Setting device, communication system, and vehicle communication management method

The setting device and method facilitate secure, flexible network construction in in-vehicle systems by allowing new functional units to communicate with existing units via relay devices, simplifying the setup process.

JP2025179220APending Publication Date: 2025-12-09SUMITOMO ELECTRIC INDUSTRIES LTD +2
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2025154773
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2019-05-30
Filing Date
2025-09-18
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

Existing in-vehicle network systems lack the capability to flexibly construct networks with new configurations while ensuring security through simple processing.

Method used

A setting device and method that acquires authentication results for new functional units added to the network, allowing them to communicate with existing units via relay devices, and configures the network using stored setting information to ensure secure communication.

Benefits of technology

Enables flexible network construction with new configurations while maintaining security by omitting unnecessary authentication processing for new functional units, simplifying the setup process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025179220000001_ABST
    Figure 2025179220000001_ABST
Patent Text Reader

Abstract

To provide a setting device, a communication system, and a vehicle communication management method that flexibly construct a newly configured network through simple processing while securing security of the network.SOLUTION: A repeating device 100A comprises: an authentication result acquisition part which acquires an authentication result of a new functional part (on-vehicle ECU 111E) as a functional part added newly to an on-vehicle network including one or more functional parts; and a setting part which performs setting processing related to at least one of a plurality of repeating devices, existent functional parts, and the new functional part for communication between the existent functional parts being functional parts included in the on-vehicle network before the new functional part is added and the new functional part through the repeating devices capable of repeating information among the functional parts when the authentication result acquired by the authentication result acquisition part is affirmative.SELECTED DRAWING: Figure 11
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a setting device, a communication system, and a vehicle communication management method. This application claims priority based on Japanese Patent Application No. 2019-101427, filed on May 30, 2019, the disclosure of which is incorporated herein in its entirety. [Background technology]

[0002] Patent Document 1 (Japanese Patent Laid-Open Publication No. 2008-59450) discloses the following vehicle information rewriting system. That is, the vehicle information rewriting system has a main control unit consisting of a CPU, and a rewriting tool functioning as a data source is detachably connected via communication means to a vehicle control unit that performs control processing of electronic devices mounted on an automobile based on the execution of predetermined software by the main control unit, and the vehicle information rewriting system rewrites the memory contents of a vehicle information storage unit that is provided as a non-volatile memory on the vehicle control unit side and stores vehicle information including the software based on rewriting data transferred from the rewriting tool via the communication means, and is characterized in that the vehicle information rewriting system is provided with: operation mode switching means for switching between a rewrite permission mode in which rewriting of the memory contents of the vehicle information storage unit is permitted and a rewrite restriction mode in which the rewriting operation is more restricted than in the rewrite permission mode; wireless polling means for wirelessly polling a wireless authentication medium to detect a wireless authentication medium that should be attached to a person qualified to use the rewriting tool during rewriting work using the rewriting tool; and mode switching command means for commanding the operation mode switching means to switch to the rewrite permission mode, on the condition that the wireless authentication medium is successfully detected by the wireless polling.

[0003] Also, Patent Document 2 (Japanese Patent Laid-Open Publication No. 2003-46536) discloses the following vehicular relay device: That is, the vehicular relay device is arranged between an in-vehicle LAN constructed in a vehicle and a communication device that performs data communication with an external device, and relays communication between the external device connected via the communication device and various in-vehicle electronic devices connected to the in-vehicle LAN, and when an access request to an in-vehicle electronic device in the in-vehicle LAN is made from an external device, the vehicular relay device identifies the access destination and, based on the identification result, determines whether the access request is an access request to the in-vehicle electronic device that requires authentication of the external device; and a first distribution means for distributing communication data transmitted from the external device via the communication device to the in-vehicle electronic device to be accessed when the first authentication means determines that the external device making the access request is an external device that has been previously authorized to access the in-vehicle electronic device, or when the first identification means determines that the access request does not require authentication of the external device. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2008-59450 [Patent Document 2] Japanese Patent Application Laid-Open No. 2003-46536 Summary of the Invention

[0005] The setting device disclosed herein includes an acquisition unit that acquires an authentication result of a new functional unit that is a functional unit newly added to an in-vehicle network that includes one or more functional units, and a setting unit that, if the authentication result acquired by the acquisition unit is positive, is capable of performing setting processing for at least one of an existing functional unit that is a functional unit included in the in-vehicle network before the new functional unit was added, and the new functional unit, so that the new functional unit can communicate with the existing functional unit via a plurality of relay devices that can relay information between the functional units.

[0006] The communication system disclosed herein comprises a setting device and a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units, wherein the setting device acquires information transmitted from the new functional unit that can identify the functional unit with which the new functional unit is to communicate, the setting device acquires an authentication result for the new functional unit, and if the acquired authentication result is positive, the setting device transmits to the new functional unit setting information that enables the new functional unit to communicate with an existing functional unit that is a functional unit included in the in-vehicle network before the new functional unit was added via a plurality of relay devices that can relay information between the functional units, and the new functional unit configures itself based on the setting information received from the setting device.

[0007] The vehicle communication management method disclosed herein is a vehicle communication management method in a setting device, and includes the steps of: acquiring an authentication result for a new functional unit, which is a functional unit newly added to an in-vehicle network including one or more functional units; and, if the acquired authentication result is positive, performing a setting process for at least one of an existing functional unit, which is a functional unit included in the in-vehicle network before the new functional unit was added, and the new functional unit, so that the new functional unit can communicate with the existing functional unit via a plurality of relay devices capable of relaying information between the functional units.

[0008] The vehicle communication management method disclosed herein is a vehicle communication management method in a communication system including a setting device and a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units, and includes the steps of: the setting device acquiring information sent from the new functional unit that can identify the functional unit that is the communication target of the new functional unit; the setting device acquiring an authentication result of the new functional unit; if the acquired authentication result is positive, the setting device sending to the new functional unit setting information that enables the new functional unit to communicate with existing functional units that are included in the in-vehicle network before the new functional unit was added via multiple relay devices that can relay information between the functional units; and the new functional unit configuring itself based on the setting information received from the setting device.

[0009] One aspect of the present disclosure may be realized as a semiconductor integrated circuit that realizes part or all of the setting device, or as a program that causes a computer to execute processing steps in the setting device.

[0010] Furthermore, one aspect of the present disclosure may be realized as a semiconductor integrated circuit that realizes part or all of a communication system, or as a program that causes a computer to execute processing steps in the communication system. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a diagram illustrating a configuration of a communication system according to an embodiment of the present disclosure. [Figure 2] FIG. 2 is a diagram illustrating setting information in an in-vehicle network according to an embodiment of the present disclosure. [Figure 3] FIG. 3 is a diagram illustrating a configuration of a relay device according to an embodiment of the present disclosure. [Figure 4] FIG. 4 is a diagram illustrating a configuration of a communication system according to an embodiment of the present disclosure. [Figure 5]FIG. 5 is a diagram illustrating an example of a configuration of a new network in a communication system according to an embodiment of the present disclosure. [Figure 6] FIG. 6 is a diagram illustrating an example of setting information in a new network according to an embodiment of the present disclosure. [Figure 7] FIG. 7 is a diagram illustrating another example of the configuration of a new network in a communication system according to an embodiment of the present disclosure. [Figure 8] FIG. 8 is a diagram illustrating another example of setting information in a new network according to an embodiment of the present disclosure. [Figure 9] FIG. 9 is a flowchart defining an operation procedure when a relay device constructs a new network in a communication system according to an embodiment of the present disclosure. [Figure 10] FIG. 10 is a diagram illustrating an example of a sequence of a process for establishing a new network in a communication system according to an embodiment of the present disclosure. [Figure 11] FIG. 11 is a diagram illustrating another example of a sequence of a process for establishing a new network in a communication system according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0012] Conventionally, in-vehicle network systems have been developed to improve security in in-vehicle networks.

[0013] [Problem to be solved by this disclosure] There is a need for a technology that goes beyond the technologies described in Patent Documents 1 and 2 and that allows for flexible construction of networks with new configurations through simple processing while ensuring security in the network.

[0014] The present disclosure has been made to solve the above-mentioned problems, and its purpose is to provide a setting device, a communication system, and a vehicle communication management method that are capable of flexibly constructing a network with a new configuration using simple processing while ensuring security in the network.

[0015] [Effects of this disclosure] According to the present disclosure, networks with new configurations can be flexibly constructed with simple processing while ensuring security in the network.

[0016] [Description of the embodiments of the present disclosure] First, the contents of the embodiments of the present disclosure will be listed and described.

[0017] (1) A setting device according to an embodiment of the present disclosure includes an acquisition unit that acquires an authentication result of a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units, and a setting unit that, if the authentication result acquired by the acquisition unit is positive, is capable of performing setting processing for at least one of an existing functional unit that is a functional unit included in the in-vehicle network before the new functional unit was added, and the new functional unit, so that the new functional unit can communicate with the existing functional unit via a plurality of relay devices that can relay information between the functional units.

[0018] In this way, if the authentication result of the new functional unit is positive, the configuration in which the setting device performs setting processing on at least one of the relay device, the existing functional unit, and the new functional unit so that the existing functional unit and the new functional unit communicate with each other via multiple relay devices makes it possible to omit authentication processing of the new functional unit by some relay devices in the in-vehicle network, for example, when building a network in which the existing functional unit and the new functional unit communicate with each other via multiple relay devices. Therefore, it is possible to flexibly build a network with a new configuration with simple processing while ensuring security in the network.

[0019] (2) Preferably, the setting device further includes a memory unit that stores setting information for each of the functional units in the in-vehicle network to communicate, and the setting unit performs the setting process based on the setting information in the memory unit.

[0020] In this way, the memory unit stores the configuration information for an in-vehicle network whose network configuration is basically fixed, and when building a new in-vehicle network including a new functional unit, the configuration information for the new in-vehicle network is generated using the configuration information for the existing in-vehicle network obtained from the memory unit, thereby simplifying the process of building a new in-vehicle network.

[0021] (3) Preferably, the setting unit performs the setting process using a virtual network for transmitting setting information for communication between the functional units in the in-vehicle network to the functional units.

[0022] With this configuration, the setting information can be transmitted from the setting device to each functional unit in the in-vehicle network using the virtual network, thereby simplifying the setting process for each functional unit.

[0023] (4) Preferably, the setting unit performs the setting process by constructing a new virtual network for communication between the new function unit and one or more of the existing function units with which the new function unit communicates.

[0024] This configuration makes it possible to suppress adverse effects such as unauthorized access to existing functional units that are not communication targets of the new functional unit, which may occur when a new functional unit is added to the in-vehicle network.

[0025] (5) Preferably, when an existing virtual network is constructed, which is a virtual network for communication between only one or more of the existing functional units that are the communication targets of the new functional unit, the setting unit performs, as the setting process, setting processing for the new functional unit and the relay device so that the new functional unit and the one or more existing functional units that are the communication targets can communicate using the existing virtual network.

[0026] With this configuration, by performing a setting process to add a new function unit to an existing virtual network, it is not necessary to construct a new network for communication between only the new function unit and the existing function unit with which it communicates.

[0027] (6) A communication system according to an embodiment of the present disclosure includes a setting device and a new function unit that is a new function unit added to an in-vehicle network including one or more function units, wherein the setting device acquires information transmitted from the new function unit that can identify the function unit that is the communication target of the new function unit, the setting device acquires an authentication result of the new function unit, and if the acquired authentication result is positive, the setting device transmits to the new function unit setting information that enables the function unit that is the communication target and the new function unit to communicate via a plurality of relay devices that can relay information between the function units, and the new function unit configures itself based on the setting information received from the setting device.

[0028] In this way, when the authentication result of the new functional unit is positive, the configuration in which the setting device transmits to the new functional unit setting information for communication between the existing functional unit and the new functional unit to be communicated with via multiple relay devices makes it possible to omit authentication processing of the new functional unit by some relay devices in the in-vehicle network, for example, when constructing a network in which the existing functional unit and the new functional unit communicate with each other via multiple relay devices. Therefore, it is possible to flexibly construct a network with a new configuration with simple processing while ensuring security in the network.

[0029] (7) A vehicle communication management method according to an embodiment of the present disclosure is a vehicle communication management method in a setting device, and includes the steps of: acquiring an authentication result of a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units; and, if the acquired authentication result is positive, performing a setting process on at least one of an existing functional unit that is a functional unit included in the in-vehicle network before the new functional unit was added, and the new functional unit, so that the new functional unit can communicate with the existing functional unit via a plurality of relay devices that can relay information between the functional units.

[0030] In this way, when the authentication result of the new functional unit is positive, the setting device performs setting processing for at least one of the relay device, the existing functional unit, and the new functional unit so that the existing functional unit and the new functional unit communicate with each other via multiple relay devices. This method makes it possible to omit authentication processing of the new functional unit by some relay devices in the in-vehicle network when building a network for communication between the existing functional unit and the new functional unit via multiple relay devices. Therefore, it is possible to flexibly build a network with a new configuration with simple processing while ensuring security in the network.

[0031] (8) A vehicle communication management method according to an embodiment of the present disclosure is a vehicle communication management method in a communication system including a setting device and a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units, and includes the steps of: the setting device acquiring information transmitted from the new functional unit that can identify the functional unit that is the communication target of the new functional unit; the setting device acquiring an authentication result of the new functional unit; if the authentication result acquired by the setting device is positive, the setting device transmitting to the new functional unit setting information that enables the functional unit that is the communication target and the new functional unit to communicate via a plurality of relay devices that can relay information between the functional units; and the new functional unit configuring itself based on the setting information received from the setting device.

[0032] In this way, when the authentication result of the new function unit is positive, the setting device transmits to the new function unit setting information for communication between the existing function unit and the new function unit via multiple relay devices, so that when building a network for communication between the existing function unit and the new function unit via multiple relay devices, it is possible to omit authentication processing of the new function unit by some relay devices in the in-vehicle network. Therefore, it is possible to flexibly build a network with a new configuration with simple processing while ensuring security in the network.

[0033] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the drawings, identical or corresponding parts are designated by the same reference numerals, and their description will not be repeated. Furthermore, at least some of the embodiments described below may be combined in any manner.

[0034] [Communication Systems] FIG. 1 is a diagram illustrating a configuration of a communication system according to an embodiment of the present disclosure.

[0035] Referring to FIG. 1, a communication system 300 includes one or more in-vehicle ECUs (Electronic Control Units) 111, a plurality of relay devices 100, and a server 200.

[0036] More specifically, the communication system 300 includes in-vehicle ECUs 111A to 111D as the in-vehicle ECU 111, and includes a relay device 100A and a relay device 100B as the relay device 100. The relay device 100A is an example of a setting device.

[0037] The in-vehicle ECU 111 is, for example, a TCU (Telematics Communication Unit), an autonomous driving ECU, an engine ECU, a sensor, a navigation device, a human-machine interface, a camera, etc. The TCU communicates with a device outside the vehicle, for example, a server 200, via a wireless base station (not shown) or the like.

[0038] The relay device 100 is, for example, a gateway device, and is capable of relaying information between a plurality of in-vehicle ECUs 111 connected thereto. More specifically, the relay device 100 is capable of performing relay processing according to, for example, Layer 2 and Layer 3, which is higher than Layer 2.

[0039] The in-vehicle ECU 111 is an example of a functional unit in the in-vehicle network 12. The in-vehicle ECU 111 and the relay device 100 configure the in-vehicle network 12.

[0040] The communication system 300 is not limited to a configuration including four in-vehicle ECUs 111, but may be a configuration including one, two, three, or five or more in-vehicle ECUs 111. The communication system 300 is not limited to a configuration including two relay devices 100, but may be a configuration including three or more relay devices 100.

[0041] The connection relationships between the functional units in the vehicle-mounted network 12 are, for example, fixed.

[0042] In the in-vehicle network 12, the in-vehicle ECU 111 is connected to the relay device 100 via an Ethernet (registered trademark) cable 11, for example.

[0043] More specifically, relay device 100A includes communication ports 1A, 2A, 3A, and 4A. Relay device 100B includes communication ports 1B, 2B, 3B, and 4B. Communication ports 1A, 2A, 3A, 4A, 1B, 2B, 3B, and 4B are terminals to which, for example, an Ethernet cable 11 can be connected.

[0044] The in-vehicle ECU 111A is connected to a communication port 2A in the relay device 100A via an Ethernet cable 11.

[0045] The in-vehicle ECU 111B is connected to the communication port 3A of the relay device 100A via an Ethernet cable 11.

[0046] The in-vehicle ECU 111C is connected to a communication port 2B in the relay device 100B via an Ethernet cable 11.

[0047] The in-vehicle ECU 111D is connected via an Ethernet cable 11 to a communication port 3B in the relay device 100B.

[0048] A communication port 4A of the relay device 100A and a communication port 1B of the relay device 100B are connected to each other via an Ethernet cable 11.

[0049] The relay device 100 relays Ethernet frames in accordance with the Ethernet communication standard. Specifically, the relay device 100 relays Ethernet frames exchanged between, for example, in-vehicle ECUs 111. An IP packet is stored in the Ethernet frame.

[0050] Note that communication system 300 is not limited to a configuration in which Ethernet frames are relayed in accordance with the Ethernet communication standard, but may also be a configuration in which data is relayed in accordance with communication standards such as CAN (Controller Area Network) (registered trademark), FlexRay (registered trademark), MOST (Media Oriented Systems Transport) (registered trademark), and LIN (Local Interconnect Network).

[0051] One or more virtual networks are constructed in the in-vehicle network 12. Specifically, the in-vehicle ECU 111A and the in-vehicle ECU 111C belong to a virtual local area network (VLAN) 10, and the in-vehicle ECU 111B and the in-vehicle ECU 111D belong to a VLAN 20 that is different from the VLAN 10.

[0052] FIG. 2 is a diagram illustrating setting information in an in-vehicle network according to an embodiment of the present disclosure.

[0053] In the following, for convenience, the port numbers of communication ports 1A, 2A, 3A, and 4A of relay device 100A will be referred to as "1," "2," "3," and "4," respectively, and the port numbers of communication ports 1B, 2B, 3B, and 4B of relay device 100B will be referred to as "1," "2," "3," and "4," respectively. Also, each in-vehicle ECU 111 is assumed to include one communication port, and the port number of that communication port is assumed to be "1."

[0054] Referring to Figure 2, the VLAN ID corresponding to communication port 2A of relay device 100A is "VLAN10," the VLAN ID corresponding to communication port 3A of relay device 100A is "VLAN20," and the VLAN IDs corresponding to communication port 4A of relay device 100A are "VLAN10" and "VLAN20."

[0055] In addition, the VLAN IDs corresponding to communication port 1B of relay device 100B are "VLAN10" and "VLAN20," the VLAN ID corresponding to communication port 2B of relay device 100B is "VLAN10," and the VLAN ID corresponding to communication port 3B of relay device 100B is "VLAN20."

[0056] The VLAN ID corresponding to each communication port 1 of the in-vehicle ECUs 111A and 111C is "VLAN10," and the VLAN ID corresponding to each communication port 1 of the in-vehicle ECUs 111B and 111D is "VLAN20."

[0057] The relay device 100 relays Ethernet frames between in-vehicle ECUs 111 that belong to the same VLAN, for example. Specifically, the relay device 100 transmits a received Ethernet frame to a destination in-vehicle ECU 111 that belongs to the same VLAN as the source, based on a source MAC (Media Access Control) address and a destination MAC address included in the received Ethernet frame.

[0058] Furthermore, the relay device 100 relays IP packets between in-vehicle ECUs 111 that belong to different VLANs. Specifically, the relay device 100 acquires an IP packet from a received Ethernet frame, and based on the destination IP address of the acquired IP packet, transmits the IP packet to a destination in-vehicle ECU 111 that belongs to a VLAN different from the source IP packet.

[0059] [Repeater] 3 is a diagram illustrating a configuration of a relay device according to an embodiment of the present disclosure, which is the relay device 100A illustrated in FIG.

[0060] 3, relay device 100A includes relay processing unit 110, detection unit 120, authentication result acquisition unit 130, authentication unit 140, setting unit 150, and storage unit 160. Storage unit 160 is, for example, a flash memory. Relay processing unit 110, detection unit 120, authentication result acquisition unit 130, authentication unit 140, and setting unit 150 are realized by, for example, a processor such as a CPU (Central Processing Unit) and a DSP (Digital Signal Processor).

[0061] The relay processing unit 110 relays Ethernet frames between the vehicle-mounted ECUs 111 .

[0062] More specifically, when the relay processing unit 110 receives an Ethernet frame from a certain in-vehicle ECU 111 or relay device 100B via a corresponding Ethernet cable 11, it transmits the received Ethernet frame to the destination in-vehicle ECU 111 or relay device 100B via the corresponding Ethernet cable 11.

[0063] Furthermore, when the relay processing unit 110 receives an Ethernet frame addressed to its own relay device 100 from a new function unit newly added to the in-vehicle network 12 , the relay processing unit 110 outputs the received Ethernet frame to the detection unit 120 .

[0064] [Detection unit] The detection unit 120 detects a new function unit that has been newly added to the in-vehicle network 12 .

[0065] 4 is a diagram illustrating a configuration of a communication system according to an embodiment of the present disclosure, in which an in-vehicle ECU 111E is newly added to the in-vehicle network 12 illustrated in FIG.

[0066] Referring to FIG. 4, the in-vehicle ECU 111E is connected to a communication port 1A in the relay device 100A via an Ethernet cable 11.

[0067] The in-vehicle ECU 111E is an example of a new functional unit that is a functional unit that is newly added to the in-vehicle network 12.

[0068] Hereinafter, the in-vehicle network 12 including the new functional unit will also be referred to as a new network, the in-vehicle network 12 before the new functional unit is added will also be referred to as an existing network, and the functional unit included in the existing network will also be referred to as an existing functional unit.

[0069] The in-vehicle ECU 111E exchanges Ethernet frames with the functional units that are communication targets. Hereinafter, the functional units that are communication targets of the new functional unit will also be referred to as target functional units.

[0070] When the in-vehicle ECU 111E is connected to the relay device 100A via the Ethernet cable 11, the in-vehicle ECU 111E transmits, to the relay device 100A, information that can identify the in-vehicle ECU 111 with which the in-vehicle ECU 111E is to communicate.

[0071] More specifically, when the in-vehicle ECU 111E is connected to the communication port 1A of the relay device 100A via the Ethernet cable 11, it generates connection request information including the ID, for example, the MAC address, of the in-vehicle ECU 111C with which it is to communicate.

[0072] Then, the in-vehicle ECU 111E generates an Ethernet frame including the generated connection request information, its own ID, an authentication password which is confidential information, and the MAC address of the relay device 100A as the destination MAC address, and transmits the generated Ethernet frame to the relay device 100A.

[0073] When the detection unit 120 in the relay device 100A receives the Ethernet frame from the in-vehicle ECU 111E via the relay processing unit 110, it detects the addition of the in-vehicle ECU 111E to the in-vehicle network 12 by obtaining connection request information, the ID of the in-vehicle ECU 111E, and the authentication password from the received Ethernet frame.

[0074] The detection unit 120 outputs the acquired connection request information, the ID of the in-vehicle ECU 111E, and the authentication password to the authentication result acquisition unit .

[0075] [Authentication result acquisition section] The authentication result acquisition unit 130 is an example of an acquisition unit that acquires the authentication result of the in-vehicle ECU 111E, which is a new functional unit newly added to the in-vehicle network 12.

[0076] For example, when the authentication result acquisition unit 130 receives connection request information, the ID of the in-vehicle ECU 111E, and the authentication password from the detection unit 120, it outputs the received connection request information, the ID of the new function unit, and the authentication password to the authentication unit 140.

[0077] When the authentication unit 140 receives the connection request information, the ID of the in-vehicle ECU 111E, and the authentication password from the authentication result acquisition unit 130, the authentication unit 140 performs authentication processing for the in-vehicle ECU 111E using the received connection request information, the ID of the in-vehicle ECU 111E, the authentication password, and the like.

[0078] If, as a result of the authentication process, the authentication unit 140 determines that the in-vehicle ECU 111E is not a legitimate communication partner with the target functional unit, it outputs authentication information indicating a negative authentication result as the authentication result of the in-vehicle ECU 111E to the authentication result acquisition unit 130.

[0079] When the authentication result acquisition unit 130 receives authentication information indicating a negative authentication result from the authentication unit 140, it generates an Ethernet frame including connection denial information indicating that the connection is not permitted and the MAC address of the in-vehicle ECU 111E as the destination MAC address, and transmits the generated Ethernet frame to the in-vehicle ECU 111E via the relay processing unit 110.

[0080] On the other hand, when the authentication unit 140 confirms, as a result of the authentication process, that the in-vehicle ECU 111E is a legitimate communication partner with the target functional unit indicated by the connection request information, it outputs authentication information indicating a positive authentication result as the authentication result of the in-vehicle ECU 111E to the authentication result acquisition unit 130.

[0081] When the authentication result acquisition unit 130 receives authentication information indicating a positive authentication result from the authentication unit 140, it outputs to the setting unit 150 the connection request information received from the detection unit 120 and the ID of the in-vehicle ECU 111E.

[0082] [Settings section] If the authentication result acquired by the authentication result acquisition unit 130 is positive, the setting unit 150 can perform setting processing for each functional unit and at least one of the relay devices 100A and 100B so that the existing functional unit and the in-vehicle ECU 111E can communicate via the relay devices 100A and 100B.

[0083] In detail, when the authentication result acquired by the authentication result acquisition unit 130 is positive, the setting unit 150 performs setting processing for each functional unit so that the existing functional unit and the in-vehicle ECU 111E can communicate with each other via its own relay device 100A and relay device 100B.

[0084] More specifically, when the setting unit 150 receives connection request information and the ID of the in-vehicle ECU 111E from the authentication result acquisition unit 130, it generates setting information for a new network based on the received connection request information and the ID of the in-vehicle ECU 111E, for communication between the target functional unit indicated by the connection request information and the in-vehicle ECU 111E via the relay devices 100A and 100B.

[0085] For example, the storage unit 160 stores setting information for the in-vehicle network 12 in which the connection relationships between the functional units are fixed as described above.

[0086] More specifically, the storage unit 160 stores setting information for each existing function unit to communicate in the existing network. Specifically, the storage unit 160 stores the setting information shown in FIG. 2 as the setting information of the existing network.

[0087] The setting unit 150 performs setting processing based on the setting information in the storage unit 160 .

[0088] More specifically, the setting unit 150 generates setting information for a new network based on the connection request information received from the authentication result acquisition unit 130 and the setting information for the existing network in the storage unit 160 .

[0089] The setting unit 150 updates the existing setting information in the storage unit 160 with the generated new setting information.

[0090] Then, based on the updated setting information in the storage unit 160, the setting unit 150 identifies functional units whose settings need to be changed in the new network, and notifies the identified functional units and the in-vehicle ECU 111E of the setting contents.

[0091] [Settings processing example 1] For example, as the setting process, the setting unit 150 performs a process of constructing a new virtual network for communication between the in-vehicle ECU 111E and one or more target functional units.

[0092] In the following, it is assumed that, as shown in FIG. 4, an in-vehicle ECU 111E, which is a new functional unit, is added to the in-vehicle network 12, and the target functional unit indicated by the connection request information transmitted from the in-vehicle ECU 111E is the in-vehicle ECU 111C.

[0093] When the setting unit 150 receives connection request information in which the target functional unit is the in-vehicle ECU 111C from the authentication result acquisition unit 130, the setting unit 150 generates setting information for a new network including a new virtual network for communication between only the in-vehicle ECU 111E and the in-vehicle ECU 111C.

[0094] Specifically, the setting unit 150 generates setting information for a new network including a new VLAN 30 for communication between only the in-vehicle ECU 111E and the in-vehicle ECU 111C.

[0095] FIG. 5 is a diagram illustrating an example of a configuration of a new network in a communication system according to an embodiment of the present disclosure.

[0096] FIG. 6 is a diagram illustrating an example of setting information in a new network according to an embodiment of the present disclosure.

[0097] Referring to Figure 6, the setting unit 150 generates new setting information for the new network by adding "VLAN30" as the ID of the VLAN corresponding to communication ports 1A and 4A of its own relay device 100A, adding "VLAN30" as the ID of the VLAN corresponding to communication ports 1B and 2B of relay device 100B, and adding "VLAN30" as the ID of the VLAN corresponding to each communication port 1 of the in-vehicle ECUs 111C and 111E to the setting information for the existing network shown in Figure 2.

[0098] The setting unit 150 updates the existing setting information in the storage unit 160 with the generated new setting information.

[0099] Based on the updated setting information in the storage unit 160, the setting unit 150 notifies the setting contents to the relay device 100B, the in-vehicle ECU 111C, and the in-vehicle ECU 111E, which are functional units whose settings need to be changed in the new network.

[0100] For example, it is assumed that a virtual network such as a VLAN 50 is configured for exchanging setting information between the functional units for communication between the functional units in the in-vehicle network 12. The setting unit 150 performs setting processing using the VLAN 50.

[0101] More specifically, setting unit 150 generates an Ethernet frame including setting information for the new network, and transmits the generated Ethernet frame to relay device 100B and in-vehicle ECUs 111C and 111E via relay processing unit 110 using VLAN 50.

[0102] For example, the relay devices 100A and 100B transmit Ethernet frames containing setting information using an encryption method based on secret information shared in advance.

[0103] The in-vehicle ECU 111E, the in-vehicle ECU 111C, and the relay device 100B change the settings in accordance with the setting information included in the Ethernet frame received from the setting unit 150 via the relay processing unit 110.

[0104] Specifically, the in-vehicle ECU 111E adds "VLAN 30" as a VLAN corresponding to its own communication port 1 in accordance with the setting information included in the received Ethernet frame.

[0105] Furthermore, the in-vehicle ECU 111C adds "VLAN30" as a VLAN corresponding to its own communication port 1 in accordance with the setting information included in the received Ethernet frame.

[0106] The setting unit 150 also adds "VLAN30" as a VLAN corresponding to the communication ports 1A and 4A of its own relay device 100A.

[0107] Furthermore, the relay device 100B adds "VLAN30" as a VLAN corresponding to its own communication ports 1B and 2B in accordance with the setting information contained in the received Ethernet frame.

[0108] In this way, in the communication system 300, when a new VLAN 30 is established for communication between the in-vehicle ECU 111E and the in-vehicle ECU 111C, the relay device 100B does not need to perform authentication processing for the in-vehicle ECU 111E. That is, the relay device 100B can change the setting in accordance with the setting information received from the setting unit 150 without performing authentication processing for the in-vehicle ECU 111E.

[0109] [Settings processing example 2] For example, when an existing virtual network, which is a virtual network for communication between only one or more target functional units, is constructed, the setting unit 150 performs setting processing on the in-vehicle ECU 111E and its own relay device 100A so that the in-vehicle ECU 111E and the target functional unit can communicate using the existing virtual network.

[0110] In the following, it is assumed that a new functional unit, an in-vehicle ECU 111E, is added to the in-vehicle network 12 as shown in FIG. 4, and the target functional units indicated by the connection request information transmitted from the in-vehicle ECU 111E are the in-vehicle ECU 111A and the in-vehicle ECU 111C.

[0111] When the setting unit 150 receives connection request information in which the target functional units are the in-vehicle ECUs 111A and 111C from the authentication result acquisition unit 130, the setting unit 150 generates setting information for a new network including a virtual network for communication between the in-vehicle ECU 111E and the in-vehicle ECUs 111A and 111C.

[0112] Specifically, the setting unit 150 refers to the setting information in the memory unit 160, and when it confirms that the existing network includes VLAN 10 for communication between only the in-vehicle ECU 111A and the in-vehicle ECU 111C, it generates setting information for a new network for communication between the in-vehicle ECU 111E and the in-vehicle ECUs 111A and 111C using VLAN 10.

[0113] FIG. 7 is a diagram illustrating another example of the configuration of a new network in a communication system according to an embodiment of the present disclosure.

[0114] FIG. 8 is a diagram illustrating another example of setting information in a new network according to an embodiment of the present disclosure.

[0115] Referring to Figure 8, the setting unit 150 generates new setting information for the new network by adding "VLAN10" as the ID of the VLAN corresponding to communication port 1A of its own relay device 100A to the setting information of the existing network shown in Figure 2, and adding "VLAN10" as the ID of the VLAN corresponding to communication port 1 of the in-vehicle ECU 111E, which is a new functional unit.

[0116] The setting unit 150 updates the existing setting information in the storage unit 160 with the generated new setting information.

[0117] Based on the updated setting information in the storage unit 160, the setting unit 150 notifies the setting contents to the in-vehicle ECU 111E, which is a functional unit whose setting needs to be changed in the new network.

[0118] More specifically, the setting unit 150 generates an Ethernet frame including the setting information, and transmits the generated Ethernet frame to the in-vehicle ECU 111E via the relay processing unit 110 using the above-mentioned VLAN 50.

[0119] The in-vehicle ECU 111E changes the setting in accordance with the setting information included in the Ethernet frame received from the setting unit 150 via the relay processing unit 110.

[0120] Specifically, the in-vehicle ECU 111E adds "VLAN10" as a VLAN corresponding to its own communication port 1 in accordance with the setting information included in the received Ethernet frame.

[0121] The setting unit 150 also adds "VLAN10" as a VLAN corresponding to the communication port 1A of its own relay device 100A.

[0122] In this way, in the communication system 300, when a new VLAN 30 is established for communication between the in-vehicle ECU 111E and the in-vehicle ECU 111C, authentication processing of the in-vehicle ECU 111E by the relay device 100B is not required.

[0123] [Operation flow] Each device in the communication system according to the embodiment of the present disclosure includes a computer including a memory, and a processing unit such as a CPU in the computer reads and executes a program including some or all of the steps in the following flowcharts and sequences from the memory. The programs for each of these devices can be installed externally. The programs for each of these devices are distributed in a state where they are stored on a recording medium.

[0124] FIG. 9 is a flowchart defining an operation procedure when a relay device constructs a new network in a communication system according to an embodiment of the present disclosure.

[0125] Referring to FIG. 9, first, the relay device 100A waits for the addition of a new functional unit to the in-vehicle network 12 (NO in step S102), and when it detects the addition of a new functional unit to the in-vehicle network 12 (YES in step S102), it performs authentication processing of the detected new functional unit (step S104).

[0126] Next, if the authentication result is negative (NO in step S106), the relay device 100A transmits connection denial information indicating that the connection is not permitted to the new function unit (step S108).

[0127] Next, the relay device 100A waits for a new function unit to be added to the in-vehicle network 12 (NO in step S102).

[0128] On the other hand, if the authentication result is positive (YES in step S106), the relay device 100A generates setting information for a new network for communication between the relay device 100B, the target function unit, and the new function unit (step S110).

[0129] Next, the relay device 100A identifies functional units whose settings need to be changed in the new network based on the generated setting information, and transmits the setting information to the identified functional units and the in-vehicle ECU 111E (step S112).

[0130] Next, the relay device 100A waits for a new function unit to be added to the in-vehicle network 12 (NO in step S102).

[0131] 10 is a diagram illustrating an example of a sequence of a process for establishing a new network in a communication system according to an embodiment of the present disclosure. 10 illustrates an example of a sequence of a process for establishing a new network such as that illustrated in FIG.

[0132] 10, first, in the existing in-vehicle network 12, the in-vehicle ECU 111A and the in-vehicle ECU 111C belong to the same VLAN 10, and communicate with each other using the VLAN 10 via the relay devices 100A and 100B (step S202).

[0133] Next, when the in-vehicle ECU 111E, which is a new functional unit newly added to the in-vehicle network 12, is connected to the relay device 100A, it transmits connection request information including information that can identify the in-vehicle ECU 111C with which it is to communicate to the relay device 100A (step S204).

[0134] Next, when the relay device 100A receives the connection request information from the in-vehicle ECU 111E, the relay device 100A detects the in-vehicle ECU 111E and performs authentication processing for the in-vehicle ECU 111E (step S206).

[0135] Next, if the authentication result is positive, the relay device 100A generates setting information for a new network for communication between the relay device 100B and the in-vehicle ECU 111C and the in-vehicle ECU 111E using the VLNA 30. Specifically, the relay device 100A generates setting information as shown in FIG. 6 (step S208).

[0136] Next, the relay device 100A transmits the generated setting information to the relay device 100B, the in-vehicle ECU 111C, and the in-vehicle ECU 111E, which are functional units whose settings need to be changed in the new network (step S210).

[0137] Next, the relay device 100A changes the setting based on the generated setting information (step S212).

[0138] Furthermore, the in-vehicle ECU 111E changes the setting in accordance with the setting information received from the relay device 100A (step S214).

[0139] Furthermore, relay device 100B changes the settings in accordance with the setting information received from relay device 100A (step S216).

[0140] Furthermore, the in-vehicle ECU 111C changes the setting in accordance with the setting information received from the relay device 100A (step S218).

[0141] Next, in the new network 12, the in-vehicle ECU 111A and the in-vehicle ECU 111C communicate with each other via the relay devices 100A and 100B using the VLAN 10 (step S220).

[0142] In the new network 12, the in-vehicle ECU 111E and the in-vehicle ECU 111C communicate with each other via the relay devices 100A and 100B using the newly created VLAN 30 (step S222).

[0143] 11 is a diagram illustrating another example of a sequence of a process for establishing a new network in a communication system according to an embodiment of the present disclosure. FIG. 11 illustrates an example of a sequence of a process for establishing a new network as illustrated in FIG.

[0144] 11, first, in the existing in-vehicle network 12, the in-vehicle ECU 111A and the in-vehicle ECU 111C belong to the same VLAN 10, and communicate with each other using the VLAN 10 via the relay devices 100A and 100B (step S302).

[0145] Next, when the in-vehicle ECU 111E, which is a new functional unit newly added to the in-vehicle network 12, is connected to the relay device 100A, it transmits connection request information to the relay device 100A, including information that can identify the in-vehicle ECUs 111A and 111C with which it is to communicate (step S304).

[0146] Next, when the relay device 100A receives the connection request information from the in-vehicle ECU 111E, the relay device 100A detects the in-vehicle ECU 111E and performs authentication processing for the in-vehicle ECU 111E (step S306).

[0147] Next, if the authentication result is positive, the relay device 100A generates setting information for a new network for communication between the relay device 100B, the in-vehicle ECUs 111A and 111C, and the in-vehicle ECU 111E using the VLNA 10. Specifically, the relay device 100A generates setting information as shown in FIG. 8 (step S308).

[0148] Next, the relay device 100A transmits the generated setting information to the in-vehicle ECU 111E, which is a functional unit whose setting needs to be changed in the new network (step S310).

[0149] Next, the relay device 100A changes the setting based on the generated setting information (step S312).

[0150] Furthermore, the in-vehicle ECU 111E changes the setting in accordance with the setting information received from the relay device 100A (step S314).

[0151] Next, in the new network 12, the in-vehicle ECU 111A, the in-vehicle ECU 111C, and the in-vehicle ECU 111E communicate with each other via the relay devices 100A and 100B using the VLAN 10 (step S316).

[0152] In the communication system 300 according to the embodiment of the present disclosure, the relay device 100A, which is the connection destination of the in-vehicle ECU 111E as the new functional unit, is configured to acquire the authentication result of the in-vehicle ECU 111E and perform the setting process as a setting device, but this is not limited to this. Of the two relay devices 100, the relay device 100B, which is the relay device 100 not connected to the in-vehicle ECU 111E, may be configured to acquire the authentication result and perform the setting process.

[0153] Furthermore, a device other than the relay device 100 in the in-vehicle network 12 may be configured to acquire the authentication result and perform the setting process as a setting device. For example, a device that is not located on the communication path between the new function unit and the target function unit in the in-vehicle network 12 may be configured to acquire the authentication result and perform the setting process as a setting device.

[0154] Alternatively, a device outside the vehicle, such as the server 200, may be configured to acquire the authentication result and perform the setting process as a setting device. In this case, the server 200 communicates with a TCU in the in-vehicle network 12 to acquire connection request information transmitted from the in-vehicle ECU 111E, which is information capable of identifying the target functional unit, acquire the authentication result, and perform the setting process.

[0155] In addition, in the communication system 300 according to the embodiment of the present disclosure, the in-vehicle ECU 111E, which is a new functional unit, is configured to transmit connection request information including the MAC address of the in-vehicle ECU 111C to the relay device 100A as information for identifying the in-vehicle ECU 111C, which is a target functional unit. However, this is not limited to this. The in-vehicle ECU 111E may be configured to transmit other information, such as the IP address of the in-vehicle ECU 111C, to the relay device 100A as information for identifying the in-vehicle ECU 111C.

[0156] In addition, in the relay device 100A according to the embodiment of the present disclosure, the authentication result acquisition unit 130 is configured to acquire the authentication result of the in-vehicle ECU 111E from the authentication unit 140 in the relay device 100A itself, but this is not limited thereto. The authentication result acquisition unit 130 may be configured to acquire the authentication result of the in-vehicle ECU 111E from a device other than the relay device 100A itself.

[0157] Furthermore, in the relay device 100A according to the embodiment of the present disclosure, the detection unit 120 is configured to detect the in-vehicle ECU 111, which is a new function unit newly added to the in-vehicle network 12, but this is not limited to this. The detection unit 120 may be configured to detect an application installed in an existing in-vehicle ECU 111 in the in-vehicle network 12 as a new function unit. In other words, the new function unit may be hardware or software.

[0158] Furthermore, in the relay device 100A according to the embodiment of the present disclosure, the setting unit 150 is configured to generate the setting information of the new network based on the setting information of the existing network stored in the storage unit 160, but this is not limiting. The setting unit 150 may be configured to send an information request notification to each functional unit in the in-vehicle network 12 requesting that the functional unit transmit information indicating the setting contents of the functional unit, and to generate the setting information of the new network based on the setting contents received from each functional unit in response to the information request notification.

[0159] Furthermore, in the relay device 100A according to the embodiment of the present disclosure, the setting unit 150 is configured to transmit the setting information to each functional unit using the VLAN 50 for exchanging the setting information between the functional units in the in-vehicle network 12, but this is not limited thereto. The setting unit 150 may be configured to transmit the setting information to the destination functional unit using a VLAN for communication between some of the functional units in the in-vehicle network 12.

[0160] Furthermore, for example, the relay devices 100A and 100B may be configured to exchange setting information and the like using an API (Application Programming Interface) for network setting used in consumer products.

[0161] Furthermore, in the relay device 100A according to the embodiment of the present disclosure, the setting unit 150 is configured to identify functional units whose settings need to be changed in the new network and transmit updated setting information to the identified functional units and the in-vehicle ECU 111E, but this is not limiting. The setting unit 150 may be configured to generate setting change information indicating the content of the setting change of each functional unit for each identified functional unit and in-vehicle ECU 111E, and transmit the corresponding setting change information to the identified functional unit and in-vehicle ECU 111E.

[0162] [assignment] For example, by adding a high-performance sensor that transmits measurement results to an autonomous driving ECU to an existing in-vehicle network 12 that includes an autonomous driving ECU, which is an example of an in-vehicle ECU 111, the control function of the autonomous driving ECU during autonomous driving can be improved.

[0163] As described above, there is a demand for a technique for customizing the in-vehicle network 12 by adding a new in-vehicle ECU 111 to the existing in-vehicle network 12.

[0164] However, in a situation where a new in-vehicle ECU 111 is added to the in-vehicle network 12, it may not be desirable from the perspective of security of the in-vehicle network 12 for the in-vehicle ECU 111 and the target functional unit to communicate using an existing virtual network in the new in-vehicle network 12.

[0165] 4, it is assumed that an in-vehicle ECU 111E, which is a new functional unit, is added to the in-vehicle network 12, and the target functional unit indicated by the connection request information transmitted from the in-vehicle ECU 111E is the in-vehicle ECU 111C.

[0166] For example, when the relay device 100A receives the connection request information from the vehicle-mounted ECU 111E and constructs a new network as shown in FIG. 7, the vehicle-mounted ECU 111E will be able to communicate not only with the vehicle-mounted ECU 111C, which is the target functional unit, but also with the vehicle-mounted ECU 111A, with which it does not originally need to communicate.

[0167] For example, if the in-vehicle ECU 111E is an unauthorized ECU, not only the in-vehicle ECU 111C but also the in-vehicle ECU 111A may be subject to unauthorized access.

[0168] Therefore, in order to avoid a situation in which the in-vehicle ECU 111A is subject to unauthorized access, it is possible to configure a new network, such as the one shown in Figure 5, in which the in-vehicle ECU 111E is only permitted to communicate with the in-vehicle ECU 111C, which is the target functional unit.

[0169] However, when configuring a new network as shown in Figure 5, each relay device 100 located on the communication path between the in-vehicle ECU 111E and the in-vehicle ECU 111C, i.e., relay devices 100A and 100B, needs to perform authentication processing for the in-vehicle ECU 111E and change the network configuration.

[0170] Therefore, it takes time after the in-vehicle ECU 111E is added to the in-vehicle network 12 until the in-vehicle ECU 111E and the in-vehicle ECU 111C can communicate with each other.

[0171] Furthermore, it is necessary to provide an authentication function for authenticating the newly added in-vehicle ECU 111E in all relay devices 100 present on the communication path between the in-vehicle ECU 111E and the in-vehicle ECU 111C, which increases the costs required for hardware and software development.

[0172] In contrast, in the relay device 100A according to the embodiment of the present disclosure, the authentication result acquisition unit 130 acquires an authentication result of a new functional unit that is a functional unit newly added to the in-vehicle network 12 that includes one or more functional units. If the authentication result acquired by the authentication result acquisition unit 130 is positive, the setting unit 150 can perform a setting process for at least one of the relay device, the existing functional unit, and the new functional unit so that the new functional unit can communicate with an existing functional unit that is a functional unit included in the in-vehicle network 12 before the new functional unit was added via multiple relay devices 100A and 100B that can relay information between the functional units.

[0173] In this way, if the authentication result of the new functional unit is positive, the relay device 100A performs configuration processing on at least one of the relay devices 100A, 100B, the existing functional unit, and the new functional unit so that the existing functional unit and the new functional unit can communicate via multiple relay devices 100A, 100B.This configuration makes it possible to omit authentication processing of the new functional unit by some of the relay devices 100B in the in-vehicle network 12, for example, when constructing a network so that the existing functional unit and the new functional unit can communicate via multiple relay devices 100A, 100B.

[0174] Therefore, the relay device 100A according to the embodiment of the present disclosure can flexibly build a network with a new configuration through simple processing while ensuring security in the network.

[0175] Furthermore, in the relay device 100A according to the embodiment of the present disclosure, the storage unit 160 stores setting information for communication between the functional units in the in-vehicle network 12. The setting unit 150 performs setting processing based on the setting information in the storage unit 160.

[0176] In this way, the memory unit 160 stores the configuration information for the in-vehicle network 12, whose network configuration is basically fixed, and when constructing a new in-vehicle network 12 that includes a new functional unit, the configuration information for the existing in-vehicle network 12 obtained from the memory unit 160 is used to generate the configuration information for the new in-vehicle network 12, thereby simplifying the process of constructing the new in-vehicle network 12.

[0177] In addition, in the relay device 100A according to the embodiment of the present disclosure, the setting unit 150 performs the setting process using a virtual network for transmitting setting information to each functional unit in the in-vehicle network 12 so that the functional units can communicate with each other.

[0178] With this configuration, the relay device 100A can transmit setting information to each functional unit in the in-vehicle network 12 using the virtual network, thereby simplifying the setting process for each functional unit.

[0179] Furthermore, in the relay device 100A according to an embodiment of the present disclosure, the setting unit 150 performs a setting process to construct a new virtual network for communication between the new function unit and one or more existing function units with which the new function unit communicates.

[0180] With this configuration, it is possible to suppress adverse effects such as unauthorized access to existing functional units that are not communication targets of the new functional unit, which may occur when a new functional unit is added to the in-vehicle network 12.

[0181] In addition, in the relay device 100A according to an embodiment of the present disclosure, when an existing virtual network is constructed, which is a virtual network for communication only between one or more existing functional units that are communication targets of the new functional unit, the setting unit 150 performs setting processing for the new functional unit and the relay device 100A so that the new functional unit and the one or more existing functional units that are communication targets can communicate using the existing virtual network.

[0182] With this configuration, by performing a setting process to add a new function unit to an existing virtual network, it is not necessary to construct a new network for communication between only the new function unit and the existing function unit with which it communicates.

[0183] Furthermore, a communication system 300 according to an embodiment of the present disclosure includes a relay device 100A and a new functional unit that is a functional unit newly added to an in-vehicle network 12 that includes one or more functional units. The relay device 100A acquires information transmitted from the new functional unit that can identify a functional unit that is a communication target of the new functional unit. The relay device 100A acquires an authentication result of the new functional unit. If the acquired authentication result is positive, the relay device 100A transmits to the new functional unit configuration information for communication between the communication target functional unit and the new functional unit via multiple relay devices 100A and 100B that can relay information between the functional units. The new functional unit configures itself based on the configuration information received from the relay device 100A.

[0184] In this way, if the authentication result of the new functional unit is positive, the relay device 100A transmits to the new functional unit setting information for the existing functional unit and the new functional unit to communicate with each other via multiple relay devices 100A and 100B.For example, when constructing a network for communication between the existing functional unit and the new functional unit via multiple relay devices 100A and 100B, authentication processing of the new functional unit by some of the relay devices 100B in the in-vehicle network 12 can be omitted.

[0185] Therefore, in the communication system 300 according to the embodiment of the present disclosure, it is possible to flexibly construct a network with a new configuration through simple processing while ensuring security in the network.

[0186] Furthermore, a vehicle communication management method according to an embodiment of the present disclosure is a vehicle communication management method in a relay device 100A. In this vehicle communication management method, first, the relay device 100A acquires an authentication result of a new functional unit that is a functional unit newly added to an in-vehicle network 12 that includes one or more functional units. Next, if the acquired authentication result is positive, the relay device 100A performs a setting process for at least one of the relay devices 100A, 100B, the existing functional unit, and the new functional unit so that the new functional unit can communicate with an existing functional unit that is a functional unit included in the in-vehicle network 12 before the new functional unit was added via multiple relay devices 100A, 100B that can relay information between the functional units.

[0187] In this way, when the authentication result of the new functional unit is positive, the relay device 100A performs configuration processing on at least one of the relay devices 100A, 100B, the existing functional unit, and the new functional unit so that the existing functional unit and the new functional unit can communicate via multiple relay devices 100A, 100B.This method makes it possible to omit authentication processing of the new functional unit by some of the relay devices 100B in the in-vehicle network 12, for example, when constructing a network in which the existing functional unit and the new functional unit can communicate via multiple relay devices 100A, 100B.

[0188] Therefore, the vehicle communication management method according to the embodiment of the present disclosure makes it possible to flexibly build a network with a new configuration using simple processing while ensuring security in the network.

[0189] A vehicle communication management method according to an embodiment of the present disclosure is a vehicle communication management method in a communication system 300 including a relay device 100A and a new functional unit that is a functional unit newly added to an in-vehicle network 12 including one or more functional units. In this vehicle communication management method, first, the relay device 100A acquires information transmitted from the new functional unit that can identify a functional unit that is a communication target of the new functional unit. Next, the relay device 100A acquires an authentication result of the new functional unit. Next, if the acquired authentication result is positive, the relay device 100A transmits to the new functional unit configuration information for communication between the communication target functional unit and the new functional unit via multiple relay devices 100A and 100B that can relay information between the functional units. Next, the new functional unit configures itself based on the configuration information received from the relay device 100A.

[0190] In this way, when the authentication result of the new functional unit is positive, the relay device 100A transmits to the new functional unit setting information for the existing functional unit to communicate with the new functional unit via multiple relay devices 100A and 100B. For example, when constructing a network for communication between the new existing functional unit and the new functional unit via multiple relay devices 100A and 100B, authentication processing of the new functional unit by some of the relay devices 100B in the in-vehicle network 12 can be omitted.

[0191] Therefore, the vehicle communication management method according to the embodiment of the present disclosure makes it possible to flexibly build a network with a new configuration using simple processing while ensuring security in the network.

[0192] The above-described embodiments should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims.

[0193] The above description includes the following additional features. [Appendix 1] A relay device capable of relaying information between functional units in an in-vehicle network including one or more functional units, a detection unit that detects a new functional unit that is the functional unit newly added to the in-vehicle network; an acquisition unit that acquires an authentication result of the new function unit detected by the detection unit; A relay device comprising: an existing functional unit, which is a functional unit included in the in-vehicle network before the new functional unit was added, and a setting unit that performs setting processing for at least one of the relay devices, the existing functional unit, and the new functional unit, so that, when the authentication result acquired by the acquisition unit is positive, the new functional unit can communicate with the existing functional unit, which is a functional unit included in the in-vehicle network before the new functional unit was added, via a plurality of relay devices that can relay information between the functional units.

[0194] [Appendix 2] an acquisition unit that acquires an authentication result of a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units; a setting unit that performs setting processing for at least one of a relay device, the existing function unit, and the new function unit, so that, when the authentication result acquired by the acquisition unit is positive, the new function unit and an existing function unit that is included in the in-vehicle network before the new function unit is added can communicate with the new function unit via a plurality of relay devices that can relay information between the function units; The setting device, wherein the acquisition unit and the setting unit are realized by a processor.

[0195] [Appendix 3] a first relay device capable of relaying information between functional units in an in-vehicle network including a plurality of functional units, and a second relay device connected to the first relay device; a new functional unit that is the functional unit newly added to the in-vehicle network, the new function unit transmits information capable of identifying the function unit with which the new function unit is to communicate to the first relay device; the first relay device detects the addition of the new function unit to the in-vehicle network; The first relay device acquires the authentication result of the detected new function unit, When the acquired authentication result is positive, the first relay device transmits to the new function unit setting information for communication between the function unit that is the communication target and the new function unit via the first relay device and the second relay device; The new function unit configures itself based on the configuration information received from the first relay device.

[0196] [Appendix 4] A setting device; a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units; the setting device acquires information transmitted from the new function unit that can identify the function unit that is a communication target of the new function unit, The setting device acquires the authentication result of the new function unit, When the acquired authentication result is positive, the setting device transmits to the new function unit setting information for communication between the function unit that is the communication target and the new function unit via a plurality of relay devices that can relay information between the function units, the new function unit performs its own configuration based on the configuration information received from the configuration device; The functional unit is an ECU. [Explanation of symbols]

[0197] 1,2,3,4 communication ports 11 Ethernet cable 12 In-vehicle network 100 Repeater 110 Relay Processing Unit 111 Automotive ECU 120 Detection unit 130 Authentication result acquisition unit 140 Authentication Department 150 Setting Section 160 Storage section 200 servers 300 Communication Systems

Claims

1. an acquisition unit that acquires an authentication result of a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units; A setting device comprising: an existing functional unit, which is a functional unit included in the in-vehicle network before the new functional unit was added, and a setting unit capable of performing setting processing for at least one of the relay devices, the existing functional unit, and the new functional unit, so that, when the authentication result acquired by the acquisition unit is positive, the new functional unit communicates with the existing functional unit, which is a functional unit included in the in-vehicle network before the new functional unit was added, via a plurality of relay devices capable of relaying information between the functional units.

2. The setting device further a storage unit that stores setting information for communication between the functional units in the in-vehicle network; The setting device according to claim 1 , wherein the setting unit performs the setting process based on the setting information in the storage unit.

3. 3. The setting device according to claim 1, wherein the setting unit performs the setting process using a virtual network for transmitting setting information for communication between the functional units in the in-vehicle network to the functional units.

4. 4. The setting device according to claim 1, wherein the setting unit performs, as the setting process, a process of constructing a new virtual network for communication between the new function unit and one or more of the existing function units that are communication targets of the new function unit.

5. 4. A setting device as described in any one of claims 1 to 3, wherein, when an existing virtual network is constructed, which is a virtual network for communication only between one or more existing function units that are communication targets of the new function unit, the setting unit performs setting processing for the new function unit and the relay device so that the new function unit and the one or more existing function units that are communication targets can communicate using the existing virtual network as the setting processing.

6. A setting device; a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units; the setting device acquires information transmitted from the new function unit that can identify the function unit that is the communication target of the new function unit, The setting device acquires the authentication result of the new function unit, When the acquired authentication result is positive, the setting device transmits to the new function unit setting information for communication between the function unit that is the communication target and the new function unit via a plurality of relay devices that can relay information between the function units, The new function unit configures itself based on the configuration information received from the configuration device.

7. A vehicle communication management method in a setting device, obtaining an authentication result of a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units; If the obtained authentication result is positive, the vehicle communication management method includes a step of performing configuration processing on at least one of the relay devices, the existing functional unit, and the new functional unit, which are functional units included in the in-vehicle network before the new functional unit was added, so that the new functional unit can communicate with the existing functional unit via a plurality of relay devices capable of relaying information between the functional units.

8. A vehicle communication management method in a communication system including a setting device and a new functional unit that is a functional unit newly added to an in-vehicle network including one or more functional units, a step in which the setting device acquires information transmitted from the new function unit, the information being capable of identifying the function unit that is a communication target of the new function unit; the setting device acquiring an authentication result of the new function unit; a step in which, when the acquired authentication result is positive, the setting device transmits to the new function unit setting information for communication between the function unit that is the communication target and the new function unit via a plurality of relay devices that can relay information between the function units; and a step in which the new function unit configures itself based on the configuration information received from the configuration device.

Citation Information

Patent Citations

  • Vlan and vlan frame switching apparatus

    JP2003244185A

  • Authenticated VLAN management device

    JP2007267139A

  • Network management method, network management program, network system, and relay equipment

    JP2010283607A

  • Network management system and management computer

    JP2013017021A

  • Controller, communication system, management method and program of virtual network function

    JP2016152429A