Moving body, authentication system, data structure, information processing method, and program

The mobile object and authentication system enable secure transmission of vehicle data by attaching authentication information, addressing the challenge of direct data handling across different OEMs and user vehicles, ensuring efficient and centralized data management.

JP2025143046APending Publication Date: 2025-10-01PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024042735
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-18
Publication Date
2025-10-01

AI Technical Summary

Technical Problem

Existing systems lack a secure mechanism for transmitting vehicle data between servers, making it difficult for service providers to handle vehicle data directly and efficiently, especially in scenarios involving different OEMs and varying user vehicles.

Method used

A mobile object, authentication system, and information processing method that utilize authentication information and data structures to securely transmit vehicle data by attaching authentication information to the data, enabling secure communication between vehicles and service servers.

Benefits of technology

Facilitates secure and efficient transmission of vehicle data, allowing service providers to manage data centrally and prevent unauthorized access, while supporting various vehicle models and OEMs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025143046000001_ABST
    Figure 2025143046000001_ABST
Patent Text Reader

Abstract

To provide a moving body and the like with a secure mechanism capable of easily sending data of the moving body.SOLUTION: The moving body includes: a receiving unit 11 that receives first credentials which is transmitted by a first server, which is the first server for providing services subscribed to by users of the moving body, and which is capable of storing second credentials from the moving body; an acquisition unit 12 that acquires data of the moving body of the moving body; and a transmission unit 16 that transmits moving body data given with the third credentials used for authentication using the second credentials and the first credentials to the second server that collects the moving body data. The first server stores fourth credentials that are used for authentication using the first credentials.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a mobile object, an authentication system, a data structure, an information processing method, and a program. [Background technology]

[0002] Conventionally, it has been considered to transmit various vehicle data acquired in a vehicle in which a user is riding to a server that provides various services to the vehicle or the user, and to provide the services using the vehicle data acquired by the server. For example, Patent Document 1 discloses an in-vehicle terminal that can provide various services to an autonomously driving vehicle that is used in a car sharing service. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2019-175185 Summary of the Invention [Problem to be solved by the invention]

[0004] When vehicle data is transmitted from a server that manages the vehicle data to a server that provides a service, mutual authentication communication is first performed between the servers, and it is desirable that the vehicle data be transmitted simply while having a secure mechanism. However, Patent Document 1 does not disclose a method for transmitting vehicle data simply while having a secure mechanism.

[0005] Therefore, the present disclosure provides a mobile body, an authentication system, a data structure, an information processing method, and a program that have a secure mechanism and can easily transmit vehicle data. [Means for solving the problem]

[0006] A mobile body according to one embodiment of the present disclosure is a first server for providing a service to which a user of the mobile body has subscribed, and includes a receiving unit that receives first authentication information transmitted by the first server capable of storing second authentication information from the mobile body, an acquiring unit that acquires mobile body data of the mobile body, and a transmitting unit that transmits third authentication information used for authentication using the second authentication information and the mobile body data with the first authentication information attached to it to a second server that collects mobile body data, and the first server stores fourth authentication information used for authentication using the first authentication information.

[0007] An authentication system according to one embodiment of the present disclosure is an authentication system including the mobile body described above, the first server, and the second server, wherein the second server transfers the mobile body data, to which the first authentication information and the third authentication information have been attached, received from the mobile body to the first server, and the first server performs authentication based on the fourth authentication information and the second authentication information and the first authentication information and the third authentication information attached to the mobile body data.

[0008] An authentication system according to one embodiment of the present disclosure is an authentication system including the mobile body described above, the first server, and the second server, wherein the second server stores the mobile body data to which the first authentication information and the third authentication information received from the mobile body are attached, and upon receiving a request for the mobile body data from the first server, performs authentication based on the fourth authentication information and the second authentication information received from the first server and the first authentication information and the third authentication information attached to the mobile body data.

[0009] A data structure according to one embodiment of the present disclosure is a data structure of data transmitted from a mobile body to a second server in an authentication system including the mobile body, the first server, and the second server described above, and includes the mobile body data of the mobile body, the third authentication information of the mobile body, and the first authentication information stored in the mobile body.

[0010] An information processing method according to one embodiment of the present disclosure includes a first server for providing a service subscribed to by a user of a mobile body, the first server being capable of storing second authentication information from the mobile body, receiving first authentication information transmitted by the first server, acquiring mobile body data of the mobile body, transmitting third authentication information used for authentication using the second authentication information and the mobile body data with the first authentication information attached to it to a second server that collects mobile body data, and the first server storing fourth authentication information used for authentication using the first authentication information.

[0011] A program according to one aspect of the present disclosure is a program for causing a computer to execute the above-described information processing method. [Effects of the Invention]

[0012] According to one aspect of the present disclosure, it is possible to realize a mobile object or the like that has a secure mechanism and can easily transmit vehicle data. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a block diagram showing a functional configuration of an authentication system according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of authentication information added to vehicle data according to the embodiment. [Figure 3] FIG. 3 is a first sequence diagram illustrating the operation of the authentication system according to the embodiment. [Figure 4] FIG. 4 is a second sequence diagram showing the operation of the authentication system according to the embodiment. [Figure 5] FIG. 5 is a flowchart showing the details of the operation of step S31 shown in FIG. [Figure 6] FIG. 6 is a diagram for explaining the aggregation of vehicle data. [Figure 7] FIG. 7 is a diagram illustrating a first example of the data structure of vehicle data to which authentication information is added according to the embodiment. [Figure 8]FIG. 8 is a diagram illustrating another example of authentication information added to vehicle data according to the embodiment. [Figure 9] FIG. 9 is a diagram illustrating a second example of the data structure of vehicle data to which authentication information is added according to the embodiment. [Figure 10] FIG. 10 is a diagram illustrating a third example of the data structure of vehicle data to which authentication information is added according to the embodiment. [Figure 11] FIG. 11 is a sequence diagram showing the operation of the authentication system according to the modified example of the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0014] (Background to this disclosure) In a Software Defined Vehicle (SDV), collaboration between the cloud and the connected car is essential, and the cloud (vehicle cloud server) receives various vehicle data (vehicle logs) from the vehicle. The vehicle data collected by these vehicle cloud servers (vehicle servers or OEM (Original Equipment Manufacturer) servers) is also information linked to the users who use the vehicle, and applications to various service fields are being considered. "Using" may mean that the user drives the vehicle (e.g., a manually driven vehicle) or that the user rides in the vehicle (e.g., an autonomously driven vehicle).

[0015] Because OEM servers are generally operated by the OEM (or OEM affiliate) that manufactures and sells the vehicle, third parties such as service providers must use vehicle data via the OEM (OEM server). Vehicle data is first transmitted from the vehicle to the OEM server, and after consultation and technical preparations (e.g., connection to a closed communication network, secure data authentication, etc.) between each service provider and the OEM, it is transferred from the OEM server to the service provider's service server. This poses a challenge for service providers, making it difficult to handle vehicle data directly and easily. As the transition to SDV and MaaS is expected to require more open ways of using vehicle data, improvements are needed to enable direct and easy handling of vehicle data.

[0016] In addition, since users do not always use the same vehicle, for example, when using different vehicles (e.g., vehicles with different models or OEMs) in car sharing, data management becomes complicated because vehicle data is transferred from the OEM server of a different OEM. However, it is more efficient for the service provider to manage vehicle data centrally for the same user even if the vehicle changes.

[0017] It is also desirable to prevent such vehicle data from being provided to the service provider without the user's permission, and to provide it in a secure manner with the user's permission.

[0018] Therefore, the inventors of the present application have conducted extensive research into how to realize a mobile body or the like that has a secure mechanism and can easily transmit vehicle data, and have devised the mobile body or the like described below.

[0019] Hereinafter, the embodiments will be specifically described with reference to the drawings.

[0020] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not described in independent claims are described as optional components.

[0021] Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. Therefore, for example, the scales of the figures do not necessarily match. Furthermore, in each figure, substantially the same components are given the same reference numerals, and redundant explanations are omitted or simplified.

[0022] Furthermore, in this specification, numerical values ​​and numerical ranges are not expressions that express only the strict meaning, but are expressions that mean that they include a substantially equivalent range, for example, a difference of about several percent (or about 10%).

[0023] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.

[0024] (Embodiment) Hereinafter, a mobile object, an authentication system including a mobile object, and the like according to this embodiment will be described with reference to FIGS.

[0025] [1. Authentication system configuration] First, the configuration of a mobile object and an authentication system including a mobile object according to this embodiment will be described with reference to Fig. 1 and Fig. 2. Fig. 1 is a block diagram showing the functional configuration of an authentication system 1 according to this embodiment. The authentication system 1 according to this embodiment is a system for easily providing vehicle data collected by a vehicle server 20 to a service server 30 operated by a third-party business operator, which is different from the vehicle server 20. Note that hereinafter, an example of the authentication system 1 including a vehicle 10, which is an example of a mobile object, will be described.

[0026] 1, the authentication system 1 includes a vehicle 10, a vehicle server 20, a service server 30, and a user terminal 40. The vehicle 10, the vehicle server 20, and the user terminal 40 are communicatively connected to each other, the vehicle server 20 and the service server 30 are communicatively connected to each other, and the service server 30 and the user terminal 40 are communicatively connected to each other.

[0027] Vehicle 10 is a vehicle used by a user. Vehicle 10 may be a manually driven vehicle driven by a user, a fully automated vehicle not driven by a user, or a vehicle capable of switching between manual and automated driving. Vehicle 10 may also be a vehicle owned by a user, a rental car, or a vehicle used for car sharing.

[0028] The vehicle 10 includes a receiving unit 11, an acquiring unit 12, a storage unit 13, a first generating unit 14, a second generating unit 15, and a transmitting unit 16. The vehicle 10 includes a processor, a memory, and the like. The memory is a read-only memory (ROM) and a random access memory (RAM), and can store a program executed by the processor. The first generating unit 14 and the second generating unit 15 are realized by a processor that executes a program stored in the memory.

[0029] The receiving unit 11 is a communication interface for receiving information used for authentication performed by the service server 30 in this embodiment. The receiving unit 11 receives first authentication information from the service server 30 for providing a service to which the user of the vehicle 10 has subscribed. The first authentication information includes user identification information (e.g., a user ID) and a public key (server public key) of the service server 30. The receiving unit 11 is configured to include, for example, a communication circuit (communication module). The server public key is an example of the first public key.

[0030] The acquisition unit 12 is an interface for acquiring user-related vehicle data. The acquisition unit 12 acquires vehicle control data (control data for driving, turning, stopping, etc.) obtained by the user's driving, the user's biometric information, camera images of the user, route information (destination, driving route), and the like as vehicle data. The acquisition unit 12 acquires vehicle data from, for example, various sensors mounted on the vehicle. The vehicle data is an example of mobile body data.

[0031] The memory unit 13 is a storage device capable of storing various information used for authentication performed by the service server 30 in this embodiment. The memory unit 13 stores, for example, information transmitted by the service server 30. Specifically, the memory unit 13 stores first authentication information received by the receiver 11. The memory unit 13 also stores, for example, information generated by the first generator 14. Specifically, the memory unit 13 stores a public key (vehicle public key) and a vehicle signature generated by the first generator 14. The memory unit 13 also stores a vehicle ID indicating identification information of the vehicle 10. The vehicle public key is an example of a second public key, the vehicle ID and vehicle public key are examples of second authentication information, and the vehicle ID and vehicle signature are examples of third authentication information.

[0032] The storage unit 13 also stores a private key (vehicle private key). The vehicle private key may be generated corresponding to a vehicle ID, for example. The vehicle private key is generated, for example, when the vehicle 10 is manufactured, and stored in the storage unit 13. The vehicle private key is stored in the storage unit 13, for example, when the vehicle 10 is shipped from the factory. The storage unit 13 is realized, for example, by a semiconductor memory, but is not limited to this. The vehicle private key is an example of a second private key.

[0033] In this embodiment, the first generation unit 14 generates information used for authentication performed by the service server 30. The first generation unit 14 generates a vehicle public key paired with the vehicle private key. The first generation unit 14 also generates a signature (vehicle signature) of the vehicle 10 using a pre-stored vehicle private key. The first generation unit 14 may generate the vehicle signature by encrypting, using the vehicle private key, at least one of the vehicle ID, the user ID, the service server domain, and the vehicle data, or information based on the at least one of the vehicle ID, the user ID, the service server domain, and the vehicle data (for example, the at least one hash value). The first generation unit 14 may generate the vehicle signature by encrypting, using the vehicle private key, at least two or all of the vehicle ID, the user ID, the service server domain, and the vehicle data, or information based on the at least two or all of the vehicle ID, the user ID, the service server domain, and the vehicle data (for example, the at least two or all hash values). The first generation unit 14 may also generate the vehicle signature by using at least information pre-stored in the vehicle 10, such as the vehicle ID, or information generated by the vehicle 10, such as the vehicle data. If security (integrity) is important, the amount of information used in the vehicle signature may be increased, and if availability is important, the amount of information used in the vehicle signature may be reduced compared to when security (integrity) is important.

[0034] The first generating unit 14 is an example of a generating unit, and the vehicle signature is an example of a second signature.

[0035] The second generation unit 15 generates vehicle data to which the first authentication information from the service server 30 and the third authentication information of the vehicle 10 are added.

[0036] FIG. 2 is a diagram showing an example of authentication information assigned to vehicle data according to this embodiment. FIG. 2 shows the correspondence between vehicle data and authentication information linked to the vehicle data. The authentication information includes a vehicle ID, a user ID, a vehicle signature, and a server public key. The authentication information may further include a service server domain.

[0037] The vehicle data type indicates the type of vehicle data, including, for example, drive recorder video, brake CAN (Control Area Network) control, accelerator CAN control, door lock CAN control, and GPS (Global Positioning System) information.

[0038] Brake CAN control, accelerator CAN control, and door lock CAN control include log information about the contents and reception timing of frames (messages) sent to the ECU (Electronic Control Unit) that controls the brake, the ECU that controls the accelerator, and the ECU that controls the door lock, which are transmitted over the CAN bus that makes up the in-vehicle network.

[0039] The vehicle ID indicates identification information of the vehicle used by the user. Different vehicle IDs mean that the vehicles 10 used by the users are different.

[0040] The user ID indicates identification information of a user who has made a contract with the service server 30. When one user has contracts with different service servers 30, a different user ID is issued for each service server 30. For example, the user IDs "0x4444" and "0x5555" shown in FIG. 2 are IDs of the same user, but are user IDs issued by different service servers 30.

[0041] The vehicle signature indicates a signature generated using a vehicle private key generated by the first generation unit 14 of the vehicle 10. A different vehicle signature means either that the service server 30 with which the user has a contract is different, or that the vehicle 10 is different.

[0042] The server public key indicates a public key generated by the service server 30. Different server public keys mean that the user has a contract with a different service server 30.

[0043] The service server domain indicates the destination address of the service server 30 that uses the vehicle data. Different service server domains mean that the user has a contract with a different service server 30.

[0044] 2, for example, when dashcam footage, which is an example of vehicle data, is transmitted to the vehicle server 20, the second generation unit 15 assigns the vehicle ID "0x777777," the user ID "0x4444," the vehicle signature "0xWWWWWW," the server public key "0xAAAAAA," and the service server domain "GooAA.co.jp" as authentication information to the dashcam footage and transmits it to the vehicle server 20. The user has a contract with the service server 30 (service provider) that has issued the server public key "0xAAAAAA," and the dashcam footage is used by the service server 30.

[0045] 2, for example, when transmitting brake CAN control, which is an example of vehicle data, to the vehicle server 20, the second generation unit 15 assigns the vehicle ID "0x777777," the user ID "0x5555," the vehicle signature "0xXXXXXX," the server public key "0xBBBBBB," and the service server domain "Akusan.co.jp" as authentication information to the brake CAN control and transmits it to the vehicle server 20. The user has a contract with the service server 30 (service provider) that issued the server public key "0xBBBBBB," and the brake CAN control is used by that service server 30. In other words, the dashcam video and the brake CAN control are used by different service servers 30.

[0046] 2 indicates that no information is added to the vehicle data. When transmitting the door lock CAN control to the vehicle server 20, the second generation unit 15 transmits the door lock CAN control to the vehicle server 20 without adding any authentication information. In this case, the vehicle server 20 does not transfer the door lock CAN control to the service server 30.

[0047] 1 again, the transmission unit 16 is a communication interface for transmitting vehicle data to the vehicle server 20. The transmission unit 16 transmits the vehicle data to which the first authentication information and the third authentication information have been assigned to the vehicle server 20. The transmission unit 16 may further assign information indicating the destination of the service server 30 (for example, a service server domain) to the vehicle data before transmitting it.

[0048] The vehicle server 20 is a server that collects vehicle data. The vehicle server 20 may be realized by a cloud server. The vehicle server 20 is also a server operated by the OEM (or an OEM affiliated company) that manufactures and sells the vehicle 10. The vehicle server 20 is an example of a second server.

[0049] The vehicle server 20 includes a communication unit 21, a control unit 22, and a storage unit 23. The vehicle server 20 includes a processor, a memory, etc. The memory is a ROM, a RAM, etc., and can store programs executed by the processor. The control unit 22 is realized by the processor, etc., that executes the programs stored in the memory.

[0050] The communication unit 21 is a communication interface for the vehicle server 20 to communicate with the vehicle 10 and the service server 30. The communication unit 21 receives vehicle data with authentication information attached from the vehicle 10. The communication unit 21 also transfers the vehicle data with authentication information attached received from the vehicle 10 to the service server 30. The communication unit 21 is configured to include, for example, a communication circuit (communication module).

[0051] The control unit 22 is a control device that controls each component of the vehicle server 20. The control unit 22 executes a process for transferring the vehicle data with the authentication information attached, received from the vehicle 10 via the communication unit 21, to the service server 30 via the communication unit 21. When the authentication information includes a service server domain, the control unit 22 transfers the vehicle data with the authentication information attached to the destination address indicated by the service server domain.

[0052] The storage unit 23 stores vehicle data and the like to which the authentication information received from the vehicle 10 has been added. The storage unit 23 is realized by, for example, a semiconductor memory, but is not limited to this.

[0053] The service server 30 is a server for providing a third-party service (a service that utilizes vehicle data) that the user has subscribed to. The service is not particularly limited, and may be, for example, a service that determines the insurance premium for the car insurance contracted by the user based on the vehicle data. The service server 30 may be realized by a cloud server. The service server 30 is also a server operated by a service provider that provides the service that the user has subscribed to. The service server 30 is an example of a first server.

[0054] The service server 30 includes a communication unit 31, a generation unit 32, an authentication unit 33, and a storage unit 34. The service server 30 includes a processor, a memory, etc. The memory is a ROM, a RAM, etc., and can store a program executed by the processor. The generation unit 32 and the authentication unit 33 are realized by a processor, etc. that executes a program stored in the memory.

[0055] The communication unit 31 is a communication interface for the service server 30 to communicate with the vehicle server 20 and the user terminal 40. The communication unit 31 receives vehicle data to which authentication information has been assigned from the vehicle server 20. The communication unit 31 also receives information related to the user contract and second authentication information from the user terminal 40. The communication unit 31 also transmits to the user terminal 40 first authentication information including a user ID and a server public key generated by the generation unit 32 after the contract has been made. The communication unit 31 is configured to include, for example, a communication circuit (communication module).

[0056] The generation unit 32 generates information used for authentication performed by the service server 30 in this embodiment. The generation unit 32 generates a user ID of a contracted user and a server public key that forms a pair with a private key (server private key) pre-stored in the storage unit 34. The generation unit 32 also generates a signature (server signature) of the service server 30 using the server private key. The generation unit 32 generates the server signature, for example, by encrypting the user ID or a hash value of the user ID with the server private key. The server private key is an example of a first private key, and the server signature is an example of a first signature.

[0057] The authentication unit 33 performs an authentication operation when the communication unit 31 receives vehicle data with authentication information attached thereto from the vehicle server 20. The authentication unit 33 performs service server authentication and user authentication based on the authentication information attached to the vehicle data and the user ID, server signature, vehicle ID, and vehicle public key stored in the storage unit 34.

[0058] Service server authentication is authentication of whether the vehicle data is linked to a user who has a contract with the service provider that operates the service server 30. User authentication is authentication of whether the vehicle data is data from a vehicle 10 that the user has authorized to use.

[0059] The memory unit 34 is a storage device capable of storing various information used for authentication performed by the service server 30 in this embodiment. The memory unit 34 stores, for example, information generated by the generation unit 32. Specifically, the memory unit 34 stores a user ID, a server public key, and a server signature. The memory unit 34 also stores, for example, information transmitted from the vehicle 10 and received via the user terminal 40. Specifically, the memory unit 34 stores a vehicle ID and a vehicle public key received via the communication unit 31. The user ID and the server public key are examples of first authentication information, and the user ID and the server signature are examples of fourth authentication information.

[0060] The storage unit 34 also stores a server private key. The server private key is, for example, generated in advance and stored in the storage unit 34. The server private key is stored in the storage unit 34, for example, before the processing of step S11 shown in Fig. 3, which will be described later, is executed. The storage unit 34 is realized by, for example, a semiconductor memory, but is not limited to this.

[0061] The user terminal 40 is a terminal device carried by a user who uses the vehicle 10. The user terminal 40 may be, for example, a portable terminal device such as a smartphone or a tablet, or a stationary terminal device such as a personal computer (PC).

[0062] The user terminal 40 includes a communication unit 41, a reception unit 42, an application execution unit 43, and a display unit 44. The user terminal 40 includes a processor, a memory, etc. The memory is a ROM, a RAM, etc., and can store a program to be executed by the processor. The application execution unit 43 is realized by the processor, etc., that executes the program stored in the memory.

[0063] The communication unit 41 is a communication interface for the user terminal 40 to communicate with the vehicle 10 and the service server 30. The communication unit 41 transmits information related to the contract acquired by user input to the service server 30, receives first authentication information from the service server 30, and transmits the received first authentication information to the vehicle 10. The communication unit 41 also receives second authentication information from the vehicle 10 and transmits it to the service server 30. The communication unit 41 is configured to include, for example, a communication circuit (communication module).

[0064] The reception unit 42 receives operations, selections, etc. from the user. The reception unit 42 receives inputs from the user regarding the contract, inputs indicating whether or not the service can be used, etc. The reception unit 42 is realized by, for example, a button, a touch panel, a sound collection device, etc., but is not limited to these.

[0065] The application execution unit 43 is a processing unit that executes a downloaded application (hereinafter also referred to as an application). The application may be a dedicated application for receiving a service from the service server 30.

[0066] The display unit 44 displays predetermined information to the user. For example, the display unit 44 displays an input screen for contracts, an input screen for indicating whether or not the service is available, etc. The display unit 44 includes a display panel such as a liquid crystal display panel.

[0067] [2. Operation of the authentication system] Next, the operation of the authentication system 1 configured as above will be described with reference to Figs. 3 to 10. Fig. 3 is a first sequence diagram showing the operation (information processing method) of the authentication system 1 according to this embodiment. The process shown in Fig. 3 is executed before the user uses the vehicle 10 or before the vehicle 10 starts traveling. Furthermore, the operation of the user terminal 40 may be executed via an app.

[0068] 3, first, the communication unit 41 of the user terminal 40 transmits a service contract for receiving a service to the service server 30 (S11). The content of the service contract includes, for example, content based on information received from the user by the reception unit 42.

[0069] Next, when the communication unit 31 receives the service contract, the generation unit 32 of the service server 30 issues a user ID and generates a server signature and a server public key (S12). The generation unit 32 executes user registration and issues the user ID. The generation unit 32 also generates a server signature using the server private key and generates a server public key. The server public key is a public key that is generated individually for each user. Any known method may be used to generate the public key.

[0070] Next, the communication unit 31 of the service server 30 transmits the user ID and the server public key to the user terminal 40 (S13). Upon receiving the user ID and the server public key from the service server 30 via the communication unit 41, the user terminal 40 stores them in, for example, a storage unit (not shown). At this point, the user terminal 40 and the vehicle 10 may be unable to communicate with each other.

[0071] Next, when the vehicle is used (for example, after the ignition is turned on and the user terminal 40 and the vehicle 10 are able to communicate), the communication unit 41 of the user terminal 40 transmits a service content notification corresponding to the service server 30 to the vehicle 10 (S14).

[0072] Next, the vehicle 10 determines whether the service is available (S15). The vehicle 10 makes a decision at step S15 by having the user decide whether the vehicle data acquired by the vehicle 10 may be used to provide the service (i.e., whether the vehicle data may be transferred to the service server 30), and acquires the decision result. When the vehicle 10 acquires an input from the user indicating that the vehicle data of the vehicle 10 will not be used to provide the service, the vehicle 10 determines that the service is unavailable (No in S15) and terminates the processing (S16). When the vehicle 10 acquires an input from the user indicating that the vehicle data of the vehicle 10 will be used to provide the service, the vehicle 10 determines that the service is available (Yes in S15) and proceeds to step S17. "Available for the service" means that the vehicle server 20 permits the vehicle data to be transferred to the service server 30.

[0073] The service here refers to a service (for example, the determination of insurance premiums as exemplified above) that uses each vehicle data related to the user in the vehicle 10. The input indicating whether or not to use the service may be, for example, a user input (for example, a touch operation) to a navigation system or the like installed in the vehicle 10.

[0074] Next, if the service is available, the transmitter 16 of the vehicle 10 transmits a service use notification indicating that the service will be used to the user terminal 40 (S17).

[0075] Next, upon receiving the service usage notification, the communication unit 41 of the user terminal 40 transmits the user ID and the server public key acquired from the service server 30 to the vehicle 10 (S18).

[0076] Next, the receiving unit 11 of the vehicle 10 receives the user ID and the server public key, and stores the received user ID and server public key in the storage unit 13 (S19). As a result, the vehicle 10 stores information for performing service server authentication.

[0077] Next, upon acquiring the user ID and the server public key, the first generation unit 14 of the vehicle 10 generates a vehicle signature and a vehicle public key (S20). The vehicle signature and the vehicle public key are generated by the first generation unit 14 in correspondence with the user ID generated by the service server 30. In other words, the vehicle public key and the vehicle signature are generated in correspondence with the user ID. Furthermore, the vehicle signature and the vehicle public key are, for example, information unique to the service server 30, and if there are multiple service servers 30, different vehicle signatures and vehicle public keys are generated for each service server 30. The vehicle public key is used by the service server 30 to verify whether the vehicle signature is authentic.

[0078] Next, the transmission unit 16 transmits the vehicle ID stored in the storage unit 13 and the vehicle public key generated by the first generation unit 14 to the user terminal 40 (S21).

[0079] Next, upon receiving the vehicle ID and the vehicle public key from the transmission unit 16, the communication unit 41 of the user terminal 40 transmits them to the service server 30 (S22).

[0080] Next, the communication unit 31 of the service server 30 receives the vehicle ID and the vehicle public key, and stores the received vehicle ID and vehicle public key in the storage unit 34 (S23). As a result, the service server 30 stores information for user authentication. If the user permits the use of the vehicle data of the vehicle 10, the service server 30 will have the vehicle ID and the vehicle public key.

[0081] In this way, in order to easily provide vehicle data to the service server 30, the user ID and server public key, and the vehicle ID and vehicle public key are exchanged in advance between the vehicle 10 and the service server 30. In other words, a state is created in advance in which the vehicle 10 stores the user ID and server public key, and the service server 30 stores the vehicle ID and vehicle public key. "In advance" means before the user uses the vehicle 10.

[0082] Next, the operation of transferring vehicle data and performing authentication will be described with reference to Figures 4 to 10. Figure 4 is a second sequence diagram showing the operation (information processing method) of authentication system 1 according to the present embodiment.

[0083] As shown in FIG. 4, the second generation unit 15 of the vehicle 10 generates vehicle data to which authentication information (user ID, vehicle signature, server public key, vehicle ID) is added (S31).

[0084] FIG. 5 is a flowchart showing details of the operation (information processing method) of step S31 shown in FIG.

[0085] 5, the second generation unit 15 generates vehicle data to be used for a service determined by the user as available for use by acquiring the vehicle data from various sensors, etc. (S31a). The vehicle data may include, for example, time-series data measured by the various sensors.

[0086] The timing of generating the vehicle data is not particularly limited. For example, the vehicle data may be generated periodically, intermittently, or on an as-needed basis. "Intermittently" means that the vehicle data is generated periodically, and the interval at which the vehicle data is generated is shorter than a predetermined interval. "On-needle generation" means that the vehicle data is generated each time an irregular event occurs.

[0087] Next, the second generation unit 15 aggregates the vehicle data (S31b) and assigns service authentication information (authentication information) to the vehicle data (data) (S31c). The aggregation may be consolidating all of the multiple data into one (to make one vehicle data), or may be thinning out some of the multiple data and consolidating them into one.

[0088] FIG. 6 is a diagram for explaining the aggregation of vehicle data.

[0089] 6(a), when one ECU 17 has multiple functions (functions X, Y, and Z), vehicle data is generated and aggregated within the ECU 17. The ECU 17 assigns authentication information to the aggregated vehicle data.

[0090] Note that functions X, Y, and Z are different from one another. For example, function X may be a function for transmitting frames (messages) via a CAN bus, function Y may be a function for capturing video data, and function Z may be a function for storing the occurrence of a predetermined vehicle event.

[0091] As shown in (b) of FIG. 6, when functions are distributed among a plurality of ECUs (e.g., the first ECU 18a, the second ECU 18b, and the third ECU 18c), vehicle data may be generated and aggregated in each ECU. Furthermore, vehicle data collected by each ECU may be aggregated in one ECU. For example, the first ECU 18a, the second ECU 18b, and the third ECU 18c may each aggregate the aggregated vehicle data, and the aggregated vehicle data may be aggregated in the third ECU 18c. In this case, the vehicle data of the first ECU 18a and the second ECU 18b is transmitted collectively by the third ECU 18c to the vehicle server 20. Note that the first ECU 18a, the second ECU 18b, and the third ECU 18c may each assign authentication information to their own vehicle data, and the vehicle data with the assigned authentication information may be aggregated in the third ECU 18c. Alternatively, vehicle data without the assigned authentication information may be aggregated in the third ECU 18c, and the third ECU 18c may assign authentication information to each vehicle data.

[0092] FIG. 7 is a diagram showing a first example of the data structure of vehicle data to which authentication information is added according to the present embodiment.

[0093] 7, the vehicle data generated in step S31c includes authentication information and vehicle data. In the example of FIG. 7, the authentication information includes a user ID, a vehicle signature, a server public key, and a vehicle ID. The vehicle data may further include a service server domain.

[0094] Here, other examples of the authentication information to be assigned will be further described with reference to Figs. 8 to 10. Fig. 8 is a diagram showing another example of authentication information to be assigned to vehicle data. Figs. 9 and 10 are diagrams showing examples of the data structure of vehicle data to which authentication information according to this embodiment is assigned. The authentication information shown in Figs. 9 and 10 is written in the order of user ID, vehicle signature, server public key, and vehicle ID from top to bottom (the same order as in Fig. 7).

[0095] FIG. 8 shows an example in which two types of authentication information are associated with each vehicle data type.

[0096] The vehicle data types include vehicle data A obtained by function X (see (b) of Figure 6), vehicle data B obtained by function Y (see (b) of Figure 6), and vehicle data C obtained by function Z (see (b) of Figure 6).

[0097] As indicated in the notes, A1 and A2 of vehicle data A are examples of authentication information that is assigned when the service and vehicle 10 are the same but the users are different. In this case, the vehicle 10 is the same, so the vehicle ID and vehicle signature are common, and the service is the same (the service server 30 is the same), so the service server domain is also common. Different information is set for each user in the user ID and server public key, so the information is different for different users.

[0098] 9(a) shows the data structure of authentication information for A2 of vehicle data A. As shown in FIG. 9(a), vehicle data A is assigned the following authentication information: user ID "0x5555", vehicle signature "0xRRRRRR", server public key "0xDDDDDD", and vehicle ID "0x777777".

[0099] Referring again to FIG. 8, B1 and B2 of vehicle data B, as indicated in the notes, are examples of authentication information that is assigned when the same vehicle is used by the same person but different services are used. In this case, the vehicle 10 is the same, so the vehicle ID and vehicle signature are the same. The user ID and server public key will be different information even for the same user if the service (service server 30 that issues the user ID) is different. Furthermore, since the service (service server 30) is different, the service server domain is also different.

[0100] 9(b) shows the data structure of authentication information for B1 and B2 of vehicle data B. As shown in FIG. 9(b), vehicle data B (B1) sent to the service server domain "SbbpBB.co.jp" is assigned the following authentication information: user ID "0x5151", vehicle signature "0xSSSSSS", server public key "0xCCCCCC", and vehicle ID "0x777777". Also, as shown in FIG. 9(b), vehicle data B (B2) sent to the service server domain "PaaoAA.co.jp" is assigned the following authentication information: user ID "0x5252", vehicle signature "0xTTTTTT", server public key "0xEEEEEE", and vehicle ID "0x777777".

[0101] Referring again to Figure 8, C1 and C2 of vehicle data C indicate examples of authentication information that are assigned when the same service is used by a person but different vehicles, as indicated in the notes. In this case, the user and service (service server 30) are the same, so the user ID, server public key, and service server domain are the same. The vehicle ID and vehicle signature are set to different information for each vehicle 10, so they are different information for different vehicles.

[0102] Fig. 9(c) shows the data structure of authentication information for C1 of vehicle data C. As shown in Fig. 9(c), vehicle data C (C1) sent from vehicle ID "0x777777" is assigned the user ID "0x5050", vehicle signature "0xUUUUUU", server public key "0xBBBBBB", and vehicle ID "0x777777" as authentication information.

[0103] Fig. 10 shows the data structure of authentication information for C2 of vehicle data C. As shown in Fig. 10, the vehicle data C (C2) sent from vehicle ID "0x999999" is assigned the user ID "0x5050", vehicle signature "0xVVVVVV", server public key "0xBBBBBB", and vehicle ID "0x999999" as authentication information.

[0104] Referring again to Figure 4, the transmitter 16 of the vehicle 10 transmits the vehicle data with the authentication information attached to it to the vehicle server 20 (S32). The authentication information includes a user ID, a vehicle signature, a server public key, and a vehicle ID. Since the user ID is attached to the vehicle data in this way, the vehicle data is transmitted to the vehicle server 20 as information linked to the user. Note that if the service is not available, only the vehicle data is transmitted without the authentication information being attached.

[0105] When the communication unit 21 of the vehicle server 20 receives the vehicle data with the authentication information attached thereto transmitted from the transmission unit 16, the communication unit 21 transfers the vehicle data with the received authentication information attached thereto to the service server 30 (S33). The communication unit 21 transfers the vehicle data with the authentication information attached thereto to the service server 30 without performing an authentication operation between the vehicle server 20 and the service server 30. As a result, the vehicle data with the authentication information attached thereto is transmitted from the vehicle server 20 to the service server 30 (S34).

[0106] The control unit 22 of the vehicle server 20 may store the received vehicle data in the storage unit 23. After the vehicle data with the authentication information attached is transmitted to the vehicle server 20, all of the authentication information of the vehicle data stored in the storage unit 23 may be deleted except for the vehicle ID.

[0107] Next, the authentication unit 33 of the service server 30 performs service server authentication and user authentication based on the authentication information attached to the received vehicle data and the user ID, server signature, vehicle ID, and vehicle public key acquired in advance and stored in the storage unit 34 (S35). The authentication unit 33 performs user authentication based on the user ID and server public key included in the authentication information and the user ID and server signature stored in the storage unit 34 of the service server 30. The authentication unit 33 also performs service server authentication based on the vehicle ID and vehicle signature included in the authentication information and the vehicle ID and vehicle public key stored in the storage unit 34 of the service server 30.

[0108] The authentication unit 33 verifies whether the server signature stored in the storage unit 34 can be decrypted using the server public key assigned to the vehicle data. If the authentication unit 33 can decrypt the server signature with the server public key, it determines that the server public key is legitimate (for example, the vehicle data is linked to the user), and if the authentication unit 33 cannot decrypt the server signature with the server public key, it determines that the server public key is illegitimate (for example, the vehicle data is not linked to the user). In this way, the server signature can verify whether the server public key is legitimate.

[0109] The authentication unit 33 may also verify whether the user ID assigned to the vehicle data matches the user ID stored in the storage unit 34.

[0110] The authentication unit 33 verifies whether the vehicle signature attached to the vehicle data can be decrypted using the vehicle public key stored in the storage unit 34. If the vehicle signature can be decrypted using the vehicle public key, the authentication unit 33 determines that the vehicle signature is legitimate (for example, vehicle data from the vehicle 10 whose use is permitted by the user), and if the vehicle signature cannot be decrypted using the vehicle public key, the authentication unit 33 determines that the vehicle signature is illegitimate (for example, vehicle data not from the vehicle 10 whose use is permitted by the user). In this way, the vehicle public key can verify whether the vehicle signature is legitimate.

[0111] The authentication unit 33 may also verify whether the vehicle ID assigned to the vehicle data matches the vehicle ID stored in the storage unit 34.

[0112] If the user authentication and service server authentication are successful, the service server 30 uses the received vehicle data to provide a predetermined service to the user.

[0113] As described above, since the user ID, vehicle ID, vehicle signature, and server public key are included in the vehicle data, even if the user changes the vehicle 10, the vehicle data with the authentication information attached can be transmitted to the service server 30. This allows the service server 30 to centrally manage the vehicle data of the same user even if the vehicle 10 is different.

[0114] (Modification of the embodiment) The authentication system according to this modification will be described below with reference to FIG. 11. The following description will focus on the differences from the embodiment, and descriptions of the same or similar parts as those in the embodiment will be omitted or simplified. The authentication system according to this modification differs from the authentication system 1 according to the embodiment in that the vehicle server 20 is provided with an authentication unit 33. The following description will use the reference numerals of the authentication system 1 according to the embodiment.

[0115] FIG. 11 is a sequence diagram showing the operation (information processing method) of the authentication system according to this modification.

[0116] 11, when the vehicle server 20 receives the vehicle data with the authentication information attached from the vehicle 10, the vehicle server 20 stores the vehicle data with the authentication information attached (S41). The control unit 22 stores the vehicle data with the authentication information attached received via the communication unit 21 in the storage unit 23.

[0117] Next, the communication unit 31 of the service server 30 requests vehicle data from the vehicle server 20 (S42). The communication unit 31 may attach the user ID, server signature, vehicle ID, and vehicle public key stored in the storage unit 34 to the vehicle data and transmit the data to the vehicle server 20. The request for vehicle data may be executed periodically or at a timing determined depending on the type of service.

[0118] Next, an authentication unit (not shown) of the vehicle server 20 has the same function as the authentication unit 33 according to the embodiment, and upon receiving the request for vehicle data, performs service server authentication and user authentication (S43). The process of step S43 is the same as step S35 shown in FIG.

[0119] Next, if the service server authentication and user authentication by the authentication unit are successful, the communication unit 21 of the vehicle server 20 transmits the vehicle data to the service server 30 (S44). The vehicle data transmitted here does not need to include authentication information. In other words, the vehicle server 20 may remove the authentication information and transmit only the vehicle data to the service server 30.

[0120] Even when the vehicle server 20 performs such authentication operations, it is possible to realize a vehicle 10 or the like that has a secure mechanism and can easily transmit vehicle data to the service server 30.

[0121] (Other embodiments) While the mobile object etc. according to one or more aspects has been described above based on the embodiments etc., the present disclosure is not limited to these embodiments etc. As long as it does not deviate from the spirit of the present disclosure, various modifications conceivable by a person skilled in the art to the present embodiment and embodiments constructed by combining components of different embodiments may also be included in the present disclosure.

[0122] For example, in the above-described embodiment, when a vehicle transmits vehicle data to a vehicle server, the vehicle adds information indicating the destination of the service server. However, the present invention is not limited to this. For example, when there is only one service server to which the vehicle data is to be transmitted, such as when a user subscribes to only one service, the vehicle does not need to add information indicating the destination of the service server to the vehicle data. In this case, for example, the vehicle server may store information indicating the destination of the service server.

[0123] In addition, in the above-described embodiment, a vehicle is used as an example of a moving body, but the moving body is not limited to a vehicle. The moving body may be a train, a ship, an air vehicle such as a drone, or the like.

[0124] 3 in the above-described embodiment, the vehicle ID and vehicle public key, and the user ID and server public key are exchanged between the vehicle 10 and the service server 30. However, the information exchanged may be either the vehicle ID and vehicle public key or the user ID and server public key. In this case, only one of the service server authentication and user authentication shown in FIG. 4 is performed.

[0125] In addition, in the above embodiments, a user ID and a server public key are exemplified as the first authentication information, but other information may be used as long as it is information that can be used to generate a vehicle signature in the vehicle. Furthermore, a vehicle ID and a vehicle public key are exemplified as the second authentication information, but other information that can be used for authentication may be used. Furthermore, a vehicle ID and a vehicle signature are exemplified as the third authentication information, but other information that can be used for authentication using the second authentication information may be used. Furthermore, a user ID and a server signature are exemplified as the fourth authentication information, but other information that can be used for authentication using the first authentication information may be used.

[0126] In the above embodiments, each component may be configured with dedicated hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0127] The order in which the steps in the flowchart are executed is merely an example for specifically explaining the present disclosure, and an order other than the above may be used. Also, some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed.

[0128] The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block.Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.

[0129] Furthermore, at least one of the vehicle server and the service server according to the above-described embodiments may be realized as a single device or may be realized by multiple devices. When at least one of the vehicle server and the service server is realized by multiple devices, the components of at least one of the vehicle server and the service server may be distributed in any manner among the multiple devices. When at least one of the vehicle server and the service server is realized by multiple devices, the communication method between the multiple devices is not particularly limited and may be wireless communication or wired communication. Furthermore, wireless communication and wired communication may be combined between the devices.

[0130] Furthermore, each component described in the above embodiments may be implemented as software or, typically, as an LSI, an integrated circuit. These components may be integrated individually on a single chip, or some or all of them may be integrated on a single chip. While LSI is used here, it may also be referred to as an IC, system LSI, super LSI, or ultra LSI depending on the level of integration. Furthermore, the integration method is not limited to LSI; it may be implemented using a dedicated circuit (a general-purpose circuit that executes a dedicated program) or a general-purpose processor. It is also possible to use a field programmable gate array (FPGA), which can be programmed after LSI fabrication, or a reconfigurable processor, which allows the connection or settings of circuit cells within an LSI to be reconfigured. Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or a derivative technology, that technology may naturally be used to integrate the components.

[0131] A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple processing units on a single chip, and is specifically a computer system consisting of a microprocessor, ROM, RAM, etc. The ROM stores computer programs. The system LSI achieves its functions when the microprocessor operates in accordance with the computer programs.

[0132] Another aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the information processing method shown in any one of FIGS.

[0133] Furthermore, for example, the program may be a program to be executed by a computer. Another aspect of the present disclosure may be a computer-readable non-transitory recording medium on which such a program is recorded. For example, such a program may be recorded on a recording medium and distributed or circulated. For example, the distributed program may be installed in a device having another processor, and the program may be executed by the processor, thereby causing the device to perform each of the above processes.

[0134] (Addendum) The above description of the embodiments and the like discloses the following techniques.

[0135] (Technology 1) A first server for providing a service subscribed to by a user of a mobile body, the first server being capable of storing second authentication information from the mobile body, includes a receiving unit that receives first authentication information transmitted by the first server, an acquiring unit that acquires mobile body data of the mobile body, and a transmitting unit that transmits third authentication information used for authentication using the second authentication information and the mobile body data to which the first authentication information has been added, to a second server that collects mobile body data, the first server being a mobile body (e.g., vehicle 10) that stores fourth authentication information used for authentication using the first authentication information.

[0136] As a result, since the first authentication information and the third authentication information are assigned to the mobile body data, when the mobile body data is transferred from the second server to the first server, the first server can perform authentication using the first to third authentication information. Since authentication is performed using the first to fourth authentication information, a secure mechanism exists in the authentication system. Furthermore, the second server only needs to transfer the mobile body data assigned with the first authentication information and the third authentication information to the first server without communicating with the first server for authentication. Therefore, a mobile body that has a secure mechanism and can easily transmit mobile body data from the second server to the first server can be realized.

[0137] (Technology 2) The second authentication information is a mobile body of technology 1, and includes identification information of the mobile body and a second public key of the mobile body that is paired with a second private key used to generate a second signature included in the third authentication information.

[0138] This allows authentication (for example, authentication as to whether the data is from a mobile device authorized for use by the user) based on whether the second signature included in the third authentication information can be decrypted using the second public key, which leads to a secure mechanism.

[0139] (Technology 3) The mobile entity of technique 2 further comprises a generation unit that generates the second signature using the second public key and the second private key of the mobile entity.

[0140] This allows the generation unit of the mobile entity to automatically generate information required for authentication, which leads to easy transmission of mobile entity data.

[0141] (Technology 4) The generating unit is a mobile entity of technique 3, which generates the second public key and the second signature when the mobile entity acquires the first authentication information.

[0142] This makes it possible to generate a second public key and a second signature according to the first authentication information.

[0143] (Technology 5) The mobile body according to any one of techniques 1 to 4, wherein the transmitting unit further adds information indicating a destination of the first server to the mobile body data and transmits the mobile body data to the second server.

[0144] This allows the second server to transmit the mobile data to the first server even if the second server does not store the destination of the first server.

[0145] (Technology 6) The mobile body is one of techniques 1 to 5, wherein the fourth authentication information includes a first signature generated using a first private key of the first server, and the first authentication information includes identification information of the user and a first public key that pairs with the first private key.

[0146] This allows authentication (for example, authentication of whether the data is mobile data associated with a user) to be performed based on whether the first signature stored in the first server can be decrypted using the first public key, which leads to a secure mechanism.

[0147] (Technology 7) The mobile body according to any one of techniques 1 to 6 further comprises a storage unit capable of storing the first authentication information.

[0148] This allows the first authentication information to be stored when it is acquired in advance.

[0149] (Technology 8) The moving body is a vehicle, and is one of the moving bodies according to any one of Techniques 1 to 7.

[0150] This makes it possible to realize a vehicle that has a secure mechanism and can easily transmit mobile body data (vehicle data) from the second server to the first server.

[0151] (Technology 9) An authentication system 1 includes the mobile body of any one of techniques 1 to 8, the first server, and the second server, wherein the second server transfers the mobile body data, to which the first authentication information and the third authentication information have been attached, received from the mobile body, to the first server, and the first server performs authentication based on the fourth authentication information and the second authentication information, and the first authentication information and the third authentication information attached to the mobile body data.

[0152] This makes it possible to realize an authentication system in which authentication is performed in the first server. Such an authentication system has a secure mechanism and can easily transmit mobile data from the second server to the first server.

[0153] (Technology 10) An authentication system 1 includes the mobile body of any one of techniques 1 to 8, the first server, and the second server, wherein the second server stores the mobile body data to which the first authentication information and the third authentication information received from the mobile body are attached, and when the second server receives a request for the mobile body data from the first server, performs authentication based on the fourth authentication information and the second authentication information received from the first server and the first authentication information and the third authentication information attached to the mobile body data.

[0154] This makes it possible to realize an authentication system in which authentication is performed in the second server. Such an authentication system has a secure mechanism and can easily transmit mobile data from the second server to the first server.

[0155] (Technology 11) A data structure of data transmitted from a mobile body to a second server in an authentication system including the mobile body of any one of techniques 1 to 8, the first server, and the second server, the data structure including the mobile body data of the mobile body, the third authentication information of the mobile body, and the first authentication information stored in the mobile body.

[0156] As a result, when data having such a data structure is transferred from the second server to the first server, authentication can be performed in the first server using the first to third authentication information. In other words, since authentication is performed using the first to third authentication information, the authentication system has a secure mechanism. Furthermore, the second server only needs to transfer the mobile object data to which the first authentication information and the third authentication information have been assigned to the first server without communicating with the first server for authentication. Therefore, a data structure can be realized that has a secure mechanism and allows mobile object data to be easily transmitted from the second server to the first server.

[0157] (Technology 12) The data structure of technology 11 is such that the first authentication information includes the user's identification information and the first public key of the first server, and the third authentication information includes the mobile entity's identification information and the mobile entity's second public key.

[0158] This allows data including the mobile entity's identification information, the mobile entity's second public key, the user's identification information, and the first public key of the first server to be transmitted to the second server. The mobile entity's identification information, the mobile entity's second public key, the user's identification information, and the first public key of the first server are information used for authentication performed in the first server or the second server.

[0159] (Technology 13) An information processing method includes receiving first authentication information transmitted by a first server for providing a service subscribed to by a user of a mobile body, the first server being capable of storing second authentication information from the mobile body, acquiring mobile body data of the mobile body, transmitting third authentication information used for authentication using the second authentication information and the mobile body data to which the first authentication information has been added to a second server that collects mobile body data, and the first server storing fourth authentication information used for authentication using the first authentication information.

[0160] This provides the same effect as the above-mentioned moving body.

[0161] (Technology 14) A program for causing a computer to execute the information processing method of Technology 13.

[0162] This provides the same effect as the above-mentioned moving body. [Industrial Applicability]

[0163] The present disclosure is useful for a mobile object that transmits vehicle data. [Explanation of symbols]

[0164] 1. Authentication System 10 Vehicles (moving objects) 11 Receiving unit 12 Acquisition Department 13, 23, 34 Storage section 14 1st generation section (generation section) 15 Second generation part 16 Transmitter 17 ECU 18a 1st ECU 18b 2nd ECU 18c 3rd ECU 20 Vehicle Server 21, 31, 41 Communications Department 22 Control Unit 30 Service Server 32 Generation part 33 Authentication Section 40 User terminals 42 Reception Department 43 Application execution unit 44 Display section

Claims

1. a receiving unit that receives first authentication information transmitted from a first server that provides a service subscribed to by a user of the mobile device and that is capable of storing second authentication information from the mobile device; an acquisition unit that acquires mobile body data of the mobile body; a transmitting unit that transmits third authentication information used for authentication using the second authentication information and the mobile body data to which the first authentication information has been added to a second server that collects mobile body data; The first server stores fourth authentication information to be used for authentication using the first authentication information. Mobile object.

2. The second authentication information includes identification information of the mobile entity and a second public key of the mobile entity, which is paired with a second private key used to generate a second signature included in the third authentication information. The moving body according to claim 1 .

3. The second signature generating unit generates the second public key and the second signature using the second private key of the mobile entity. The moving body according to claim 2 .

4. The generation unit generates the second public key and the second signature when the mobile entity acquires the first authentication information. The moving body according to claim 3 .

5. The transmitting unit further adds information indicating a destination of the first server to the mobile data and transmits the mobile data to the second server. A moving body according to any one of claims 1 to 4.

6. the fourth authentication information includes a first signature generated using a first private key of the first server; The first authentication information includes identification information of the user and a first public key that is paired with the first private key. A moving body according to any one of claims 1 to 4.

7. Further, a storage unit capable of storing the first authentication information is provided. A moving body according to any one of claims 1 to 4.

8. The moving body is a vehicle. A moving body according to any one of claims 1 to 4.

9. An authentication system including the mobile object according to any one of claims 1 to 4, the first server, and the second server, the second server transfers the mobile body data to which the first authentication information and the third authentication information have been added, received from the mobile body, to the first server; The first server performs authentication based on the fourth authentication information, the second authentication information, and the first authentication information and the third authentication information assigned to the mobile body data. Authentication system.

10. An authentication system including the mobile object according to any one of claims 1 to 4, the first server, and the second server, The second server stores the mobile body data to which the first authentication information and the third authentication information received from the mobile body are attached, and when a request for the mobile body data is received from the first server, performs authentication based on the fourth authentication information and the second authentication information received from the first server and the first authentication information and the third authentication information attached to the mobile body data. Authentication system.

11. 5. A data structure of data transmitted from the mobile device to the second server in an authentication system including the mobile device according to claim 1, the first server, and the second server, comprising: The mobile body data of the mobile body; the third authentication information of the mobile unit; the first authentication information stored in the mobile unit. Data structure.

12. the first authentication information includes identification information of the user and a first public key of the first server; The third authentication information includes identification information of the mobile unit and a second public key of the mobile unit. The data structure of claim 11.

13. receiving first authentication information transmitted from a first server for providing a service subscribed to by a user of the mobile device, the first server being capable of storing second authentication information from the mobile device; acquiring mobile object data of the mobile object; transmitting the mobile body data to which the first authentication information and third authentication information used for authentication using the second authentication information have been added to a second server that collects mobile body data; The first server stores fourth authentication information to be used for authentication using the first authentication information. Information processing methods.

14. A program for causing a computer to execute the information processing method according to claim 13.

Citation Information

Patent Citations

  • Data structure, vehicle-mounted terminal, information communication method, program, and storage medium

    JP2019175185A