Authentication method, authentication system and authentication device
The authentication method validates a third certificate for vehicle and external device combinations in autonomous driving systems, addressing level determination challenges and ensuring safety by monitoring and controlling certificate status.
Patent Information
- Application Number
- JP2025130973
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2019-08-30
- Filing Date
- 2025-08-05
- Publication Date
- 2025-10-14
AI Technical Summary
In autonomous driving systems, determining the appropriate autonomous driving level becomes challenging when an external device is installed, as it can change the system's capabilities, leading to uncertainties in responsibility and safety.
An authentication method that validates a third certificate for the combination of a vehicle and an external device using first and second certificates, monitoring their status, and invalidating the certificate upon changes or failures to ensure the system operates at the correct level.
This approach allows for accurate determination of the autonomous driving level, preventing unauthorized devices and ensuring a safe operating state by validating and invalidating certificates based on device authentication and status monitoring.
Smart Images

Figure 2025156539000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an authentication method, an authentication system, and an authentication device in an autonomous driving system. [Background technology]
[0002] In recent years, there has been a shift in automobile driving from human driving to automated driving systems. In automated driving systems (hereafter referred to as automated driving systems), an electronic control unit (hereafter referred to as ECU) performs all operations such as steering, braking, and acceleration based on the values of various sensors. This is expected to reduce the number of traffic accidents caused by human error and curb environmental pollution caused by exhaust gases, etc.
[0003] Generally, an autonomous driving system is broadly divided into three components. The three components are a recognition unit that acquires information such as traffic conditions using sensors or communications to measure the surrounding environment; a judgment unit that determines the optimal driving route and driving speed based on the information from the recognition unit; and a control unit that operates the accelerator, brakes, steering, etc. based on the judgment results of the judgment unit. Among these, the technical fields related to the recognition unit and judgment unit in particular have been continuously researched and developed to realize more advanced autonomous driving, and the technology is evolving significantly. Since vehicle development is unavoidably protracted, typically spanning several years, methods are being considered to realize the recognition unit and judgment unit as separate external devices. By connecting a separate external device equipped with components that realize an even more advanced autonomous driving system to a vehicle already equipped with an autonomous driving system, it is possible to always realize the latest autonomous driving system.
[0004] However, in the process of realizing full automation of automated driving systems, it is expected that there will be cases where steering is performed by both the driver and the ECU, and there has been much discussion about who is responsible in these cases. For example, Non-Patent Document 1 defines automated driving levels in six stages from 0 to 5, and defines responsibility according to each level. [Prior art documents] [Non-patent literature]
[0005] [Non-Patent Document 1] SAE-J3016_201806:Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicle Summary of the Invention [Problem to be solved by the invention]
[0006] When dealing with these levels of autonomous driving, it is extremely important to know the current level of autonomous driving of the vehicle. However, in the case of an autonomous driving system that includes a separate external device as described above, a more advanced autonomous driving system can be realized by installing an external device, and the autonomous driving level may change depending on the installed external device. In other words, it is necessary to appropriately determine the autonomous driving level when an external device is installed in the vehicle.
[0007] Therefore, in order to solve the above problem, the present disclosure aims to provide an authentication method, etc. that can appropriately determine the autonomous driving level of the entire autonomous driving system when an external device is installed in a vehicle. [Means for solving the problem]
[0008] In order to achieve the above-mentioned object, one aspect of the present disclosure is an authentication method in an autonomous driving system including a vehicle and an external device that communicates with the vehicle and provides functions for the vehicle to perform autonomous driving, wherein the vehicle holds a first certificate for proving the legitimacy of the vehicle, and the external device holds a second certificate for proving the legitimacy of the external device, the authentication method validates a third certificate for proving the legitimacy of the combination of the vehicle and the external device based on the result of equipment authentication between the vehicle and the external device using the first certificate and the second certificate, outputs information regarding the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, which corresponds to the validated third certificate, and further monitors the status of the vehicle and the external device, and invalidates the third certificate in accordance with changes in the status, the status being the status of the external device, and invalidating the third certificate when a failure occurs in the external device. [Effects of the Invention]
[0009] According to the present disclosure, it is possible to appropriately determine the autonomous driving level of the entire autonomous driving system when an external device is installed in a vehicle, thereby providing a safer autonomous driving system. [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 is a diagram illustrating an example of the overall configuration of an autonomous driving system according to the first embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of the configuration of the ECU according to the first embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of the configuration of the autonomous driving ECU according to the first embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of the configuration of the vehicle-side communication ECU according to the first embodiment. [Figure 5] FIG. 5 is a diagram showing an example of the format of a public key certificate. [Figure 6]FIG. 6 is a diagram illustrating an example of a format of the certificate table according to the first embodiment. [Figure 7] FIG. 7 is a diagram illustrating an example of the configuration of the communication ECU on the external device side according to the first embodiment. [Figure 8] FIG. 8 is a sequence diagram showing an example of an authentication operation between a vehicle and an external device according to the first embodiment. [Figure 9] FIG. 9 is a flowchart showing an example of an operation for validating a public key certificate according to the first embodiment. [Figure 10] FIG. 10 is a flowchart showing an example of the operation of revoking a public key certificate according to the first embodiment. [Figure 11] FIG. 11 is a flowchart showing an example of an operation for validating a public key certificate according to a modification of the first embodiment. [Figure 12] FIG. 12 is a flowchart showing an example of an operation for revoking a public key certificate according to the modification of the first embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of the overall configuration of an autonomous driving system according to the second embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of the configuration of the vehicle-side communication ECU according to the second embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of the configuration of the V2X communication ECU according to the second embodiment. [Figure 16] FIG. 16 is a diagram illustrating an example of a configuration of a server according to the second embodiment. [Figure 17] FIG. 17 is a diagram illustrating an example of a format of the certificate table according to the second embodiment. [Figure 18] FIG. 18 is a sequence diagram showing an example of an operation for issuing a public key certificate according to the second embodiment. [Figure 19] FIG. 19 is a sequence diagram showing an example of an operation for revoking a public key certificate according to the second embodiment. [Figure 20] FIG. 20 is a sequence diagram showing an example of an operation for issuing a public key certificate in a variation of the second embodiment. [Figure 21] FIG. 21 is a sequence diagram showing an example of an operation for revoking a public key certificate in a variation of the second embodiment. [Figure 22] FIG. 22 is a diagram illustrating an example of the overall configuration of an autonomous driving system according to the third embodiment. [Figure 23] FIG. 23 is a diagram illustrating an example of the configuration of the vehicle-side communication ECU according to the third embodiment. [Figure 24] FIG. 24 is a diagram illustrating an example of the configuration of a communication ECU on the external device side according to the third embodiment. [Figure 25] FIG. 25 is a sequence diagram showing an example of an operation for issuing a public key certificate according to the third embodiment. [Figure 26] FIG. 26 is a sequence diagram showing an example of an operation for revoking a public key certificate according to the third embodiment. [Figure 27] FIG. 27 is a sequence diagram showing an example of an operation for issuing a public key certificate in a variation of the third embodiment. [Figure 28] FIG. 28 is a sequence diagram showing an example of an operation for revoking a public key certificate in a variation of the third embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0011] In order to solve the above problem, an authentication method in one embodiment of the present disclosure is an authentication method in an autonomous driving system including a vehicle and an external device that communicates with the vehicle and provides functions for the vehicle to perform autonomous driving, wherein the vehicle holds a first certificate for proving the legitimacy of the vehicle, the external device holds a second certificate for proving the legitimacy of the external device, and the authentication method is characterized in that it validates a third certificate for proving the legitimacy of the combination of the vehicle and the external device based on the result of equipment authentication between the vehicle and the external device using the first certificate and the second certificate.
[0012] When an external device is attached to a vehicle in an autonomous driving system, device authentication between the vehicle and the external device is performed. If the device authentication is successful, the autonomous driving system can recognize the combination of a legitimate vehicle and a legitimate external device included in the autonomous driving system as a result of the device authentication. For example, the autonomous driving system holds a third certificate for each combination of a vehicle and an external device, and each third certificate corresponds to the autonomous driving level of the entire autonomous driving system for that combination. Therefore, the autonomous driving system can validate the third certificate corresponding to the recognized combination and recognize the autonomous driving level corresponding to the validated third certificate, i.e., the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined. In this way, it is possible to appropriately determine the autonomous driving level of the entire autonomous driving system when an external device is attached to the vehicle, thereby maintaining a safe state for the entire system.
[0013] The authentication method may further be characterized by outputting information regarding the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, which corresponds to the validated third certificate.
[0014] This makes it possible to notify vehicle occupants or managers of the autonomous driving level of the entire autonomous driving system, and to perform autonomous driving according to the autonomous driving level of the entire autonomous driving system.
[0015] Furthermore, the validation of the third certificate may be characterized by validating the third certificate corresponding to at least one of the vehicle ID of the vehicle and the device ID of the external device obtained as a result of the device authentication.
[0016] In this way, by obtaining the vehicle ID of a legitimate vehicle or the device ID of a legitimate external device, it is possible to validate the third certificate corresponding to the vehicle ID or the device ID.
[0017] The third certificate may be issued when the vehicle is manufactured and stored in the vehicle in advance.
[0018] This allows the certificate to be quickly validated in the vehicle without the need for an external communication device, etc. Furthermore, by issuing a third certificate in advance only for a specific combination of a specific vehicle and a specific external device, it becomes possible to restrict the validation of the third certificate for combinations other than the specific combination, thereby maintaining an even more secure state for the entire system.
[0019] The autonomous driving system may further include a server, and the third certificate may be sent from the server to the vehicle or the external device when the equipment authentication is performed.
[0020] This eliminates the need to provide a storage area for storing pre-issued certificates in the vehicle, etc., thereby saving storage area. Also, it becomes easy to add a third certificate for a new combination of the vehicle and the external device.
[0021] The third certificate may be validated when a driving state of the vehicle satisfies a specific condition.
[0022] This allows the third certificate to be validated only when the vehicle's driving status satisfies certain conditions. For example, it can be validated at a time when the vehicle's driving status does not affect the driver, thereby preventing a decrease in convenience.
[0023] The vehicle's running state that satisfies the specific condition may be that the vehicle is stopped.
[0024] Since an external device is not normally attached to a vehicle while it is moving, attaching an external device to a vehicle while it is moving, in other words, performing device authentication while the vehicle is moving, may indicate the possibility of some kind of abnormality. Therefore, by validating the third certificate only when the vehicle is stopped, it is possible to prevent the third certificate from being validated in a state where an abnormality may be occurring. It is also possible to prevent malfunctions such as accidentally activating the third certificate while the vehicle is moving.
[0025] Furthermore, the state of the vehicle and the external device may be monitored, and the third certificate may be invalidated in response to a change in the state.
[0026] Depending on the state of the vehicle and external devices, it may be better to revert the autonomous driving level from that of the entire autonomous driving system to that of the vehicle alone. Therefore, it is possible to invalidate the third certificate depending on the state of the vehicle and external devices and set the autonomous driving level appropriately.
[0027] Further, the state may be a communication state between the vehicle and the external device, and the invalidation of the third certificate may be characterized in that the third certificate is invalidated when the communication state becomes abnormal.
[0028] If a communication abnormality occurs between the vehicle and the external device, the autonomous driving system including the vehicle and the external device will not function properly, so it is possible to invalidate the third certificate depending on the communication status between the vehicle and the external device, which affects the autonomous driving level, and set the autonomous driving level appropriately.
[0029] The monitoring of the state may be characterized in that the state is monitored when the running state of the vehicle satisfies a specific condition.
[0030] This makes it possible to ensure the safety of the driver by checking the need for invalidation processing of the third certificate when the vehicle's driving conditions change.
[0031] The vehicle's running state that satisfies the specific condition may be that the vehicle is stopped.
[0032] This allows the processing load to be reduced by limiting the invalidation process of the third certificate to when the vehicle is stopped.
[0033] Furthermore, an authentication system in one embodiment of the present disclosure is an authentication system in an autonomous driving system including a vehicle and an external device that communicates with the vehicle and provides functions for the vehicle to perform autonomous driving, wherein the vehicle holds a first certificate for proving the legitimacy of the vehicle, the external device holds a second certificate for proving the legitimacy of the external device, and the authentication system is characterized in that it includes a management unit that validates a third certificate for proving the legitimacy of the combination of the vehicle and the external device based on the result of equipment authentication between the vehicle and the external device using the first certificate and the second certificate.
[0034] This makes it possible to provide an authentication system that can appropriately determine the autonomous driving level of the entire autonomous driving system when an external device is installed in a vehicle.
[0035] In addition, an authentication device in one embodiment of the present disclosure is an authentication device provided in a vehicle in an autonomous driving system including a vehicle and an external device that communicates with the vehicle and provides functions for the vehicle to perform autonomous driving, and is characterized in that the authentication device includes: a holding unit that holds a first certificate for proving the legitimacy of the vehicle; an authentication unit that authenticates the external device using a second certificate for proving the legitimacy of the external device; and a management unit that uses the result of the authentication to validate a third certificate for proving the legitimacy of the combination of the vehicle and the external device.
[0036] This makes it possible to provide an authentication device that can appropriately determine the autonomous driving level of the entire autonomous driving system when an external device is installed in a vehicle. It also makes it possible to prevent the installation of unauthorized external devices in the vehicle, thereby maintaining a safe state without accidentally raising the autonomous driving level.
[0037] In addition, an authentication device in one embodiment of the present disclosure is an authentication device provided in an external device in an autonomous driving system including a vehicle and an external device that communicates with the vehicle and provides functions for the vehicle to perform autonomous driving, and is characterized in that the authentication device includes a holding unit that holds a second certificate to prove the legitimacy of the external device, an authentication unit that authenticates the vehicle using a first certificate to prove the legitimacy of the vehicle, and a management unit that uses the result of the authentication to validate a third certificate to prove the legitimacy of the combination of the vehicle and the external device.
[0038] This makes it possible to provide an authentication device that can appropriately determine the autonomous driving level of the entire autonomous driving system when an external device is installed in a vehicle. It also makes it possible to prevent unauthorized installation of external devices in vehicles, thereby maintaining a safe state without accidentally raising the autonomous driving level.
[0039] Hereinafter, an authentication method and the like according to embodiments of the present disclosure will be described with reference to the drawings. Note that each of the embodiments described below represents a preferred specific example of the present disclosure. In other words, the numerical values, components, arrangement and connection of components, steps, and order of steps shown in the following embodiments are examples of the present disclosure and are not intended to limit the present disclosure. The present disclosure is defined based on the claims. Therefore, among the components in the following embodiments, components not recited in the independent claims that represent the highest concept of the present disclosure are not necessarily required to achieve the objectives of the present disclosure, but are described as components that constitute more preferred embodiments.
[0040] (Embodiment 1) [1. System configuration] Here, an autonomous driving system 1000 will be described as an embodiment of the present disclosure with reference to the drawings.
[0041] [1.1 Overall configuration of the Autonomous Driving System 1000] FIG. 1 is a diagram illustrating an example of the overall configuration of an autonomous driving system 1000 according to the first embodiment.
[0042] The autonomous driving system 1000 is composed of a vehicle 1001 and an external device 1002 that is connected to and operates with the vehicle 1001.
[0043] For example, vehicle 1001 is composed of ECUs 1100a, 1100b, 1100c, and 1100d, which are connected via various in-vehicle networks; a camera 1010, a brake 1011, a steering wheel 1012, and an accelerator 1013, which are controlled by each ECU; an autonomous driving ECU 1200, which communicates with each of ECUs 1100a to 1100d to perform control related to autonomous driving; and a communication ECU 1300, which communicates with autonomous driving ECU 1200 via the in-vehicle networks.
[0044] The ECUs 1100a to 1100d control the vehicle by transmitting and receiving communication messages to each other through an in-vehicle network, which may use Ethernet (registered trademark) or CAN (Controller Area Network) (registered trademark).
[0045] The autonomous driving ECU 1200 communicates with other ECUs via the in-vehicle network and makes the decisions and control instructions required for autonomous driving.
[0046] The communication ECU 1300 communicates with the external device 1002 and transmits and receives messages to and from the external device 1002 and other ECUs in the vehicle 1001 .
[0047] The external device 1002 is a device that communicates with the vehicle 1001 and provides one or more functions for the vehicle 1001 to perform automatic driving (for example, steering and acceleration / deceleration instructions, etc.) For example, the external device 1002 includes an ECU 1100e, a lidar 1014 that is controlled by the ECU 1100e, and a communication ECU 1400 that communicates with the ECU 1100e via an in-vehicle network.
[0048] The ECU 1100e exchanges communication messages through an in-vehicle network, similar to the ECU 1100a, etc. Ethernet or the like is used for the in-vehicle network.
[0049] The communication ECU 1400 communicates with the vehicle 1001 and transmits and receives messages to and from other ECUs in the vehicle 1001 and the external device 1002 .
[0050] [1.2 ECU1100a configuration diagram] FIG. 2 is a diagram showing an example of the configuration of ECU 1100a according to the first embodiment.
[0051] For example, the ECU 1100a includes a communication unit 1101 and a message conversion unit 1102. The ECUs 1100b, 1100c, 1100d, and 1100e have the same configuration, and therefore will not be described here.
[0052] The communication unit 1101 communicates with external ECUs or various sensors via an in-vehicle network. The communication unit 1101 notifies the message conversion unit 1102 of the received message or sensor value. The communication unit 1101 also transmits the message notified by the message conversion unit 1102 to other ECUs or various sensors.
[0053] The message conversion unit 1102 converts the sensor values of the various sensors notified by the communication unit 1101 based on the format of the in-vehicle network, and transmits them to other ECUs via the communication unit 1101. The message conversion unit 1102 also converts communication messages received from the communication unit 1101 into sensor values or setting information, and transmits them to the various sensors via the communication unit 1101.
[0054] [1.3 Autonomous Driving ECU 1200 Configuration Diagram] FIG. 3 is a diagram illustrating an example of the configuration of the autonomous driving ECU 1200 according to the first embodiment.
[0055] For example, the autonomous driving ECU 1200 includes a communication unit 1201, a determination unit 1202, and an autonomous driving level management unit 1203.
[0056] The communication unit 1201 communicates with other ECUs via an in-vehicle network and notifies the received messages to the determination unit 1202 and the autonomous driving level management unit 1203. The communication unit 1201 also transmits messages notified by the determination unit 1202 to the other ECUs.
[0057] The determination unit 1202 acquires various sensor values from the received message notified by the communication unit 1201, and transmits necessary control instructions to other ECUs via the communication unit 1201.
[0058] The autonomous driving level management unit 1203 manages the current autonomous driving level by acquiring information on the current certificate from the message notified by the communication unit 1201, and notifies the determination unit 1202. The determination unit 1202 can operate according to the current autonomous driving level. For example, the type of sensor used or the amount of data may be changed according to the current autonomous driving level.
[0059] [1.4 Configuration diagram of the communication ECU 1300 on the vehicle 1001 side] FIG. 4 is a diagram showing an example of the configuration of communication ECU 1300 on the vehicle 1001 side according to the first embodiment.
[0060] For example, the communication ECU 1300 includes a communication unit 1301, an authentication processing unit 1302, an authentication information holding unit 1303, a certificate management unit 1304, and a certificate holding unit 1305. The communication ECU 1300 is an example of an authentication device provided in the vehicle 1001 in the autonomous driving system 1000.
[0061] The communication unit 1301 communicates with the external device 1002. For example, the communication unit 1301 communicates with the external device 1002 via a wired connection. The communication unit 1301 also communicates with the autonomous driving ECU 1200 in the vehicle 1001 via an in-vehicle network. The communication unit 1301 may also communicate with a server or the like. The communication unit 1301 notifies the authentication processing unit 1302 and the certificate management unit 1304 of a communication message received from the external device 1002. The communication unit 1301 also receives a notification from the authentication processing unit 1302 and transmits a communication message to the external device 1002. Although details will be described later, the communication unit 1301 is an example of an output unit that outputs information related to the autonomous driving level of the entire autonomous driving system 1000 when the vehicle 1001 and the external device 1002 are combined, corresponding to the validated third certificate.
[0062] The authentication processing unit 1302 communicates with the external device 1002 via the communication unit 1301 and performs authentication processing for the external device 1002. The authentication processing unit 1302 is an example of an authentication unit that authenticates the external device 1002 using a second certificate for proving the legitimacy of the external device 1002. The authentication processing unit 1302 also acquires information required for the authentication processing from the authentication information holding unit 1303. The authentication processing unit 1302 also notifies the certificate management unit 1304 of the result of the authentication processing.
[0063] The authentication information storage unit 1303 stores a key pair of a private key and a public key certificate. The authentication information storage unit 1303 is an example of a storage unit that stores a first certificate for certifying the legitimacy of the vehicle 1001. The public key certificate stored in the authentication information storage unit 1303 is an example of a first certificate. The private key and the public key certificate are embedded in the authentication information storage unit 1303 when the vehicle 1001 is shipped.
[0064] FIG. 5 is a diagram showing an example of the format of a public key certificate.
[0065] The public key certificate consists of information such as the version, issuer, start and end of validity period, autonomous driving level, certificate ID, and certificate authority signature. Note that the public key certificate does not necessarily have to include the autonomous driving level.
[0066] The certificate holding unit 1305 holds a group of public key certificates and a certificate table. The public key certificates held by the certificate holding unit 1305 are examples of third certificates for verifying the validity of the combination of the vehicle 1001 and the external device 1002. There are various types of vehicles 1001 and external devices 1002, and the certificate holding unit 1305 holds a third certificate (i.e., a group of third certificates) for each of the various combinations of the vehicle 1001 and the external device 1002. In the first embodiment, the group of third certificates is issued when the vehicle 1001 is manufactured and is held in advance in the vehicle 1001. For example, the group of third certificates is embedded in the certificate holding unit 1305 when the vehicle 1001 is shipped. Each of the third certificates corresponds to the autonomous driving level of the entire autonomous driving system 1000 at the time the external device 1002 is installed in the vehicle 1001.
[0067] FIG. 6 is a diagram showing an example of the format of the certificate table in the first embodiment. Each row in the certificate table corresponds to a third certificate. For example, each row in the certificate table is composed of the certificate ID of the third certificate, the autonomous driving level corresponding to the third certificate, the device ID corresponding to the third certificate, and the status of the third certificate. Note that the status of each third certificate is rewritten between valid and invalid depending on the current status.
[0068] The certificate management unit 1304 is an example of a management unit that validates a third certificate using the authentication result of the authentication processing unit 1302. Using the authentication result notified from the authentication processing unit 1302 and a certificate table held in the certificate holding unit 1305, the certificate management unit 1304 notifies the authentication information holding unit 1303 of a third certificate corresponding to the authentication result from a group of third certificates previously held therein, and stores the third certificate in the authentication information holding unit 1303. As a result, the notified third certificate is registered in the authentication information holding unit 1303, and the third certificate is validated. Furthermore, the certificate management unit 1304 deletes the third certificate stored in the authentication information holding unit 1303 based on the communication processing result from the communication unit 1301. As a result, the registration of the third certificate in the authentication information holding unit 1303 is cancelled, and the validated third certificate is invalidated. Details of the process of validating and invalidating a third certificate will be described later.
[0069] [1.5 Configuration diagram of communication ECU 1400 on external device 1002 side] FIG. 7 is a diagram showing an example of the configuration of communication ECU 1400 on the external device 1002 side according to the first embodiment.
[0070] The communication ECU 1400 includes a communication unit 1401 , an authentication processing unit 1402 , and an authentication information holding unit 1403 .
[0071] The communication unit 1401 communicates with the vehicle 1001. For example, the communication unit 1401 communicates with the vehicle 1001 via a wired connection. The communication unit 1401 also communicates with the ECU 1100e in the external device 1002 via an in-vehicle network. The communication unit 1401 notifies the authentication processing unit 1402 of a communication message received from the vehicle 1001. The communication unit 1401 also receives a notification from the authentication processing unit 1402 and transmits the communication message to the vehicle 1001.
[0072] The authentication processing unit 1402 communicates with the vehicle 1001 via the communication unit 1401 and performs authentication processing of the vehicle 1001. The authentication processing unit 1402 is an example of an authentication unit that authenticates the vehicle 1001 using a first certificate for proving the legitimacy of the vehicle 1001. In addition, the authentication processing unit 1402 obtains information required for the authentication processing from the authentication information storage unit 1403.
[0073] The authentication information holding unit 1403 holds a key pair of a private key and a public key certificate. The authentication information holding unit 1403 is an example of a holding unit that holds a second certificate for verifying the authenticity of the external device 1002. The public key certificate held by the authentication information holding unit 1403 is an example of a second certificate. The private key and the public key certificate are embedded in the authentication information holding unit 1403 when the external device 1002 is shipped. The format of the public key certificate (second certificate) is the same as that shown in FIG. 5, for example, and therefore will not be described here.
[0074] [1.6 Example of authentication sequence] Next, mutual authentication performed between the communication ECU 1300 on the vehicle 1001 side and the communication ECU 1400 on the external device 1002 side when the external device 1002 is attached to the vehicle 1001 will be described with reference to FIG.
[0075] FIG. 8 is a sequence diagram showing an example of an authentication operation between the vehicle 1001 and the external device 1002 according to the first embodiment.
[0076] The external device 1002 sends a connection request to the vehicle 1001 (S1101). At this time, the external device 1002 also sends the device ID and public key certificate (that is, the second certificate) of the external device 1002.
[0077] The vehicle 1001 verifies the signature of the public key certificate received from the external device 1002 (S1102). If the verification is not successful (N in S1102), the vehicle 1001 notifies the external device 1002 of an error and ends the process.
[0078] If the verification is successful (Y in S1102), the vehicle 1001 generates a random number and transmits the generated random number together with the vehicle ID and public key certificate (i.e., the first certificate) of the vehicle 1001 to the external device 1002 (S1103).
[0079] The external device 1002 receives the random number and the public key certificate and verifies the signature of the public key certificate received from the vehicle 1001 (S1104). If the verification is not successful (N in S1104), the external device 1002 notifies the vehicle 1001 of an error and ends the processing.
[0080] If the verification is successful (Y in S1104), the external device 1002 generates a signature from the random number received from the vehicle 1001 and the private key of the external device 1002 (S1105).
[0081] The external device 1002 generates a random number and transmits the generated random number together with the signature generated in S1105 to the vehicle 1001 (S1106).
[0082] The vehicle 1001 receives the signature and the random number and verifies the signature using the public key certificate received in S1101 (S1107). If the signature verification is not successful (N in S1107), the vehicle 1001 notifies the external device 1002 of an error and ends the process.
[0083] If the signature verification is successful (Y in S1107), the vehicle 1001 generates a signature from the random number received in S1107 and the private key of the vehicle 1001, and transmits the generated signature to the external device 1002 (S1108).
[0084] The external device 1002 receives the signature and verifies the signature using the public key certificate received in S1104 (S1109). If the signature verification is not successful (N in S1109), the external device 1002 notifies the vehicle 1001 of an error and ends the process.
[0085] If the verification is successful in S1109, the vehicle 1001 registers the device ID of the external device 1002 as a connection destination, and the external device 1002 registers the vehicle ID of the vehicle 1001 as a connection destination (S1110). In this way, as a result of device authentication between the vehicle 1001 and the external device 1002, the vehicle ID of the legitimate vehicle 1001 and the device ID of the legitimate external device 1002 are obtained.
[0086] The device ID is an identifier for identifying the external device 1002, and its format is not particularly limited, and may be, for example, a Media Access Control (MAC) address or an identifier individually set by each manufacturer. The vehicle ID is an identifier for identifying the vehicle 1001, and its format is not particularly limited, and may be, for example, a MAC address or an identifier individually set by each manufacturer.
[0087] [1.7 Example of a flowchart for validating a certificate] Next, the validation of the third certificate held in the vehicle 1001 according to the autonomous driving level will be described with reference to FIG.
[0088] FIG. 9 is a flowchart showing an example of an operation for validating a public key certificate (third certificate) according to the first embodiment.
[0089] The certificate management unit 1304 determines whether or not it is possible to acquire a registered device ID (S1201). If there is no registered device ID, the certificate management unit 1304 cannot acquire the device ID (N in S1201), and ends the process as an error. Here, it is assumed that the authentication process in Fig. 8 is completed and the device ID is registered.
[0090] If the certificate management unit 1304 has acquired the device ID (Y in S1201), it checks whether the acquired device ID exists in the certificate table (S1202). If the acquired device ID does not exist in the certificate table (N in S1202), the certificate management unit 1304 regards it as an error and terminates the process.
[0091] If the acquired device ID exists in the certificate table (Y in S1202), the certificate management unit 1304 changes the third certificate corresponding to the acquired device ID to "valid" (S1203). Specifically, the certificate management unit 1304 compares the acquired device ID with the certificate table, notifies the authentication information holding unit 1403 of the third certificate having the certificate ID in the row corresponding to the device ID, and changes the status of the row corresponding to the device ID to "valid." For example, when the external device 1002 having the device ID "XXX" is installed in the vehicle 1001 and device authentication is completed, the certificate management unit 1304 acquires the device ID "XXX," compares the device ID "XXX" with the certificate table, and, as shown in FIG. 6, notifies the authentication information holding unit 1403 of the third certificate having the certificate ID "1" in the row corresponding to the device ID "XXX," and changes the status of the row corresponding to the device ID "XXX" to "valid."
[0092] In this way, a third certificate is validated that corresponds to at least one of the vehicle ID of the vehicle 1001 and the device ID of the external device 1002, which are obtained as a result of device authentication between the vehicle 1001 and the external device 1002. Here, the third certificate is validated in the vehicle 1001, and since the vehicle ID of the vehicle 1001 itself is fixed, the third certificate that corresponds to the device ID of the external device 1002 is validated.
[0093] Then, the communication unit 1301 outputs information regarding the autonomous driving level of the entire autonomous driving system 1000, which corresponds to the validated third certificate (S1204). The autonomous driving level of the entire autonomous driving system 1000 is the autonomous driving level of the autonomous driving system 1000 when the vehicle 1001 and the external device 1002 are combined. The information regarding the autonomous driving level of the entire autonomous driving system 1000 may be information for displaying the autonomous driving level on a display provided in the vehicle 1001 or in a monitoring room that monitors the vehicle 1001, or for displaying that manual driving is not required. Furthermore, the information regarding the autonomous driving level of the entire autonomous driving system 1000 may be information for causing the autonomous driving ECU 1200 to perform autonomous driving according to the autonomous driving level of the entire autonomous driving system 1000.
[0094] [1.8 Example of a flowchart for revoking a certificate] Next, invalidation of the third certificate held in the vehicle 1001 according to the autonomous driving level will be described with reference to FIG.
[0095] FIG. 10 is a flowchart showing an example of the operation of revoking a public key certificate (third certificate) according to the first embodiment.
[0096] The certificate management unit 1304 monitors the communication state between the vehicle 1001 and the external device 1002 via the communication unit 1301 (S1301).
[0097] The certificate management unit 1304 determines whether or not an abnormality has occurred in the communication state between the vehicle 1001 and the external device 1002 (S1302). If no abnormality has occurred in the communication state (N in S1302), the certificate management unit 1304 ends the process.
[0098] If a communication error has occurred (Y in S1302), the certificate management unit 1304 increments the error counter (S1303).
[0099] The certificate management unit 1304 determines whether the error counter is equal to or greater than the threshold value (S1304). If the error counter is less than the threshold value (N in S1304), the process returns to S1302. The threshold value is not particularly limited and may be set as appropriate.
[0100] If the error counter is equal to or greater than the threshold value (Y in S1304), the certificate management unit 1304 invalidates the validated third certificate (S1305). That is, if a communication abnormality between the vehicle 1001 and the external device 1002 continues for a certain period of time or longer, the certificate management unit 1304 invalidates the validated third certificate. For example, the certificate management unit 1304 invalidates the third certificate by deleting the third certificate stored in the authentication information holding unit 1303. At that time, the certificate management unit 1304 also changes the status of the third certificate in the certificate table to "invalid."
[0101] The certificate management unit 1304 resets the error counter (S1306).
[0102] The certificate management unit 1304 deletes the device ID of the connection destination (S1307).
[0103] In this way, the certificate management unit 1304 monitors the states of the vehicle 1001 and the external device 1002, and revokes the third certificate in response to changes in the states. Specifically, the states of the vehicle 1001 and the external device 1002 are communication states between the vehicle 1001 and the external device 1002, and the certificate management unit 1304 revokes the third certificate when the communication state becomes abnormal.
[0104] [1.9 Effects of the First Embodiment] In the autonomous driving system 1000 shown in embodiment 1, a third certificate is installed in advance in addition to the first certificate of the vehicle 1001 and the second certificate of the external device 1002, and the third certificate is switched between valid and invalid based on the communication results between the vehicle 1001 and the external device 1002, thereby making it possible to determine the appropriate autonomous driving level when the vehicle 1001 and the external device 1002 operate together, thereby ensuring safety.
[0105] (Modification of the first embodiment) In the autonomous driving system 1000 shown in the first embodiment, the third certificate can be validated or invalidated at any time, but the timing of validation or invalidation may be controlled depending on the driving state. This will be described as a modified example of the first embodiment. Note that a description of the same points as those in the first embodiment will be omitted.
[0106] [1.10 Example of a flowchart for validating a certificate] 11 is a flowchart showing an example of the operation of validating a public key certificate (third certificate) in a variation of the first embodiment. In the variation of the first embodiment, the third certificate is validated when the traveling state of the vehicle 1001 satisfies a specific condition. Note that steps similar to those in the first embodiment are given the same numbers and descriptions thereof will be omitted.
[0107] For example, the traveling state of the vehicle 1001 that satisfies a specific condition is stopped, and the certificate management unit 1304 determines whether the traveling state of the vehicle 1001 is stopped or not before validating the third certificate (S1205). If the vehicle 1001 is not stopped (N in S1205), the certificate management unit 1304 suspends and terminates the validation process of the third certificate, and if the vehicle 1001 is stopped (Y in S1205), it validates the third certificate (S1203).
[0108] [1.11 Example of a flowchart for revoking a certificate] 12 is a flowchart showing an example of an operation for revoking a public key certificate (third certificate) in a modification of the first embodiment. In the modification of the first embodiment, when the traveling state of the vehicle 1001 satisfies a specific condition, the states of the vehicle 1001 and the external device 1002 (for example, the communication state between the vehicle 1001 and the external device 1002) are monitored, and the third certificate is revoked according to the communication state. Note that steps similar to those in the first embodiment are given the same numbers, and explanations thereof will be omitted.
[0109] The certificate management unit 1304 determines whether the vehicle 1001 is currently stopped (S1308). If the vehicle 1001 is not currently stopped (N in S1308), the certificate management unit 1304 suspends and terminates the invalidation process of the third certificate, and if the vehicle 1001 is currently stopped (Y in S1308), the certificate management unit 1304 monitors the communication status (S1301) and continues the invalidation process.
[0110] [1.12 Effects of the Modification of the First Embodiment] In the autonomous driving system 1000 shown in the modified example of embodiment 1, a third certificate is installed in advance in addition to the first certificate of the vehicle 1001 and the second certificate of the external device 1002, and the third certificate is enabled or disabled based on the driving state of the vehicle 1001 as well as the communication results between the vehicle 1001 and the external device 1002, thereby making it possible to determine the appropriate autonomous driving level when the vehicle 1001 and the external device 1002 operate together, thereby ensuring safety.
[0111] The external device 1002 may have the functions of the communication ECU 1300 of the vehicle 1001. That is, the third certificate group may be pre-installed in the external device 1002, and the external device 1002 may switch between validity and invalidity of the third certificate. In this case, the third certificate is validated in the external device 1002, and since the device ID of the external device 1002 itself is fixed, the third certificate corresponding to the vehicle ID of the vehicle 1001 is validated. In this case, the same effect is also achieved.
[0112] (Embodiment 2) [2. System Configuration] Next, an automated driving system 2000 will be described as a second embodiment of the present disclosure with reference to the drawings.
[0113] [2.1 Overall configuration of Autonomous Driving System 2000] FIG. 13 is a diagram illustrating an example of the overall configuration of an autonomous driving system 2000 according to the second embodiment.
[0114] The autonomous driving system 2000 is composed of a vehicle 2001, an external device 1002 that is connected to and operates with the vehicle 2001, and a server 2600 that communicates with the vehicle 2001 via V2X.
[0115] The same components as those in the first embodiment are given the same numbers and the description thereof will be omitted.
[0116] For example, vehicle 2001 is composed of ECUs 1100a, 1100b, 1100c, and 1100d, which are connected via various in-vehicle networks; a camera 1010, a brake 1011, a steering wheel 1012, and an accelerator 1013, which are controlled by each ECU; an autonomous driving ECU 1200 that communicates with each of ECUs 1100a to 1100d to perform control related to autonomous driving; a communication ECU 2300 that communicates with the autonomous driving ECU 1200 and a V2X communication ECU 2500 via the in-vehicle network; and a V2X communication ECU 2500 that performs V2X communication with a server 2600.
[0117] The communication ECU 2300 communicates with the external device 1002 and transmits and receives messages to and from the external device 1002 and other ECUs in the vehicle 2001. The communication ECU 2300 also communicates with the server 2600 via the V2X communication ECU 2500 and transmits and receives messages required to validate a public key certificate (third certificate) corresponding to a new autonomous driving level when the external device 1002 is installed in the vehicle 2001.
[0118] The V2X communication ECU 2500 communicates with the server 2600, and transmits and receives messages between the server 2600 and the communication ECU 2300 in the vehicle 2001.
[0119] The server 2600 communicates with the vehicle 2001 and, depending on the authentication result between the vehicle 2001 and the external device 1002, issues a public key certificate (third certificate) corresponding to the new autonomous driving level when the external device 1002 is installed in the vehicle 2001.
[0120] [2.2 Configuration diagram of the communication ECU 2300 on the vehicle 2001 side] FIG. 14 is a diagram illustrating an example of the configuration of communication ECU 2300 on vehicle 2001 side according to the second embodiment.
[0121] For example, the communication ECU 2300 includes a communication unit 2301, an authentication processing unit 1302, an authentication information holding unit 1303, and a certificate management unit 2304. The communication ECU 2300 is an example of an authentication device provided in the vehicle 2001 in the autonomous driving system 2000. Note that the same components as those in the first embodiment are given the same numbers, and the following description will be omitted.
[0122] The communication unit 2301 communicates with the external device 1002. For example, the communication unit 2301 communicates with the external device 1002 via a wired connection. The communication unit 2301 also communicates with the autonomous driving ECU 1200 and the V2X communication ECU 2500 in the vehicle 2001 via an in-vehicle network. The communication unit 2301 notifies the authentication processing unit 1302 and the certificate management unit 2304 of communication messages received from the external device 1002 and the server 2600. The communication unit 2301 also receives notifications from the authentication processing unit 1302 and the certificate management unit 2304, and transmits communication messages to the external device 1002 and the server 2600.
[0123] The certificate management unit 2304 is an example of a management unit that validates a third certificate using the result of authentication by the authentication processing unit 1302. The certificate management unit 2304 obtains a public key certificate (third certificate) corresponding to a new autonomous driving level issued by the server 2600 from the server 2600 via the communication unit 2301 using the authentication result notified from the authentication processing unit 1302, and stores the public key certificate in the authentication information holding unit 1303. As a result, the third certificate is registered in the authentication information holding unit 1303, and the third certificate is validated on the vehicle 2001 side. Furthermore, the certificate management unit 2304 deletes the third certificate from the authentication information holding unit 1303 based on the communication processing result from the communication unit 2301. As a result, the registration of the third certificate in the authentication information holding unit 1303 is cancelled, and the third certificate that had been validated on the vehicle 2001 side is invalidated.
[0124] [2.3 V2X communication ECU2500 configuration diagram] 15 is a diagram illustrating an example of the configuration of a V2X communication ECU 2500 according to embodiment 2. The V2X communication ECU 2500 includes a communication unit 2501 and a message conversion unit 2502.
[0125] The communication unit 2501 communicates with the communication ECU 2300 through an in-vehicle network. The communication unit 2501 also communicates wirelessly with the server 2600 through V2X communication. The communication unit 2501 notifies the message conversion unit 2502 of the received message. The communication unit 2501 also transmits the message notified by the message conversion unit 2502 to the communication ECU 2300 or the server 2600.
[0126] The message conversion unit 2502 converts a message received from the server 2600 via the communication unit 2501 based on the format of the in-vehicle network, and transmits the converted message to the communication ECU 2300 via the communication unit 2501. The message conversion unit 2502 also transmits a communication message received from the communication ECU 2300 via the communication unit 2501 to the server 2600 via the communication unit 2501.
[0127] [2.4 Server 2600 Configuration Diagram] FIG. 16 is a diagram showing an example of the configuration of the server 2600 according to the second embodiment.
[0128] The server 2600 includes a communication unit 2601, an authentication processing unit 2602, an authentication information holding unit 2603, a certificate management unit 2604, and a certificate holding unit 2605. The server 2600 is an example of an authentication system in the autonomous driving system 2000.
[0129] The communication unit 2601 performs V2X communication with the vehicle 2001. The communication unit 2601 also notifies the authentication processing unit 2602 and the certificate management unit 2604 of the public key certificates (first certificate and second certificate) received from the vehicle 2001. The communication unit 2601 also receives notifications from the authentication processing unit 2602 and the certificate management unit 2604, and transmits a communication message to the vehicle 2001. The communication unit 2601 is an example of an output unit that outputs information related to the autonomous driving level of the entire autonomous driving system 2000 when the vehicle 2001 and the external device 1002 are combined, corresponding to the validated third certificate.
[0130] The authentication processing unit 2602 communicates with the vehicle 2001 via the communication unit 2601 and performs signature verification processing of the public key certificates (first certificate and second certificate) notified by the vehicle 2001. The authentication processing unit 2602 also obtains information required for the signature verification processing from the authentication information holding unit 2603. The authentication processing unit 2602 also notifies the certificate management unit 2604 of the result of the signature verification processing.
[0131] The authentication information storage unit 2603 stores a key pair consisting of a private key and a public key certificate of the certification authority. An example of the configuration of the public key certificate is the same as that shown in Fig. 5, so a description thereof will be omitted here.
[0132] The certificate holder 2605 holds a certificate table.
[0133] FIG. 17 is a diagram showing an example of the format of the certificate table in the second embodiment. Each row in the certificate table corresponds to a third certificate. For example, each row in the certificate table is composed of the certificate ID of the third certificate, the autonomous driving level to which the third certificate applies, a combination of a vehicle ID and a device ID corresponding to the third certificate, and the status of the third certificate. Note that the status of each third certificate is rewritten between valid and invalid depending on the current status.
[0134] The certificate management unit 2604 is an example of a management unit that validates a third certificate based on the result of device authentication between the vehicle 2001 and the external device 1002 using the first certificate and the second certificate. The certificate management unit 2604 issues a new third certificate for verifying the validity of the combination of the vehicle 2001 and the external device 1002, using the authentication result notified from the authentication processing unit 2602 and the certificate table held in the certificate holding unit 2605, notifies the vehicle 2001 of the new third certificate via the communication unit 2601, and stores the new third certificate in the authentication information holding unit 2603. As a result, the notified third certificate is registered in the authentication information holding unit 2603, and the third certificate is validated on the server 2600 side. Furthermore, the certificate management unit 2604 deletes the third certificate stored in the authentication information holding unit 2603 based on an invalidation instruction from the communication unit 2301. As a result, the registration of the third certificate in the authentication information storage unit 2603 is cancelled, and the third certificate that was valid on the server 2600 side is invalidated.
[0135] [2.5 Example of a sequence for issuing a certificate] Next, the issuance of a third certificate by the server 2600 according to the autonomous driving level, which is performed after mutual authentication between the vehicle 2001 and the external device 1002, will be described with reference to Fig. 18. The third certificate issued by the server 2600 is stored and validated in the vehicle 2001.
[0136] FIG. 18 is a sequence diagram showing an example of an operation for issuing a public key certificate (third certificate) in the second embodiment.
[0137] The vehicle 2001 determines whether or not it can acquire a registered device ID (S2201). If there is no registered device ID, the vehicle 2001 cannot acquire the device ID (N in S2201), which means that the authentication process has not been completed, and therefore the process ends. Here, it is assumed that the authentication process in FIG. 8 has been completed and the device ID has been registered.
[0138] If the vehicle 2001 is able to acquire the device ID of the external device 1002 (Y in S2201), it transmits the acquired device ID to the server 2600 together with the vehicle ID of the vehicle 2001, the public key certificate (first certificate) of the vehicle 2001, and the public key certificate (second certificate) of the external device 1002.
[0139] The server 2600 receives the device ID of the external device 1002, the vehicle ID of the vehicle 2001, and the two types of public key certificates, and verifies the signatures of the received two types of public key certificates (S2202). If the verification is not successful (N in S2202), the server 2600 notifies the vehicle 2001 of an error and ends the process.
[0140] If the verification is successful (Y in S2202), the server 2600 checks whether the combination of the device ID and vehicle ID received in S2202 exists in the certificate table (S2203). If the combination of the received device ID and vehicle ID does not exist in the certificate table (N in S2203), the server 2600 notifies the vehicle 2001 of this fact and terminates the process as an error.
[0141] If the combination of the received device ID and vehicle ID exists in the certificate table (Y in S2203), the server 2600 issues a third certificate corresponding to the acquired combination and transmits it to the vehicle 2001 (S2204). Specifically, the certificate management unit 2604 of the server 2600 compares the acquired combination of device ID and vehicle ID with the certificate table, notifies the authentication information holding unit 2603 of the third certificate for the certificate ID in the row corresponding to the combination, and changes the state of the row corresponding to the combination to "valid." For example, when the external device 1002 with a device ID of "XXX" is installed in the vehicle 2001 with a vehicle ID of "AAA" and device authentication is completed, the certificate management unit 2604 acquires the device ID "XXX" and the vehicle ID "AAA," compares the combination of the device ID "XXX" and the vehicle ID "AAA" with the certificate table, and notifies the authentication information holding unit 2603 of the third certificate with the certificate ID "1" in the row corresponding to the device ID "XXX" and the vehicle ID "AAA," as shown in FIG. 17 , and changes the status of the row corresponding to the device ID "XXX" and the vehicle ID "AAA" to "valid." In this way, the third certificate corresponding to the vehicle ID of the vehicle 2001 and the device ID of the external device 1002, which are obtained as a result of device authentication between the vehicle 2001 and the external device 1002, is validated. Then, the third certificate validated on the server 2600 side is transmitted to the vehicle 2001.
[0142] Vehicle 2001 stores the third certificate issued by server 2600 (S2205). For example, the third certificate is stored in authentication information storage unit 1303 in communication ECU 2300 of vehicle 2001, and thereby the third certificate is also validated on the vehicle 2001 side.
[0143] Furthermore, although not shown, the server 2600 outputs information relating to the autonomous driving level of the entire autonomous driving system 2000 when the vehicle 2001 and the external device 1002 are combined, which corresponds to the validated third certificate. Note that the vehicle 2001 (e.g., the communication unit 2301) may output information relating to the autonomous driving level of the entire autonomous driving system 2000 when the vehicle 2001 and the external device 1002 are combined, which corresponds to the validated third certificate.
[0144] [2.6 Example of sequence for revoking a certificate] Next, the invalidation of the third certificate held by vehicle 2001 and server 2600 according to the autonomous driving level will be described with reference to Fig. 19. Note that the same steps as those in the first embodiment will be assigned the same numbers, and the description will be omitted.
[0145] FIG. 19 is a sequence diagram showing an example of an operation for revoking a public key certificate (third certificate) according to the second embodiment.
[0146] Vehicle 2001 determines whether the error counter is equal to or greater than the threshold value (S2304), and if the error counter is equal to or greater than the threshold value (Y in S2304), vehicle 2001 notifies server 2600 of the issued public key certificate (third certificate) and issues an invalidation instruction to invalidate the third certificate in server 2600. If the error counter does not exceed the threshold value (N in S2304), the process returns to S1302.
[0147] If the error counter is equal to or greater than the threshold value (Y in S2304), vehicle 2001 and server 2600 each invalidate the third certificate held by them (S2305). For example, certificate management unit 2304 in communication ECU 2300 of vehicle 2001 invalidates the third certificate by deleting the third certificate stored in authentication information holding unit 1303. Furthermore, certificate management unit 2604 of server 2600 invalidates the third certificate by deleting the third certificate stored in authentication information holding unit 2603. Furthermore, certificate management unit 2604 changes the status of the third certificate in the certificate table to "invalid."
[0148] As described above, in the second embodiment, the autonomous driving system 2000 includes the server 2600, and the third certificate is sent from the server 2600 to the vehicle 2001 when device authentication is performed.
[0149] [2.7 Effects of the Second Embodiment] In the autonomous driving system 2000 shown in the second embodiment, a third certificate, which is separate from the first certificate of the vehicle 2001 and the second certificate of the external device 1002, is issued by the server 2600, and the issued third certificate is managed within the vehicle 2001. Then, by switching between validity and invalidity of the third certificate based on the results of communication between the vehicle 2001 and the external device 1002, it is possible to determine an appropriate autonomous driving level when the vehicle 2001 and the external device 1002 operate together, and it is possible to ensure safety.
[0150] (Modification of the second embodiment) In the automated driving system 2000 shown in the second embodiment, the third certificate can be validated or invalidated at any time, but the timing of validation or invalidation may be controlled depending on the traveling state of the vehicle 2001. This will be described as a modified example of the second embodiment. Note that a description of the same points as those in the second embodiment will be omitted.
[0151] [2.8 Example of a sequence for issuing a certificate] 20 is a sequence diagram showing an example of the operation of issuing a public key certificate (third certificate) in a variation of the second embodiment. In the variation of the second embodiment, the third certificate is issued when the traveling state of the vehicle 2001 satisfies certain conditions. Note that steps similar to those in the second embodiment are given the same numbers and descriptions thereof will be omitted.
[0152] For example, the traveling state of vehicle 2001 that satisfies a specific condition is that the vehicle is stopped, and before starting the process to validate the third certificate, vehicle 2001 determines whether the traveling state of vehicle 2001 is stopped (S2206). If vehicle 2001 is not stopped (N in S2206), it does not start the process to validate the third certificate and ends the process. If vehicle 2001 is stopped (Y in S2206), it starts the process to validate the third certificate.
[0153] [2.9 Example of sequence for revoking a certificate] 21 is a sequence diagram showing an example of the operation of revoking a public key certificate (third certificate) in a variation of the second embodiment. In the variation of the second embodiment, when the traveling state of the vehicle 2001 satisfies a specific condition, the states (e.g., communication state) of the vehicle 2001 and the external device 1002 are monitored, and the third certificate is revoked according to the communication state. Note that steps similar to those in the first and second embodiments are given the same numbers, and descriptions thereof will be omitted.
[0154] Vehicle 2001 determines whether vehicle 2001 is currently stopped (S2308). If vehicle 2001 is not currently stopped (N in S2308), vehicle 2001 suspends and terminates the invalidation process of the third certificate, and if vehicle 2001 is currently stopped (Y in S2308), vehicle 2001 monitors the communication status (S1301) and continues the invalidation process.
[0155] [2.10 Effects of the Modification of the Second Embodiment] In the autonomous driving system 2000 shown in the second embodiment, a third certificate, which is separate from the first certificate of the vehicle 2001 and the second certificate of the external device 1002, is issued by the server 2600, and the issued third certificate is managed within the vehicle 2001. Then, by switching between validity and invalidity of the third certificate based on the driving state of the vehicle 2001 as well as the communication result between the vehicle 2001 and the external device 1002, it is possible to determine an appropriate autonomous driving level when the vehicle 2001 and the external device 1002 operate together, and it is possible to ensure safety.
[0156] (Embodiment 3) [3. System Configuration] Next, an autonomous driving system 3000 will be described as a third embodiment of the present disclosure with reference to the drawings.
[0157] [3.1 Overall configuration of Autonomous Driving System 3000] FIG. 22 is a diagram illustrating an example of the overall configuration of an autonomous driving system 3000 according to the third embodiment.
[0158] The autonomous driving system 3000 is composed of a vehicle 3001, an external device 3002 that is connected to and operates with the vehicle 3001, and a server 2600 that communicates with the external device 3002 via V2X.
[0159] The same components as those in the first and second embodiments are given the same numbers, and the description thereof will be omitted.
[0160] For example, vehicle 3001 is composed of ECUs 1100a, 1100b, 1100c, and 1100d, which are connected via various in-vehicle networks; a camera 1010, a brake 1011, a steering wheel 1012, and an accelerator 1013, which are controlled by each ECU; an autonomous driving ECU 1200, which communicates with each of ECUs 1100a to 1100d to perform control related to autonomous driving; and a communication ECU 3300, which communicates with autonomous driving ECU 1200 via the in-vehicle networks.
[0161] The communication ECU 3300 communicates with the external device 3002 and transmits and receives messages to and from the external device 3002 and other ECUs in the vehicle 3001 .
[0162] For example, the external device 3002 is composed of an ECU 1100e, a Lidar 1014 that is controlled by the ECU 1100e, a communication ECU 3400 that communicates with the ECU 1100e and the V2X communication ECU 2500 via an in-vehicle network, and the V2X communication ECU 2500 that communicates with the server 2600 via V2X.
[0163] The communication ECU 3400 communicates with the vehicle 3001 and transmits and receives messages to and from other ECUs in the vehicle 3001 and the external device 3002. The communication ECU 3400 also communicates with the server 2600 via the V2X communication ECU 2500 and transmits and receives messages required to validate a public key certificate (third certificate) corresponding to a new autonomous driving level when the external device 3002 is installed in the vehicle 3001.
[0164] [3.2 Configuration diagram of the communication ECU 3300 on the vehicle 3001 side] FIG. 23 is a diagram illustrating an example of the configuration of a communication ECU 3300 on the vehicle 3001 side according to the third embodiment.
[0165] For example, the communication ECU 3300 includes a communication unit 3301, an authentication processing unit 3302, and an authentication information holding unit 1303. Note that the same components as those in the first embodiment are given the same reference numerals, and the following description will be omitted.
[0166] The communication unit 3301 communicates with the external device 3002. For example, the communication unit 3301 communicates with the external device 3002 via a wired connection. The communication unit 3301 also communicates with the autonomous driving ECU 1200 in the vehicle 3001 via an in-vehicle network. The communication unit 3301 notifies the authentication processing unit 3302 of a communication message received from the external device 3002. The communication unit 3301 also receives a notification from the authentication processing unit 3302 and transmits the communication message to the external device 3002.
[0167] The authentication processing unit 3302 communicates with the external device 3002 via the communication unit 3301 and performs authentication processing for the external device 3002. The authentication processing unit 3302 also obtains information required for the authentication processing from the authentication information holding unit 1303.
[0168] [3.3 Configuration diagram of communication ECU 3400 on external device 3002 side] FIG. 24 is a diagram illustrating an example of the configuration of a communication ECU 3400 on the external device 3002 side according to the third embodiment.
[0169] The communication ECU 3400 includes a communication unit 3401, an authentication processing unit 3402, an authentication information holding unit 1403, and a certificate management unit 3404. The communication ECU 3400 is an example of an authentication device included in the external device 3002 in the autonomous driving system 3000. Note that the same components as those in the first embodiment are given the same numbers, and the following description will be omitted.
[0170] The communication unit 3401 communicates with the vehicle 3001. For example, the communication unit 3401 communicates with the vehicle 3001 via a wired connection. The communication unit 3401 also communicates with the ECU 1100e in the external device 3002 and the V2X communication ECU 2500 via an in-vehicle network. The communication unit 3401 notifies the authentication processing unit 3402 and the certificate management unit 3404 of communication messages received from the vehicle 3001 and the server 2600. The communication unit 3401 also receives notifications from the authentication processing unit 3402 and the certificate management unit 3404, and transmits communication messages to the vehicle 3001 and the server 2600.
[0171] The authentication processing unit 3402 communicates with the vehicle 3001 via the communication unit 3401 and performs authentication processing for the vehicle 3001. The authentication processing unit 3402 is an example of an authentication unit that authenticates the vehicle 3001 using a first certificate for proving the legitimacy of the vehicle 3001. The authentication processing unit 3402 also acquires information required for the authentication processing from the authentication information holding unit 1403. The authentication processing unit 3402 also notifies the certificate management unit 3404 of the result of the authentication processing.
[0172] The certificate management unit 3404 is an example of a management unit that validates a third certificate using the result of authentication by the authentication processing unit 3402. The certificate management unit 3404 uses the authentication result notified from the authentication processing unit 3402 to obtain a public key certificate (third certificate) corresponding to a new autonomous driving level issued by the server 2600 from the server 2600 via the communication unit 3401, and stores the third certificate in the authentication information holding unit 1403. As a result, the third certificate is registered in the authentication information holding unit 1403, and the third certificate is validated on the external device 3002 side. Furthermore, the certificate management unit 3404 deletes the third certificate from the authentication information holding unit 1403 based on the communication processing result from the communication unit 3401. As a result, the registration of the third certificate in the authentication information holding unit 1403 is cancelled, and the third certificate that had been validated on the external device 3002 side is invalidated.
[0173] [3.4 Example of a sequence for issuing a certificate] Next, the issuance of a third certificate by the server 2600 according to the autonomous driving level, which is performed after mutual authentication between the vehicle 3001 and the external device 3002, will be described with reference to Fig. 25. The third certificate issued by the server 2600 is stored and validated in the external device 3002.
[0174] FIG. 25 is a sequence diagram showing an example of an operation for issuing a public key certificate (third certificate) in the third embodiment.
[0175] The external device 3002 determines whether or not it can acquire a registered vehicle ID (S3201). If there is no registered vehicle ID, the external device 3002 cannot acquire the vehicle ID (N in S3201), which means that the authentication process has not been completed, and therefore ends the process. Here, it is assumed that the authentication process in FIG. 8 has been completed and the vehicle ID has been registered.
[0176] If the external device 3002 is able to acquire the vehicle ID of the vehicle 3001 (Y in S3201), it transmits the acquired vehicle ID to the server 2600 along with the device ID of the external device 3002, the public key certificate (first certificate) of the vehicle 3001, and the public key certificate (second certificate) of the external device 3002.
[0177] The server 2600 receives the device ID of the external device 3002, the vehicle ID of the vehicle 3001, and the two types of public key certificates, and verifies the signatures of the received two types of public key certificates (S3202). If the verification is not successful (N in S3202), the server 2600 notifies the external device 3002 of an error and ends the processing.
[0178] If the verification is successful (Y in S3202), the server 2600 checks whether the combination of the device ID and vehicle ID received in S3202 exists in the certificate table (S3203). If the combination of the received device ID and vehicle ID does not exist in the certificate table (N in S3203), the server 2600 notifies the external device 3002 of this fact and terminates the process as an error.
[0179] If the combination of the received device ID and vehicle ID exists in the certificate table (Y in S3203), the server 2600 issues a third certificate corresponding to the acquired combination and transmits it to the external device 3002 (S3204).
[0180] The external device 3002 stores the third certificate issued by the server 2600 (S3205). For example, the third certificate is stored in the authentication information storage unit 1403 in the communication ECU 3400 of the external device 3002, and thereby the third certificate is also validated on the external device 3002 side.
[0181] Furthermore, although not shown, the server 2600 outputs information relating to the autonomous driving level of the entire autonomous driving system 3000 when the vehicle 3001 and the external device 3002 are combined, which corresponds to the validated third certificate. Note that the external device 3002 (e.g., the communication unit 3401) may output information relating to the autonomous driving level of the entire autonomous driving system 3000 when the vehicle 3001 and the external device 3002 are combined, which corresponds to the validated third certificate.
[0182] [3.5 Example of a sequence for revoking a certificate] Next, invalidation of the third certificate according to the autonomous driving level held by the external device 3002 and the server 2600 will be described with reference to FIG.
[0183] FIG. 26 is a sequence diagram showing an example of an operation for revoking a public key certificate (third certificate) according to the third embodiment.
[0184] The external device 3002 monitors the communication status with the vehicle 3001 (S3301).
[0185] The external device 3002 determines whether or not an abnormality has occurred in the state of communication with the vehicle 3001 (S3302). If no abnormality has occurred in communication (N in S3302), the external device 3002 ends the process.
[0186] If a communication error occurs (Y in S3302), the external device 3002 increments the error counter (S3303).
[0187] The external device 3002 determines whether the error counter is equal to or greater than the threshold value (S3304), and if the error counter is equal to or greater than the threshold value (Y in S3304), it notifies the server 2600 of the issued public key certificate (third certificate) and issues an invalidation instruction to invalidate the third certificate in the server 2600. If the error counter does not exceed the threshold value (N in S3304), the process returns to S3302.
[0188] If the error counter is equal to or greater than the threshold value (Y in S3304), the external device 3002 and the server 2600 invalidate the third certificate held by each of them (S3305). For example, the certificate management unit 3404 in the communication ECU 3400 of the external device 3002 invalidates the third certificate by deleting the third certificate stored in the authentication information holding unit 1403.
[0189] The external device 3002 resets the error counter (S3306).
[0190] The external device 3002 deletes the vehicle ID of the connection destination (S3307).
[0191] As described above, in the third embodiment, the autonomous driving system 3000 includes the server 2600, and the third certificate is sent from the server 2600 to the external device 3002 when device authentication is performed.
[0192] [3.6 Effects of the Third Embodiment] In the autonomous driving system 3000 shown in the third embodiment, a third certificate separate from the first certificate of the vehicle 3001 and the second certificate of the external device 3002 is issued by the server 2600, and the issued third certificate is managed within the external device 3002. Then, by switching between validity and invalidity of the third certificate based on the results of communication between the vehicle 3001 and the external device 3002, it is possible to determine an appropriate autonomous driving level when the vehicle 3001 and the external device 3002 operate together, and it is possible to ensure safety.
[0193] (Modification of the third embodiment) In the autonomous driving system 3000 shown in the third embodiment, the third certificate can be validated or invalidated at any time, but the timing of validation or invalidation may be controlled depending on the traveling state of the vehicle 3001. This will be described as a modified example of the third embodiment. Note that a description of the same points as those in the third embodiment will be omitted.
[0194] [3.7 Example of a sequence for issuing a certificate] 27 is a sequence diagram showing an example of the operation of issuing a public key certificate (third certificate) in a variation of the third embodiment. In the variation of the third embodiment, the third certificate is issued when the traveling state of the vehicle 3001 satisfies certain conditions. Note that steps similar to those in the third embodiment are given the same numbers and descriptions thereof will be omitted.
[0195] For example, the traveling state of the vehicle 3001 that satisfies a specific condition is stopped, and the external device 3002 determines whether the traveling state of the vehicle 3001 is stopped or not before starting the process to validate the third certificate (S3206). If the vehicle 3001 is not stopped (N in S3206), the external device 3002 does not start the process to validate the third certificate and ends the process. If the vehicle 3001 is stopped (Y in S3206), the external device 3002 starts the process to validate the third certificate.
[0196] [3.8 Example of a sequence for revoking a certificate] 28 is a sequence diagram showing an example of the operation of revoking a public key certificate (third certificate) in a variation of the third embodiment. In the variation of the third embodiment, when the traveling state of the vehicle 3001 satisfies a specific condition, the states (e.g., communication state) of the vehicle 3001 and the external device 3002 are monitored, and the third certificate is revoked according to the communication state. Note that steps similar to those in the third embodiment are given the same numbers, and descriptions thereof will be omitted.
[0197] The external device 3002 determines whether the vehicle 3001 is stopped (S3308). If the vehicle 3001 is not stopped (N in S3308), the external device 3002 suspends and terminates the invalidation process of the third certificate, and if the vehicle 3001 is stopped (Y in S3308), the external device 3002 monitors the communication status (S3301) and continues the invalidation process.
[0198] [3.9 Effects of the Modification of the Third Embodiment] In the autonomous driving system 3000 shown in the third embodiment, a third certificate separate from the first certificate of the vehicle 3001 and the second certificate of the external device 3002 is issued by the server 2600, and the issued third certificate is managed within the external device 3002. Then, by switching between validating and invalidating the third certificate based on the driving state of the vehicle 3001 as well as the communication results between the vehicle 3001 and the external device 3002, it is possible to determine an appropriate autonomous driving level when the vehicle 3001 and the external device 3002 operate together, and it is possible to ensure safety.
[0199] (Other variations) Although the present disclosure has been described based on the above-described embodiments, it goes without saying that the present disclosure is not limited to the above-described embodiments. The following cases are also included in the present disclosure.
[0200] (1) In the above embodiment, Ethernet and CAN protocols are used for the in-vehicle network, but the present invention is not limited to these. For example, CAN-FD (CAN with Flexible Data Rate), LIN (Local Interconnect Network), or MOST (Media Oriented Systems Transport), etc. may be used for the in-vehicle network. Alternatively, the in-vehicle network may have a network configuration in which these networks are combined as sub-networks.
[0201] (2) In the above-described embodiments, the newly validated third certificate is managed either on the vehicle side or on the external device side, but the present invention is not limited to this example. Both the vehicle side and the external device side may have the same third certificate, or the types of certificates held by the vehicle side or the external device side may be differentiated depending on the purpose.
[0202] (3) In the above-described embodiment, an example is described in which the communication ECU responsible for communication between the vehicle and the external device includes a certificate management unit that performs authentication processing and certificate management, but this configuration is not limited to this. The certificate management unit may be included in a separate ECU dedicated to certificate management, or may be included in the autonomous driving ECU or another ECU. Furthermore, in the above-described second and third embodiments, the V2X communication ECU may include a certificate management unit.
[0203] (4) In the above embodiment, the communication ECU determines the abnormality, but this configuration is not limited to this. Alternatively, communication contents may be mirrored to another ECU, and the other ECU may determine the abnormality. Furthermore, the other ECU may be physically or logically separate from the communication ECU. For example, a virtual environment may be created on a multifunction ECU such as a central gateway, zone ECU, or domain controller, and an application that monitors the communication status may be provided on one of the virtual operating systems (hereinafter, referred to as OS). Alternatively, a similar virtual environment may be created on the communication ECU, and the communication status may be monitored from an OS other than the OS responsible for communication.
[0204] (5) In the above embodiment, the state of communication between the vehicle and the external device is taken as an example of the state of the vehicle and the external device, but this is not limiting. For example, in the third embodiment, if a failure occurs in the external device itself, the external device may detect this and notify the vehicle or the server.
[0205] (6) In the above-mentioned second and third embodiments, the server plays the role of a certification authority that issues a new public key certificate (third certificate), but this configuration is not limited to this. For example, the server may obtain a certificate issued by another certification authority in advance, store it, and send it to the vehicle or external device at the appropriate time.
[0206] (7) In the above embodiment, the certificate table is used to determine the combination of a vehicle and an external device and to determine the autonomous driving level, but the autonomous driving level of the entire autonomous driving system after the combination may be pre-installed in the certificate. In other words, information similar to the certificate table may already be installed in the certificate, and the autonomous driving level of the entire autonomous driving system may be determined without referencing the certificate table.
[0207] (8) In the modified example of the above embodiment, the vehicle's driving state is determined, but this determination may be made by a specific ECU, and other ECUs may acquire the driving state via an in-vehicle network, or each ECU may determine the driving state independently. Furthermore, in addition to driving states such as driving, stopped, or parked, other states such as accessories ON, ignition ON, driving at low speed or high speed, etc. may also be determined.
[0208] (9) In the above-described modified example of the embodiment, the third certificate is validated only when the vehicle is stopped. However, the present invention is not limited to this. For example, the third certificate may be validated only when the vehicle is parked or in a specific driving state other than when the vehicle is stopped. Even when the vehicle is parked, the third certificate may be validated only when the ignition is not turned on. Furthermore, the third certificate may be validated when the driving state changes, such as when the vehicle is moving and then stopped, or when the vehicle is parked and then parked.
[0209] (10) In the above-described modified example of the embodiment, the third certificate is invalidated only when the vehicle is stopped. However, the present invention is not limited to this. For example, the third certificate may be invalidated only when the vehicle is parked or in a specific driving state other than when the vehicle is stopped. Furthermore, the third certificate may be invalidated when the driving state changes, such as when the vehicle goes from stopped to driving, or from low-speed driving to high-speed driving.
[0210] (11) In the modified example of the above embodiment, the third certificate is invalidated, i.e., the autonomous driving level is changed, based on the communication result. However, the driver may be notified of the change at the timing of the change. The notification may be sent to an ECU having a display device, such as an infotainment system or a speedometer, and a pop-up display or icon may be displayed for the driver at the timing of the change, or these may be deleted or changed.
[0211] (12) Each device and system in the above embodiments is specifically a computer system comprising a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is recorded in the RAM or hard disk unit. Each device and system achieves its function when the microprocessor operates in accordance with the computer program. Here, a computer program is composed of a combination of multiple instruction codes that indicate commands to a computer to achieve a predetermined function.
[0212] (13) In each of the devices and systems in the above embodiments, some or all of the constituent elements may be configured from a single system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured to include a microprocessor, ROM, RAM, etc. A computer program is stored in the RAM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.
[0213] Furthermore, each of the components constituting each of the above-described devices and systems may be individually implemented as a single chip, or some or all of them may be integrated into a single chip.
[0214] System LSIs are also called ICs, LSIs, super LSIs, or ultra LSIs depending on their level of integration. The integration method is not limited to LSIs; it can also be realized using dedicated circuits or general-purpose processors. It is also possible to use FPGAs (Field Programmable Gate Arrays), which can be programmed after LSI manufacturing, or reconfigurable processors, which allow the connections and settings of circuit cells within LSIs to be reconfigured.
[0215] Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or other derivative technologies, it is natural that such technology may be used to integrate functional blocks. The application of biotechnology, etc. is also a possibility.
[0216] (14) Some or all of the components constituting each of the above devices may be configured as an IC card or a standalone module that can be attached to each device. The IC card or module is a computer system consisting of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned ultra-multifunctional LSI. The IC card or module achieves its functions when the microprocessor operates according to a computer program. This IC card or module may be tamper-resistant.
[0217] (15) The present disclosure may be an authentication method.
[0218] For example, the authentication method is a method for an autonomous driving system including a vehicle and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving. The vehicle holds a first certificate for verifying the legitimacy of the vehicle, and the external device holds a second certificate for verifying the legitimacy of the external device. The authentication method is executed by a computer and includes processing (e.g., S1201 to S1203 in FIG. 9 ) of validating a third certificate for verifying the legitimacy of the combination of the vehicle and the external device based on a result of device authentication between the vehicle and the external device using the first certificate and the second certificate.
[0219] Furthermore, the present disclosure may be a computer program that implements the authentication method on a computer, or may be a digital signal that comprises a computer program.
[0220] The present disclosure may also be realized as a computer program or a digital signal recorded on a computer-readable non-transitory recording medium, such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), or a semiconductor memory. The present disclosure may also be realized as a digital signal recorded on such a recording medium.
[0221] The present disclosure may also be applied to transmitting a computer program or a digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, or data broadcasting.
[0222] The present disclosure may also be a computer system having a microprocessor and a memory, the memory storing the computer program, and the microprocessor operating in accordance with the computer program.
[0223] Furthermore, the program or digital signal may be implemented by another independent computer system by recording the program or digital signal on a recording medium and transferring it, or by transferring the program or digital signal via a network or the like.
[0224] (16) The above-described embodiments and modifications may be combined with each other. [Industrial Applicability]
[0225] The present disclosure can be applied to an autonomous driving system that includes a vehicle and an external device that communicates with the vehicle and provides functions for the vehicle to perform autonomous driving. [Explanation of symbols]
[0226] 1000, 2000, 3000 Autonomous Driving Systems 1001, 2001, 3001 vehicles 1002, 3002 External device 1010 Camera 1011 Brake 1012 Handle 1013 Axel 1014 Lidar 1100a, 1100b, 1100c, 1100d, 1100e ECU 1101, 1201, 1301, 1401, 2301, 2501, 2601, 3301, 3401 Communications Department 1102, 2502 Message conversion unit 1200 Autonomous Driving ECU 1202 Judgment Department 1203 Autonomous Driving Level Management Department 1300, 1400, 2300, 3300, 3400 Communication ECU 1302, 1402, 2602, 3302, 3402 Authentication processing section 1303, 1403, 2603 Authentication information storage unit 1304, 2304, 2604, 3404 Certificate Management Department 1305, 2605 Certificate Holder 2500 V2X communication ECU 2600 Server
Claims
1. Vehicles and An external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving, The vehicle holds a first certificate for verifying the authenticity of the vehicle; the external device holds a second certificate for verifying the authenticity of the external device; the authentication method includes validating a third certificate for verifying the validity of a combination of the vehicle and the external device based on a result of device authentication between the vehicle and the external device using the first certificate and the second certificate; outputting information relating to the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, the information corresponding to the validated third certificate; moreover, monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, In the revocation of the third certificate, when a failure occurs in the external device, the third certificate is revoked. Authentication method.
2. Vehicles and An external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving, The vehicle holds a first certificate for verifying the authenticity of the vehicle; the external device holds a second certificate for verifying the authenticity of the external device; the authentication method includes validating a third certificate for verifying the validity of a combination of the vehicle and the external device based on a result of device authentication between the vehicle and the external device using the first certificate and the second certificate; the third certificate is issued when the vehicle is manufactured and is pre-installed in the vehicle; moreover, monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, In the revocation of the third certificate, when a failure occurs in the external device, the third certificate is revoked. Authentication method.
3. Vehicles and An external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving, The vehicle holds a first certificate for verifying the authenticity of the vehicle; the external device holds a second certificate for verifying the authenticity of the external device; the authentication method includes validating a third certificate for verifying the validity of a combination of the vehicle and the external device based on a result of device authentication between the vehicle and the external device using the first certificate and the second certificate; The autonomous driving system further includes a server. the third certificate is sent from the server to the vehicle or the external device when the device authentication is performed; moreover, monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, In the revocation of the third certificate, when a failure occurs in the external device, the third certificate is revoked. Authentication method.
4. and validating the third certificate by validating the third certificate corresponding to at least one of a vehicle ID of the vehicle and a device ID of the external device obtained as a result of the device authentication. The authentication method according to any one of claims 1 to 3.
5. the validation of the third certificate includes validating the third certificate when a driving state of the vehicle satisfies a specific condition; The authentication method according to any one of claims 1 to 4.
6. The running state of the vehicle that satisfies the specific condition is that the vehicle is stopped. The authentication method according to claim 5.
7. Vehicles and An external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving, The vehicle holds a first certificate for verifying the authenticity of the vehicle; the external device holds a second certificate for verifying the authenticity of the external device; The authentication system includes a management unit that validates a third certificate for verifying the validity of a combination of the vehicle and the external device based on a result of device authentication between the vehicle and the external device using the first certificate and the second certificate; an output unit that outputs information related to the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, the information corresponding to the validated third certificate; The management unit further monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, The management unit invalidates the third certificate when a failure occurs in the external device. Authentication system.
8. Vehicles and An external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving, The vehicle holds a first certificate for verifying the authenticity of the vehicle; the external device holds a second certificate for verifying the authenticity of the external device; the authentication system includes a management unit that validates a third certificate for verifying the validity of a combination of the vehicle and the external device based on a result of device authentication between the vehicle and the external device using the first certificate and the second certificate; the third certificate is issued when the vehicle is manufactured and is pre-installed in the vehicle; The management unit further monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, The management unit invalidates the third certificate when a failure occurs in the external device. Authentication system.
9. Vehicles and An external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving, The vehicle holds a first certificate for verifying the authenticity of the vehicle; the external device holds a second certificate for verifying the authenticity of the external device; the authentication system includes a management unit that validates a third certificate for verifying the validity of a combination of the vehicle and the external device based on a result of device authentication between the vehicle and the external device using the first certificate and the second certificate; The autonomous driving system further includes a server. the third certificate is sent from the server to the vehicle or the external device when the device authentication is performed; The management unit further monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, The management unit invalidates the third certificate when a failure occurs in the external device. Authentication system.
10. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving; The authentication device a storage unit that stores a first certificate for verifying the authenticity of the vehicle; an authentication unit that authenticates the external device using a second certificate that proves the authenticity of the external device; a management unit that uses a result of the authentication to validate a third certificate for verifying the validity of a combination of the vehicle and the external device; an output unit that outputs information related to the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, the information corresponding to the validated third certificate; The management unit further monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, The management unit invalidates the third certificate when a failure occurs in the external device. Authentication device.
11. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving; The authentication device a storage unit that stores a first certificate for verifying the authenticity of the vehicle; an authentication unit that authenticates the external device using a second certificate that proves the authenticity of the external device; a management unit that uses a result of the authentication to validate a third certificate for verifying the validity of a combination of the vehicle and the external device; the third certificate is issued when the vehicle is manufactured and is pre-installed in the vehicle; The management unit further monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, The management unit invalidates the third certificate when a failure occurs in the external device. Authentication device.
12. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving; The authentication device a storage unit that stores a first certificate for verifying the authenticity of the vehicle; an authentication unit that authenticates the external device using a second certificate that proves the authenticity of the external device; a management unit that uses a result of the authentication to validate a third certificate for verifying the validity of a combination of the vehicle and the external device; The autonomous driving system further includes a server. the third certificate is sent from the server when the authentication is performed; The management unit further monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, The management unit invalidates the third certificate when a failure occurs in the external device. Authentication device.
13. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving, The vehicle holds a first certificate for verifying the authenticity of the vehicle; The authentication method includes: authenticating the external device using a second certificate for verifying the authenticity of the external device; using a result of the authentication to validate a third certificate for verifying the validity of the combination of the vehicle and the external device; outputting information relating to the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, the information corresponding to the validated third certificate; moreover, monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, In the revocation of the third certificate, when a failure occurs in the external device, the third certificate is revoked. Authentication method.
14. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving, The vehicle holds a first certificate for verifying the authenticity of the vehicle; The authentication method includes: authenticating the external device using a second certificate for verifying the authenticity of the external device; using a result of the authentication to validate a third certificate for verifying the validity of the combination of the vehicle and the external device; the third certificate is issued when the vehicle is manufactured and is pre-installed in the vehicle; moreover, monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, In the revocation of the third certificate, when a failure occurs in the external device, the third certificate is revoked. Authentication method.
15. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving, The vehicle holds a first certificate for verifying the authenticity of the vehicle; The authentication method includes: authenticating the external device using a second certificate for verifying the authenticity of the external device; using a result of the authentication to validate a third certificate for verifying the validity of the combination of the vehicle and the external device; The autonomous driving system further includes a server. the third certificate is sent from the server when the authentication is performed; moreover, monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, In the revocation of the third certificate, when a failure occurs in the external device, the third certificate is revoked. Authentication method.
16. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving; and an authentication device provided in the external device in an autonomous driving system, The authentication device a storage unit that stores a second certificate for verifying the authenticity of the external device; an authentication unit that authenticates the vehicle using a first certificate for verifying the authenticity of the vehicle; and, a management unit that uses a result of the authentication to validate a third certificate for verifying the validity of a combination of the vehicle and the external device; an output unit that outputs information related to the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, the information corresponding to the validated third certificate; The management unit further monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, The management unit invalidates the third certificate when a failure occurs in the external device. Authentication device.
17. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving; and an authentication device provided in the external device in an autonomous driving system, The authentication device a storage unit that stores a second certificate for verifying the authenticity of the external device; an authentication unit that authenticates the vehicle using a first certificate that proves the legitimacy of the vehicle; a management unit that uses a result of the authentication to validate a third certificate for verifying the validity of a combination of the vehicle and the external device; the third certificate is issued when the vehicle is manufactured and is pre-installed in the vehicle; The management unit further monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, The management unit invalidates the third certificate when a failure occurs in the external device. Authentication device.
18. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving; and an authentication device provided in the external device in an autonomous driving system, The authentication device a storage unit that stores a second certificate for verifying the authenticity of the external device; an authentication unit that authenticates the vehicle using a first certificate that proves the legitimacy of the vehicle; a management unit that uses a result of the authentication to validate a third certificate for verifying the validity of a combination of the vehicle and the external device; The autonomous driving system further includes a server. the third certificate is sent from the server when the authentication is performed; The management unit further monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, The management unit invalidates the third certificate when a failure occurs in the external device. Authentication device.
19. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving; The external device is maintaining a second certificate for verifying the authenticity of the external device; The authentication method includes: authenticating the vehicle using a first certificate to verify the authenticity of the vehicle; using a result of the authentication to validate a third certificate for verifying the validity of the combination of the vehicle and the external device; outputting information relating to the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, the information corresponding to the validated third certificate; moreover, monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, In the revocation of the third certificate, when a failure occurs in the external device, the third certificate is revoked. Authentication method.
20. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving; The external device is maintaining a second certificate for verifying the authenticity of the external device; The authentication method includes: authenticating the vehicle using a first certificate to verify the authenticity of the vehicle; using a result of the authentication to validate a third certificate for verifying the validity of the combination of the vehicle and the external device; the third certificate is issued when the vehicle is manufactured and is pre-installed in the vehicle; moreover, monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, In the revocation of the third certificate, when a failure occurs in the external device, the third certificate is revoked. Authentication method.
21. Vehicles and an external device that communicates with the vehicle and provides a function for the vehicle to perform autonomous driving; The external device is maintaining a second certificate for verifying the authenticity of the external device; The authentication method includes: authenticating the vehicle using a first certificate to verify the authenticity of the vehicle; using a result of the authentication to validate a third certificate for verifying the validity of the combination of the vehicle and the external device; The autonomous driving system further includes a server. the third certificate is sent from the server when the authentication is performed; moreover, monitor the status of the vehicle and the external device; revoke the third certificate in response to the change in status; the state is a state of the external device, In the revocation of the third certificate, when a failure occurs in the external device, the third certificate is revoked. Authentication method.