the generated MAC in the memory unit 22, associating them with the CGW-ID of the identified CGW 11, the ECU-ID of the identified ECU 12, and the key ID of the digital key that needs to be updated.

[0114] Next, the key management system S transmits information necessary for updating the digital key (step S31). Specifically, the key management server device 20 transmits update information including the key ID of the digital key that needs to be updated, a key value for updating the digital key, the ECU-ID of the identified ECU 12, the CGW-ID of the identified CGW 11, and the generated verification random number (an example of verification data) to the CGW 11 with which the session has been established. The key management server device 20 stores the generated verification random number in the storage unit 22 in association with the CGW-ID of the identified CGW 11, the ECU-ID of the identified ECU 12, and the key ID of the digital key that needs to be updated.

[0115] Next, the key management system S determines whether or not there is a target ECU 12, as in step S3 (step S32).

[0116] If the target ECU 12 is not present (step S32; NO), the key management system S performs an error response process (step S33) as in step S4.

[0117] Next, the key management system S performs the digital key update again, as in step S5 (step S34).

[0118] If a target ECU 12 is found (step S32; YES), the key management system S transmits information required for digital key update to the ECU 12 (step S35). Specifically, the CGW 11 transmits the key ID of the digital key that needs to be updated, a key value for updating the digital key, a verification random number, the CGW-ID of the CGW 11, and a MAC check code to the target ECU 12 that corresponds to the ECU-ID included in the update information. The ECU 12 acquires the key ID of the digital key that needs to be updated, the key value for updating the digital key, the CGW-ID, the verification random number, and the check code from the CGW 11. Here, the key value for updating and / or the CGW-ID are an example of verification data. The verification random number is an example of verification data. Note that if the ECU 12 holds the CGW-ID, the CGW 11 does not need to transmit the CGW-ID. In this way, ECU12 functions as an example of an update information acquisition means that acquires update information having a key value for updating the digital key and including verification data from a key management server device that manages the digital key.

[0119] Next, the key management system S determines whether the MAC is correct in the ECU 12, as in step S16 (step S36).

[0120] If the MAC is incorrect (step S36; NO), the ECU 12 transmits information indicating that the MAC is incorrect, together with the key ID and its own ECU-ID, to the CGW 11. In step S33, the CGW 11 again requests the key management server device 20 to update the digital key.

[0121] If the MAC is correct (step S36; YES), the key management system S performs key writing and verification processing in the ECU as in step S7, and transmits the verification result to the CGW 11 (step S37). Note that as in step S17, the target ECU 12 may determine whether the CGW-ID and ECU-ID are correct, and if correct, may write an update key value to the storage unit 12b based on the key ID, or may transmit the update result together with the verification result to the CGW 11.

[0122] Next, in the key management system S, the CGW 11 transmits the verification result and the CGW-ID to the key management server device 20 as in step S8 (step S38).

[0123] Next, the key management system S determines whether the verification result is correct (step S39), as in step S9. Note that, as in step S19, the key management server device 20 may further determine whether the update was successful or not based on the received update result.

[0124] If the verification result is correct (step S39; YES), the key management system S ends the key update. The key management server device 20 stores the update completion in the database of the storage unit 22 based on the received CGW-ID, ECU-ID, and key ID.

[0125] If the verification result is incorrect (step S39; NO), the key management system S performs digital key update again in step S34. Specifically, the key management server device 20 again transmits update information to the CGW 11, as in step S31. The key management system S repeats the process until the update is complete.

[0126] It is noted that the key management server device 20 does not have to transmit the generated check code such as MAC. In this case, as in step S27, the ECU 12 encrypts the verification data, which is the linkage between the acquired key value and the CGW-ID, with a key shared with the key management server device 20 to generate verification data, which is the verification result, and transmits it to the CGW 11. Then, the two types of verification results are transmitted to the key management server device 20. In step S39, it is determined whether the two types of verification results are correct. If the two types of verification results are correct, the update is completed.

[0127] Note that the operations of the above-described embodiments 1 to 4 may be performed by connecting the diagnostic device 30 to the DLC 14 without going through the TCU 13. Also, authentication may be performed or a secure session may be established between the CGW 11 and the ECU 12. When responding to the result to the key management server device 20 via the TCU 13 using the CGW-ID, the CGW 11 may also create an electronic signature using its own private key for the data to be sent to the TCU 13 and send it to the TCU 13.

[0128] Furthermore, to share the verification method, the key management server device 20 may include information on the verification method in the update information. The verification data may be data in which the update key value and the CGW-ID are linked, or the key value alone, or the key value may incorporate the ECU-ID, key ID, etc. in addition to the CGW-ID.

[0129] Furthermore, in step S9, step S19, step S29, or step S39, the key management server device 20 may determine whether the verification result is correct (whether verification failed) or whether the update result is correct (whether verification of the check code on the ECU 12 side failed), as well as whether the CGW-ID of the CGW 11 is the expected one, whether verification of the electronic signature failed, etc. Also, a limit may be placed on the number of times to retry key update. If the number of retransmissions exceeds a predetermined number, the key management server device 20 does not retransmit the key and notifies the key management system S. For example, the key management server device 20 displays a notice on the display unit 23 that the retransmission has exceeded the predetermined number and the update could not be completed, or notifies a PC terminal used by the administrator to access the key management server device 20.

[0130] As described above, according to the above embodiment, the ECU 12 acquires update information, including a key value for updating the digital key and verification data, from the key management server device 20 that manages the digital key. The ECU 12, which is an example of an electronic information storage medium, calculates verification data from the verification data using the update key value. The ECU 12 then outputs the verification data to a verification means that verifies the verification data according to a predetermined correspondence between the verification data and the verification data. This checks whether the correspondence between the verification data and the verification data is correct, thereby verifying whether the digital key has been properly updated. This verification allows the digital key to be reliably written to the ECU 12 of the on-board electronic device 10. Therefore, proper authentication and reprogramming can be performed. Even if a memory write error in the ECU 12, a processing error (decryption error, etc.) in the CGW 11, or data transmission to an incorrect destination occurs due to an error, the digital key can be reliably written to the ECU 12. Furthermore, the system is robust against transmission errors and tampering that change the key value during transmission.

[0131] When ECU12 encrypts the verification data using an update key value to calculate verification data, and compares the verification data with the value into which the verification data is encrypted in the key management server device 20 to verify the verification data, it can verify whether the digital key has been properly updated in the key management server device 20.

[0132] When the verification data includes an update key value, the verification data is encrypted using a shared key between the key management server device 20 and the ECU 12 to calculate verification data, and the verification data is compared with the value obtained by encrypting the verification data using the shared key in the key management server device 20 to verify the verification data, it can be verified whether the digital key has been updated appropriately.

[0133] If the verification data is random numbers, security is improved.

[0134] When an update key value is written based on the verification results obtained by comparing the verification data with the value obtained by encrypting the verification data with the shared key in the key management server device 20, it can be verified whether the digital key has been properly updated in the key management server device 20.

[0135] When the verification data and the verification data are not associated with each other as specified, if update information is acquired again from the key management server device 20, the digital key of the ECU 12 of the in-vehicle electronic device 10 can be updated reliably.

[0136] The system further includes a CGW11, which is an example of an intermediary electronic information storage medium that distributes update information sent from the key management server device 20 to multiple ECUs 12. When the CGW11 determines whether or not there is an ECU 12 to be updated based on the update information, and determines whether or not to resend the update information to the ECU 12, the computational resources of the electronic information storage medium can be utilized effectively.

[0137] When update information is transmitted to the ECU 12 after a secure session between the ECU 12 and the key management server device 20 is started, the system becomes robust against external attacks. [Explanation of symbols]

[0138] 10 In-vehicle electronic equipment 11 CGW (intermediary electronic information storage medium) 12 ECU (electronic information storage medium) 20 Key management server device S Key Management System

Claims

1. an update information acquisition means for acquiring update information having a key value for updating the digital key and including verification data from a key management server device that manages the digital key; a verification data calculation means for calculating verification data from the verification data using the update key value; a verification data output means for outputting the verification data to a verification means for verifying the verification data in accordance with a predetermined correspondence between the verification data and the verification data; An electronic information storage medium comprising:

2. 2. The electronic information storage medium according to claim 1, the verification data calculation means encrypts the verification data with the update key value to calculate the verification data; An electronic information storage medium, wherein the verification means verifies the verification data by comparing the verification data with a value obtained by encrypting the verification data in the key management server device.

3. 3. The electronic information storage medium according to claim 1, the verification data includes the update key value, the verification data calculation means encrypts the verification data using a shared key shared between the key management server device and the electronic information storage medium to calculate the verification data; An electronic information storage medium, wherein the verification means verifies the verification data by comparing the verification data with a value obtained by encrypting the verification data with the shared key in the key management server device.

4. 3. The electronic information storage medium according to claim 2, 10. An electronic information storage medium, wherein the verification data is a random number.

5. 4. The electronic information storage medium according to claim 3, An electronic information storage medium characterized in that the update key value is written based on the verification result obtained by comparing the verification data with the value obtained by encrypting the verification data with the shared key in the key management server device.

6. 3. The electronic information storage medium according to claim 1, An electronic information storage medium characterized in that, if the specified correspondence is not established between the verification data and the verification data, the update information acquisition means re-acquires the update information from the key management server device.

7. an update information acquisition step in which update information acquisition means acquires update information having a key value for updating the digital key and including verification data from a key management server device that manages the digital key; a verification data calculation step in which a verification data calculation means calculates verification data from the verification data using the key value for update; a verification data output step in which a verification data output means outputs the verification data to a verification means that verifies the verification data in accordance with a predetermined correspondence between the verification data and the verification data; A key management method comprising:

8. Computer, an update information acquisition means for acquiring update information having a key value for updating the digital key and including verification data from a key management server device that manages the digital key; verification data calculation means for calculating verification data from the verification data using the update key value; and A program for an electronic information storage medium, characterized in that it causes a verification means for verifying the verification data in accordance with a predetermined correspondence between the verification data and the verification data to function as a verification data output means for outputting the verification data.

9. A key management system including an electronic information storage medium for storing a digital key and a key management server device for managing the digital key, an update information transmitting means, in the key management server device, for transmitting update information to the electronic information storage medium, the update information including a key value for updating the digital key and verification data; a verification data calculation means in the electronic information storage medium for calculating verification data from the verification data using the update key value; a verification means for verifying the verification data in accordance with a predetermined correspondence between the verification data and the verification data; a determination means for determining whether or not to retransmit the update information to the electronic information storage medium according to the verification result; A key management system having:

10. 10. The key management system of claim 9, an intermediary electronic information storage medium that distributes the update information transmitted from the key management server device to the plurality of electronic information storage media; A key management system characterized in that a determination means determines whether or not to resend the update information to the electronic information storage medium based on the result of the intermediate electronic information storage medium determining whether or not there is an electronic information storage medium to be updated based on the update information.

11. 11. The key management system of claim 10, A key management system characterized in that, after a secure session is initiated between the intermediary electronic information storage medium and the key management server device, the update information transmission means transmits the update information to the electronic information storage medium.

Citation Information

Patent Citations

  • Portable recording medium and terminal

    JP2013246672A