Electronic control apparatus update system, secure device, gateway apparatus, and electronic control apparatus update method
The electronic control unit update system uses a gateway and secure device to authenticate and establish a secure channel, ensuring only authorized update files are transmitted, thereby securing the in-vehicle network.
Patent Information
- Application Number
- JP2024021181
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-15
- Publication Date
- 2025-08-27
AI Technical Summary
The in-vehicle network security is compromised when unauthorized update files are transmitted to electronic control units, especially when using diagnostic devices connected via a wired connection, as the identity of these devices cannot be guaranteed by the key management center.
An electronic control unit update system involving a gateway device, a diagnostic machine, and a secure device, where the gateway and secure devices perform mutual authentication using encryption keys issued by the key management center to establish a secure channel, ensuring only authorized update files are transmitted.
This system ensures that update files for electronic control units are received from devices whose identity is guaranteed by the key management center, preventing unauthorized access and maintaining network security.
Smart Images

Figure 2025125246000001_ABST
Abstract
Description
[Technical Field]
[0001] The present application relates to a technology for updating an electronic control unit (ECU) mounted on a vehicle. [Background technology]
[0002] As electronic control of vehicles (automobiles) has progressed, electronic control units (ECUs) used for electronic vehicle control have begun to be installed in vehicles. Electronic control units are used to control various vehicle functions, such as engine control, brake control, and steering control. In recent vehicles, the various ECUs installed in the vehicle are networked, and the ECUs work together to perform complex controls.
[0003] The network connecting the various electronic control units installed in a vehicle is called an in-vehicle network. CAN (Controller Area Network) is the standard for in-vehicle networks. Electronic control units installed in a vehicle are subject to various cyber attacks. Unauthorized use of an electronic control unit can lead to unauthorized use of the vehicle. For this reason, the security of electronic control units is strengthened by storing encryption keys in the electronic control units.
[0004] Even if the security of an electronic control unit is strengthened by using an encryption key, if the encryption key of the electronic control unit is leaked to a third party, the electronic control unit may be used fraudulently. Therefore, in recent years, vehicle manufacturers have established key management centers that securely generate encryption keys for the electronic control units installed in their vehicles and securely distribute the encryption keys of the electronic control units to factories and other locations, thereby preventing the leakage of encryption keys stored in the electronic control units.
[0005] When the encryption algorithm used in an electronic control unit is compromised or when there is a possibility that the encryption key stored in the electronic control unit has been leaked, the vehicle manufacturer updates the encryption key and other information stored in the electronic control unit. To update the encryption key and other information stored in the electronic control unit, it is necessary to access the in-vehicle network and transmit an update file for the electronic control unit to the electronic control unit to be updated. Methods for accessing the in-vehicle network include a wireless connection method (e.g., Patent Document 1) that uses a TCU (Telematics Control Unit) installed in the vehicle to access the in-vehicle network via a wireless network, and a wired connection method (e.g., Patent Document 2) that uses a diagnostic device connected to the vehicle's diagnostic port (OBD Port, OBD: On-Board Diagnostics) to access the in-vehicle network. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-326689 [Patent Document 2] Japanese Patent Application Publication No. 2019-161521 Summary of the Invention [Problem to be solved by the invention]
[0007] The update file for the electronic control unit is encrypted with an encryption key that is paired with the encryption key stored in the electronic control unit to be updated. However, if an unauthorized update file is used, the security of the in-vehicle network may be compromised. For this reason, it is necessary for the in-vehicle network to verify that the update file for the electronic control unit has been sent from a device whose identity is guaranteed by the key management center. When updating an electronic control unit using a wireless connection method, the device that accesses the in-vehicle network is the key management center, but when updating an electronic control unit using a wired connection method, the device that accesses the in-vehicle network is a diagnostic device.
[0008] Therefore, the present application aims to enable the in-vehicle network to confirm that the update file for the electronic control unit has been sent from a device whose identity is guaranteed by the key management center, even when updating the electronic control unit using a diagnostic device connected to the vehicle's diagnostic port. [Means for solving the problem]
[0009] The first invention that solves the above-mentioned problems is a system invention, which is an electronic control unit update system including a gateway device connected to one or more electronic control units mounted on a vehicle, a diagnostic machine connected to the gateway device via a diagnostic port provided in the vehicle, and a secure device connected to the diagnostic machine. The gateway device according to the first aspect of the present invention includes a memory that stores a first encryption key issued to the gateway device by a key management center that distributes update files for electronic control devices, and a first control unit that, when the diagnostic machine connects to the gateway device, communicates data with the secure device via the diagnostic machine, performs mutual authentication with the secure device using the first encryption key, and then exchanges session keys to establish a secure channel with the secure device. The secure device according to the first aspect of the present invention includes a memory that stores a second encryption key issued to the secure device by the key management center, and a second control unit that communicates data with the gateway device via the diagnostic machine, performs mutual authentication with the gateway device using the second encryption key, and then exchanges session keys to establish a secure channel with the gateway device. The diagnostic machine according to the first aspect of the present invention includes a reader / writer that communicates data with the secure device, and a third control unit that, when connected to the gateway device, relays data communication between the gateway device and the secure device, and, when a secure channel is established between the secure device and the gateway device, transmits an update file for the electronic control device to the gateway device using the secure channel. In the first invention, it is desirable that the gateway device stores a root certificate of the key management center and a first private key and a first public key certificate as the first encryption key, the secure device stores the root certificate and a second private key and a second public key certificate as the second encryption key, and the first control unit of the gateway device and the second control unit of the secure device each perform mutual authentication and establish a secure channel using a PKI (Public Key Infrastructure) mechanism. In addition, this application also claims patent rights to the secure device that constitutes the electronic control unit update system according to the first invention, and the gateway device that constitutes the electronic control unit update system according to the first invention.
[0010] The second invention for solving the above-mentioned problem is a method invention, which is an electronic control unit update method executed by a gateway device connected to a plurality of electronic control units, a diagnostic machine connected to the gateway device via a diagnostic port provided in a vehicle, and a secure device connected to the diagnostic machine. An electronic control device updating method according to a second aspect of the present invention includes step a) of connecting the diagnostic device to the gateway device; step b) of using the diagnostic device to relay data communication between the gateway device and the secure device, and the gateway device and the secure device performing mutual authentication using a first encryption key issued to the gateway device by a key management center that distributes update files for electronic control devices and a second encryption key issued to the secure device by the key management center, and then exchanging session keys to establish a secure channel between the gateway device and the secure device; and step c) of using the diagnostic device to transmit the update file for the electronic control device to the gateway device using the secure channel between the gateway device and the secure device. In the electronic control device updating method according to the second aspect of the present invention, it is desirable that the gateway device stores a root certificate of the key management center and a first private key and a first public key certificate as the first encryption key, and the secure device stores the root certificate and a second private key and a second public key certificate as the second encryption key, and that in step b, the gateway device and the secure device perform mutual authentication and establish a secure channel using a PKI (Public Key Infrastructure) mechanism. [Effects of the Invention]
[0011] In this application, by making the secure device that communicates data with the diagnostic machine a device whose identity is guaranteed by the key management center, even when a wired connection for data communication with the electronic control unit is established using a diagnostic machine connected to the vehicle's diagnostic port, the electronic control unit can receive update files for the electronic control unit from a device whose identity is guaranteed by the key management center. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 2 is a diagram illustrating an electronic control unit update system. [Figure 2] FIG. 2 is a diagram showing electrical functional blocks of the gateway device. [Figure 3] FIG. 2 is a diagram showing electrical function blocks of a diagnostic machine. [Figure 4] FIG. 1 is a diagram showing electrical function blocks of a secure device. [Figure 5] FIG. 2 is a diagram illustrating an electronic control device updating method. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, an embodiment of the present invention will be described. This embodiment is intended to facilitate understanding of the present invention, and the present invention is not limited to this embodiment. Furthermore, unless otherwise specified, the drawings are schematic diagrams drawn to facilitate understanding of the present invention.
[0014] FIG. 1 is a diagram illustrating an electronic control unit update system 1 according to this embodiment. The electronic control unit update system 1 shown in FIG. 1 is a system in which an electronic control unit update method, which is an invention related to the method disclosed in this application, is implemented. The electronic control unit update system 1 according to this embodiment includes a gateway device 3 connected to one or more electronic control units 21 mounted on a vehicle 2, a diagnostic machine 5 connected to the gateway device 3 via a diagnostic port 22 provided in the vehicle 2, and a secure device 4 connected to the diagnostic machine 5. Furthermore, FIG. 1 illustrates a key management center 6 operated by the vehicle manufacturer.
[0015] An in-vehicle network 20 is constructed in the vehicle 2, to which a plurality of electronic control units 21 are connected. The electronic control units 21 are microcomputers used for electronic control of the vehicle 2. The functions of the vehicle 2 controlled by the electronic control units 21 differ for each electronic control unit 21. The electronic control units 21 store encryption keys and the like used to decrypt encrypted data sent to the electronic control units 21.
[0016] Furthermore, the in-vehicle network 20 established in the vehicle 2 is provided with a gateway device 3 that functions as a connection point between the in-vehicle network 20 and the outside. The gateway device 3 is a microcomputer, and is sometimes called a central gateway (CGW). All electronic control units 21 included in the in-vehicle network 20 are connected to the gateway device 3. The gateway device 3 has a function of relaying data communication between the electronic control units 21 included in the in-vehicle network 20 and external devices, and a function of ensuring security of the in-vehicle network 20. The gateway device 3 according to the present application has a function of performing mutual authentication with the secure device 4 and establishing a secure channel, which is a safe communication path protected by a session key, between the gateway device 3 and the secure device 4, as a function of ensuring security of the in-vehicle network 20.
[0017] The secure device 4 is a device equipped with security functions for protecting data from data leakage, unauthorized access, tampering, and the like. The secure device 4 has a function for performing mutual authentication with the gateway device 3 and establishing a secure channel between the secure device 4 and the gateway device 3. Various types of secure devices 4 can be used in the present application. Examples of secure devices 4 that can be used in the present application include IC cards, SIM cards, and USB keys. An embedded SIM can also be used as the secure device 4. Furthermore, if an application that provides the functions required for the secure device 4 according to the present application is installed in a smartphone that supports NFC (Near Field Communication), the smartphone can also be used as the secure device 4.
[0018] The diagnostic machine 5 is a computer device that is provided in the vehicle 2, connected to the vehicle 2 via the diagnostic port 22, and used to read out fault codes from the electronic control unit 21 provided in the vehicle 2. The diagnostic machine 5 according to this embodiment has a function for communicating with the secure device 4. Some diagnostic machines 5 are compatible only with vehicles 2 made by a specific vehicle manufacturer, while other diagnostic machines 5 are general-purpose diagnostic machines that are compatible with multiple vehicle manufacturers. The invention disclosed in this application is suitable for the latter type of diagnostic machine 5, but can also be applied to the former type of diagnostic machine 5.
[0019] When updating the electronic control unit 21, the gateway device 3 obtains an update file for the electronic control unit 21 distributed by the key management center 6 from a device connected to the gateway device 3, and transmits the update file for the electronic control unit 21 to the electronic control unit 21 to be updated. The electronic control unit 21 obtains the update file for the electronic control unit 21 via the gateway device 3 and updates the encryption key and other data stored in the electronic control unit 21. The update file for the electronic control unit 21 is encrypted in a state that can be decrypted by the electronic control unit 21, but to prevent unauthorized update files from entering the in-vehicle network 20, the gateway device 3 must obtain the update file for the electronic control unit 21 from a device whose identity is guaranteed by the key management center 6.
[0020] When updating the electronic control unit 21 using a diagnostic machine 5 connected to the diagnostic port 22, the gateway device 3 connects to the diagnostic machine 5 connected to the diagnostic port 22. It would be ideal if the diagnostic machine 5 could be a device whose identity is guaranteed by the key management center 6, but since diagnostic machines 5 compatible with multiple vehicle manufacturers are often used, it is difficult to make the diagnostic machine 5 a device whose identity is guaranteed by the key management center 6. Furthermore, if a diagnostic machine 5 is prepared for each vehicle manufacturer, the cost of purchasing the diagnostic machine 5 will be high.
[0021] In the present application, even when a general-purpose diagnostic machine 5 compatible with various vehicle manufacturers is used to update the electronic control unit 21, the gateway device 3 uses the secure device 4, whose identity is guaranteed by the key management center 6, as an authentication device for the diagnostic machine 5 so that the update file for the electronic control unit 21 can be obtained from a device whose identity is guaranteed by the key management center 6. Because the secure device 4 is relatively inexpensive, even if a secure device 4 is prepared for each vehicle manufacturer, the required cost will not be high.
[0022] As described above, in the electronic control device update system 1 according to the present application, when updating the electronic control device 21, the devices whose identities are guaranteed by the key management center 6 are the secure device 4 and the gateway device 3. The gateway device 3 stores the first encryption key 33 issued to the gateway device 3 by the key management center 6 as information whose identity is guaranteed by the key management center 6. Furthermore, the secure device 4 stores the second encryption key 43 issued to the secure device 4 by the key management center 6 as information whose identity is guaranteed by the key management center 6.
[0023] When updating the electronic control device 21, the secure device 4 and the gateway device 3 need to mutually confirm that the electronic control device 21 is a device whose identity is guaranteed by the key management center 6. Therefore, when updating the electronic control device 21, the secure device 4 and the gateway device 3 communicate data using the diagnostic device 5 as a repeater, perform mutual authentication using the first encryption key 33 and the second encryption key 43 issued by the key management center 6, and establish a secure channel between the secure device 4 and the gateway device 3. By performing mutual authentication between the secure device 4 and the gateway device 3, the secure device 4 and the gateway device 3 can mutually confirm that the secure device 4 and the gateway device 3 are devices whose identity is guaranteed by the key management center 6. Furthermore, by transmitting an update file for the electronic control device 21 to the gateway device 3 using the secure channel established between the secure device 4 and the gateway device 3, the gateway device 3 can detect tampering with the update file for the electronic control device 21 or spoofing of the device sending the update file for the electronic control device 21.
[0024] The types of the second encryption key 43 stored in the secure device 4 and the first encryption key 33 stored in the gateway apparatus 3 are determined by the type of encryption method used in mutual authentication. If the encryption method used in mutual authentication is a symmetric key encryption method such as AES (Advanced Encryption Standard), the type of encryption key stored in the secure device 4 and the gateway apparatus 3 will be an encryption key of the symmetric key encryption method. In this case, the secure device 4 and the gateway apparatus 3 perform mutual authentication using a challenge-response method, and then exchange session keys to establish a secure channel.
[0025] When the encryption method used for mutual authentication is a public key encryption method such as ECDSA (Elliptic Curve Digital Signature Algorithm), the type of encryption keys stored in the secure device 4 and the gateway apparatus 3 is a pair of encryption keys of the public key encryption method. Specifically, the pair of encryption keys of the public key encryption method is a private key and a public key certificate. In this case, the secure device 4 and the gateway apparatus 3 perform mutual authentication using a PKI (Public Key Infrastructure) mechanism, and then exchange session keys to establish a secure channel.
[0026] Hereinafter, an embodiment will be described in which the encryption method used in mutual authentication is a public key encryption method such as ECDSA.
[0027] FIG. 2 shows electrical functional blocks of the gateway device 3. The gateway device 3 includes a central processing unit (CPU) 300, a read-only memory (ROM) 301, a random access memory (RAM) 302, a solid-state drive (SSD) 303, and a data transfer circuit 304. The ROM 301 is a non-volatile memory that stores computer programs executed by the CPU 300. The RAM 302 is a volatile memory that temporarily stores data by the CPU 300. The data transfer circuit 304 is a circuit that controls data communication in accordance with the communication protocol of the in-vehicle network 20. The data transfer circuit 304 has functions such as relaying data communication between electronic control units 21 connected to the in-vehicle network 20 and preventing unauthorized access to the in-vehicle network 20 from outside. The SSD 303 is a storage medium that uses a semiconductor memory. Various types of data used by the CPU 300 are stored in the SSD 303. In this embodiment, the SSD 303 stores a first private key 31 issued by the key management center 6 to the gateway device 3, a first public key certificate 32 issued by the key management center 6 to the gateway device 3, and a root certificate 60 of the key management center 6 that issued the first public key certificate 32. The first public key certificate 32 includes the public key of the gateway device 3, and further includes a digital signature of the first public key certificate 32 generated using the private key of the key management center 6. Furthermore, the root certificate 60 of the key management center 6 includes the public key of the key management center 6. The pair of the first private key 31 and the first public key certificate 32 corresponds to the first encryption key 33 in FIG. 1.
[0028] The CPU 300 is an integrated circuit configured to be able to execute a computer program. A computer program is stored in the ROM 301 of the gateway apparatus 3. The computer program executes a process of establishing a secure channel by exchanging a session key with the secure device 4 after performing mutual authentication with the secure device 4 using a PKI mechanism. By executing this computer program, the CPU 300 functions as the first control unit 30 according to the present application.
[0029] FIG. 3 shows electrical functional blocks of the diagnostic device 5. The diagnostic device 5 includes a CPU 500, a ROM 501, a RAM 502, an SSD 503, a vehicle communication module 504, a connector 505, and a reader / writer 506. The ROM 501 is a non-volatile memory that stores computer programs executed by the CPU 500. The RAM 502 is a volatile memory that temporarily stores data in the CPU 500. The connector 505 is a terminal for detachably connecting the diagnostic device 5 to a diagnostic port 22 provided in the vehicle 2. The connector 505 is connected to the vehicle communication module 504. The vehicle communication module 504 is a circuit that performs data communication in accordance with the communication protocol of the in-vehicle network 20. The SSD 503 is a storage medium that uses a semiconductor memory. Various data used by the CPU 500 is stored in the SSD 503. The reader / writer 506 is a device that performs data communication with the secure device 4.
[0030] The CPU 500 is an integrated circuit configured to be able to execute a computer program. A computer program for controlling the reader / writer 506 to execute processes such as relaying data communication between the secure device 4 and the gateway device 3 is stored in the ROM 501 of the diagnostic device 5. By executing this computer program, the CPU 500 functions as a third control unit 50 that, when transmitting an update file for the electronic control unit 21 to the gateway device 3, relays data communication between the gateway device 3 and the secure device 4, performs mutual authentication and establishes a secure channel between the secure device 4 and the gateway device 3, and then transmits the update file for the electronic control unit 21 to the gateway device 3 using this secure channel.
[0031] FIG. 4 shows electrical functional blocks of the secure device 4. The secure device 4 includes a CPU 400, a ROM 401, a RAM 402, a non-volatile memory (NVM) 403, and an input / output interface 404. The ROM 401 is a non-volatile memory that stores computer programs executed by the CPU 400. The RAM 402 is a volatile memory that temporarily stores data in the CPU 400. The input / output interface 404 is a circuit that performs data communication with a reader / writer 506 of the diagnostic device 5. The NVM 403 is an electrically rewritable non-volatile memory. Various types of data used by the CPU 400 are stored in the NVM 403. In this embodiment, the NVM 403 stores a second private key 41 issued to the secure device 4 by the key management center 6, a second public key certificate issued to the secure device 4 by the key management center 6, and a root certificate 60 of the key management center 6 that issued the second public key certificate 42. The second public key certificate 42 includes the public key of the secure device 4, and further includes a digital signature of the second public key certificate 42 generated using the private key of the key management center 6. Furthermore, the root certificate 60 of the key management center 6 includes the public key of the key management center 6. The second private key 41 and the second public key certificate 42 correspond to the second encryption key in FIG.
[0032] The CPU 400 is an integrated circuit configured to be able to execute a computer program. A computer program is stored in the ROM 401 of the secure device 4. The computer program executes a process of establishing a secure channel by exchanging a session key with the secure device 4 after performing mutual authentication with the gateway apparatus 3 using a PKI mechanism. By executing this computer program, the CPU 400 functions as the second control unit 40 according to the present application.
[0033] Next, an electronic control unit updating method executed by the electronic control unit updating system 1 shown in Fig. 1 will be described. Fig. 5 is a diagram illustrating the electronic control unit updating method. In the electronic control unit updating method according to the embodiment, the second public key certificate 42 stored in the electronic control unit 21 is used as a client certificate, and the first public key certificate 32 stored in the gateway device 3 is used as a server certificate, and mutual authentication (handshake) and session key exchange are performed using a PKI mechanism such as TLS (Transport Layer Security). When executing the electronic control unit updating method, the diagnostic device 5 and the gateway device 3 communicate according to the communication protocol of the in-vehicle network 20, and the diagnostic device 5 and the secure device 4 communicate using a communication protocol other than the communication protocol of the in-vehicle network 20 (for example, ISO / IEC 7816 part 3).
[0034] When updating the electronic control unit 21 installed in the vehicle 2, the diagnostic machine 5 connects to the gateway device 3 via the diagnostic port 22 of the vehicle 2 (step S1).
[0035] When the diagnostic device 5 is connected, the first control unit 30 of the gateway device 3 transmits a verification request message for the first public key certificate 32 to be used as the server certificate to the diagnostic device 5 via the diagnostic port 22 (step S2). The third control unit 50 of the diagnostic device 5 transfers the verification request message for the first public key certificate 32 to the secure device 4 using the reader / writer 506 (step S3).
[0036] The second control unit 40 of the secure device 4 verifies the first public key certificate 32 sent by the gateway apparatus 3 via the diagnostic apparatus 5 (step S4). If the hash value obtained by decrypting the digital signature added to the first public key certificate 32 using the public key included in the root certificate 60 is the same as the hash value calculated from the first public key certificate 32, the second control unit 40 of the secure device 4 determines that the verification of the first public key certificate 32 has been successful. By verifying the first public key certificate 32, the second control unit 40 of the secure device 4 can confirm whether the gateway apparatus 3 that stored the first public key certificate 32 is a device whose identity is guaranteed by the key management center 6. The second control unit 40 of the secure device 4 transmits the verification result of the first public key certificate 32 to the diagnostic apparatus 5 (step S5), and the third control unit 50 of the diagnostic apparatus 5 transfers the verification result of the first public key certificate 32 to the gateway apparatus 3 via the diagnostic port 22 (step S6).
[0037] If the verification result of first public key certificate 32 indicates success, first control unit 30 of gateway device 3 transmits a transmission request message for second public key certificate 42 to diagnostic device 5 to secure device 4 (step S7). Third control unit 50 of diagnostic device 5 transfers the transmission request message for second public key certificate 42 received from gateway device 3 to secure device 4 (step S8). Second control unit 40 of secure device 4 transmits second public key certificate 42 stored in NVM 403 of secure device 4 to diagnostic device 5 (step S9). Third control unit 50 of diagnostic device 5 transfers second public key certificate 42 received from secure device 4 to gateway device 3 (step S10).
[0038] The first control unit 30 of the gateway device 3 verifies the second public key certificate 42 acquired from the secure device 4 via the diagnostic device 5 (step S11). If the hash value obtained by decrypting the digital signature added to the second public key certificate 42 using the public key included in the root certificate 60 is the same as the hash value calculated from the second public key certificate 42, the first control unit 30 of the gateway device 3 determines that the verification of the second public key certificate 42 has been successful. By verifying the second public key certificate 42, the first control unit 30 of the gateway device 3 can confirm whether the secure device 4 that stores the second public key certificate 42 is a device whose identity is guaranteed by the key management center 6. The steps up to this point are steps related to mutual authentication.
[0039] If the verification of second public key certificate 42 is successful, it means that the gateway device 3 and the secure device 4 have mutually confirmed that the device is one whose identity is guaranteed by the key management center 6. Therefore, if the gateway device 3 succeeds in verifying the second public key certificate 42, the second control unit 40 of the secure device 4 and the first control unit 30 of the gateway device 3 generate and exchange a session key using random numbers, and establish a secure channel using the session key between the secure device 4 and the gateway device 3 (step S12).
[0040] The first private key 31 stored in the gateway device 3 and the second private key 41 stored in the secure device 4 are each used in exchanging a session key. The first control unit 30 of the gateway device 3 encrypts a random number value used to generate a session key for the gateway device 3 using the first private key 31 stored in the gateway device 3, and transmits the encrypted data to the secure device 4. The second control unit 40 of the secure device 4 decrypts the encrypted data using the public key included in the first public key certificate 32, and generates a session key for the gateway device 3. Similarly, the second control unit 40 of the secure device 4 encrypts a random number value used to generate a session key for the secure device 4 using the second private key 41 stored in the secure device 4, and transmits the encrypted data to the gateway device 3. The first control unit 30 of the gateway device 3 decrypts the encrypted data using the public key included in the second public key certificate 42, and generates a session key for the secure device 4.
[0041] Once the secure channel is established, the third control unit 50 of the diagnostic machine 5 transmits a command to the secure device 4 requesting encryption of the update file with the session key (step S13). The second control unit 40 of the secure device 4 encrypts the update file for the electronic control unit 21 with the session key used in the secure channel with the gateway device 3 (step S14), and transmits the update file encrypted with the session key to the diagnostic machine 5 (step S15).
[0042] The third control unit 50 of the diagnostic machine 5 transmits the update file encrypted with the session key to the gateway device 3 (step S16), and requests that the electronic control device 21 be updated using the update file encrypted with the session key. The first control unit 30 of the gateway device 3 decrypts the encrypted update file using the session key used in the secure channel with the secure device 4 (step S17). The first control unit 30 of the gateway device 3 transmits the decrypted update file to the electronic control device 21 corresponding to the update file, and updates the electronic control device 21 corresponding to the update file (step S18). [Explanation of symbols]
[0043] 1. Electronic control unit update system 2 vehicles 20 In-vehicle network 21 Electronic control device 22 Diagnostic Port 3 Gateway Device 30 First Control Section 31 1st private key 32 First Public Key Certificate 4 Secure Devices 40 Second Control Section 41 2nd private key 42 Second Public Key Certificate 5 Diagnostic equipment 50 Third Control Section 506 Reader / Writer 6. Key Management Center 60 Root Certificates
Claims
1. A gateway device connected to one or more electronic control units mounted on a vehicle, a diagnostic machine connected to the gateway device via a diagnostic port provided in the vehicle, and a secure device connected to the diagnostic machine, the gateway device stores a first encryption key issued to the gateway device by a key management center that distributes update files for electronic control devices, and includes a first control unit that, when the diagnostic machine connects to the gateway device, performs data communication with the secure device via the diagnostic machine, performs mutual authentication with the secure device using the first encryption key, and then exchanges a session key to establish a secure channel with the secure device; the secure device includes a second control unit that stores a second encryption key issued to the secure device by the key management center, performs data communication with the gateway device via the diagnostic machine, and performs mutual authentication with the gateway device using the second encryption key, and then exchanges a session key to establish a secure channel with the gateway device; the diagnostic machine includes a reader / writer that performs data communication with the secure device, and a third control unit that, when connected to the gateway device, relays data communication between the gateway device and the secure device, and, when a secure channel is established between the secure device and the gateway device, transmits an update file for the electronic control device to the gateway device using the secure channel; An electronic control unit update system.
2. 2. The electronic control unit update system according to claim 1, wherein the gateway device stores a root certificate of the key management center and a first private key and a first public key certificate as the first encryption key, the secure device stores the root certificate and a second private key and a second public key certificate as the second encryption key, and the first control unit of the gateway device and the second control unit of the secure device each perform mutual authentication and establish a secure channel using a PKI (Public Key Infrastructure) mechanism.
3. A secure device constituting the electronic control unit update system according to claim 1 or 2.
4. 3. A gateway device constituting the electronic control unit updating system according to claim 1.
5. A method executed by a gateway device connected to one or more electronic control units mounted on a vehicle, a diagnostic machine connected to the gateway device via a diagnostic port provided in the vehicle, and a secure device connected to the diagnostic machine, comprising: a step a) of connecting the diagnostic machine to the gateway device; a step b in which the diagnostic machine relays data communication between the gateway device and the secure device, and the gateway device and the secure device perform mutual authentication using a first encryption key issued to the gateway device by a key management center that distributes update files for electronic control devices and a second encryption key issued to the secure device by the key management center, and then exchange session keys to establish a secure channel between the gateway device and the secure device; a step c) in which the diagnostic machine transmits an update file for the electronic control unit to the gateway device using a secure channel between the gateway device and the secure device; 1. An electronic control unit updating method comprising:
6. the gateway device stores a root certificate of the key management center and a first private key and a first public key certificate as the first encryption key, and the secure device stores the root certificate and a second private key and a second public key certificate as the second encryption key; 6. The electronic control unit updating method according to claim 5, wherein in step b, the gateway device and the secure device perform mutual authentication and establish a secure channel using a PKI (Public Key Infrastructure) mechanism.
Citation Information
Patent Citations
Method for rewriting software of on-vehicle equipment, system of telematics system, and telematics device
JP2004326689A
Vehicle key distribution system and general-purpose scanning tool
JP2019161521A