Electronic control device
The electronic control device is a unique device that generates a unique random number each time, using a unique value and eigenvalue to improve confidentiality in authentication.
Patent Information
- Application Number
- JP2024086540
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-28
- Publication Date
- 2025-12-10
AI Technical Summary
Existing electronic control devices face challenges in generating random numbers with sufficient variance for authentication and security applications, as existing systems fail to generate random numbers efficiently, resulting in potential security vulnerabilities.
The electronic control device comprises a unique value acquisition unit that acquires a unique value acquisition unit that acquires a unique value that is different each time a random number is generated; an eigenvalue acquisition unit that acquires an eigenvalue that is unique to the electronic control device; and a generating unit that generates random numbers using the unique value and the unique value.
The electronic control device can generate a different random number each time, thereby improving confidentiality in authentication, thereby improving confidentiality in authentication, thereby improving confidentiality in authentication, thereby improving confidentiality in authentication, thereby improving confidentiality in authentication, thereby improving confidentiality in authentication, thereby improving confidentiality in authentication, thereby improving confidentiality in authentication, thereby improving confidentiality in authentication, thereby improving confidentiality in authentication, thereby improving confidentiality in authentication.
Smart Images

Figure 2025179648000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to electronic control devices. [Background technology]
[0002] As disclosed in Patent Document 1, there is a pseudorandom number generator. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Special Publication No. 2019-531541 Summary of the Invention [Problem to be solved by the invention]
[0004] Some electronic control devices have a function for generating random numbers using information for random number generation. Depending on the information, the electronic control device may generate random numbers with little variance. In the above respects and in other respects not mentioned, further improvements in electronic control devices are required.
[0005] One disclosed object is to provide an electronic control device that can generate a different random number each time. [Means for solving the problem]
[0006] The electronic control device disclosed herein comprises: An electronic control device having a function of generating random numbers, a unique value acquisition unit (S30) that acquires a unique value that is different each time a random number is generated; an eigenvalue acquisition unit (S32) that acquires an eigenvalue that is unique to the electronic control device; and a generating unit (S38, S38a) that generates random numbers using the unique value and the eigenvalue.
[0007] In this way, the electronic control unit generates a random number using the unique value and the specific value, so that the electronic control unit can generate a different random number each time.
[0008] The various aspects disclosed in this specification employ different technical means to achieve their respective objectives. The reference numerals in parentheses in the claims and in this section are intended to exemplify correspondences with the following embodiments and are not intended to limit the technical scope. The objectives, features, and advantages disclosed in this specification will become more apparent by reference to the following detailed description and the accompanying drawings. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a block diagram showing a schematic configuration of an electronic control device according to a first embodiment. [Figure 2] 4 is a flowchart showing the processing operation of the diagnostic tool in the first embodiment. [Figure 3] 4 is a flowchart showing the processing operation of the electronic control device in the first embodiment. [Figure 4] 4 is a flowchart showing a random number generation process of the electronic control unit in the first embodiment. [Figure 5] 10 is a flowchart showing a random number generation process of an electronic control unit according to a modified example. [Figure 6] FIG. 10 is a block diagram showing a schematic configuration of an electronic control device according to a second embodiment. [Figure 7] 10 is a flowchart showing a random number generation process of an electronic control unit in a second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, several embodiments for carrying out the present disclosure will be described with reference to the drawings. In each embodiment, parts corresponding to matters described in the preceding embodiment may be assigned the same reference numerals, and duplicated explanations may be omitted. In each embodiment, when only a part of the configuration is described, the other parts of the configuration may be applied by referring to the other embodiment described previously.
[0011] (First embodiment) An electronic control device 1 according to a first embodiment will be described with reference to Figs. 1 to 4. The electronic control device 1 is configured to be mountable on a mobile object, for example. Examples of mobile objects include vehicles such as electric cars, hybrid cars, and fuel cell cars, flying objects such as electric vertical take-off and landing aircraft and drones, ships, construction machinery, and agricultural machinery. In this embodiment, an electronic control device 1 mounted on a vehicle is used as an example. However, the electronic control device 1 can also be applied to other applications.
[0012] For example, the electronic control unit 1 can be applied to a device that controls a motor as a controlled object. The motor can be one that assists the driver's steering force. Therefore, the electronic control unit 1 can be applied to a steering device such as an electric power steering. However, the controlled object of the electronic control unit 1 may be something other than a motor.
[0013] <Configuration> The configuration of the electronic control device 1 will be described using Figure 1. The electronic control device 1 mainly includes a microcontroller 100 (hereinafter referred to as a microcomputer). The electronic control device 1 may also include a communication device for communicating with an external device. In other words, the electronic control device 1 may be configured to be able to communicate with an external device. Furthermore, the electronic control device 1 may also include multiple sensors for detecting temperature, behavior of a controlled object, etc. In the drawing, the electronic control device 1 is referred to as an ECU, and the microcomputer 100 is referred to as an MCU.
[0014] The external device is a device provided separately from the electronic control device 1. In this embodiment, a diagnostic tool 2 is used as an example of the external device. The diagnostic tool 2 is a device that performs fault diagnosis on the electronic control device 1. The diagnostic tool 2 includes a processing device such as a CPU, storage devices such as a ROM and a RAM, a communication device for communicating with the electronic control device 1, and the like.
[0015] The electronic control unit 1 performs authentication with the diagnostic tool 2 using a random number, which will be explained later. That is, the electronic control unit 1 generates a random number to be used for authenticating the diagnostic tool 2. The authentication process between the electronic control unit 1 and the diagnostic tool 2 will be explained in detail later.
[0016] However, the use of the random numbers is not limited to this. The electronic control unit 1 may, for example, generate random numbers for use in various applications. Furthermore, the external device is not limited to the diagnostic tool 2. The external device may, for example, be a device installed in the vehicle together with the electronic control unit 1 itself, a device installed in another vehicle, or a server installed in an external center. The external center may, for example, be an OTA server. OTA is an abbreviation for over the air.
[0017] The microcomputer 100 mainly includes a CPU 10 and a storage device 20. The storage device 20 includes a volatile memory and a nonvolatile memory such as a ROM 21 and an NVM 22. The microcomputer 100 also includes an input / output port and the like.
[0018] CPU is an abbreviation for Central Processing Unit. ROM is an abbreviation for Read Only Memory. Volatile memory can be DRAM or SRAM. DRAM is an abbreviation for Dynamic RAM. SRAM is an abbreviation for Static RAM. RAM is an abbreviation for Random Access Memory. NVM is an abbreviation for non-volatile memory.
[0019] The CPU 10 is configured to be able to access the ROM 21 and the NVM 22. The CPU 10 executes a program stored in the ROM 21. The CPU 10 performs arithmetic processing by executing the program. At this time, the CPU 10 performs arithmetic processing using data stored in the volatile memory and data obtained from the input / output port. The CPU 10 then performs various controls by outputting the results of the calculations from the input / output port. The program is, for example, a control program. The control program corresponds to control software.
[0020] Furthermore, it can be said that the CPU 10 executes various functions by performing arithmetic processing. For this reason, the CPU 10 has a plurality of functional blocks. The functional blocks of the CPU 10 include, for example, an entropy source generation unit 11, a random number generation unit 12, and an upper limit check unit 13. In the drawings, the entropy source generation unit 11 is represented as EGR, the random number generation unit 12 as RGP, and the upper limit check unit 13 as ULC.
[0021] The entropy source generation unit 11 generates an entropy input from the contents stored in the ROM 21 or NVM 22. The entropy source generation unit 11 passes the generated entropy input to the random number generation unit 12. The random number generation unit 12 generates random numbers using the entropy input from the entropy source generation unit 11. The entropy input can also be referred to as input data.
[0022] In this way, the electronic control unit 1 has the function of generating random numbers. In the drawings, the entropy input is represented as INP. Note that "passing" can also be said to make the data available for reference.
[0023] The microcomputer 100 also has a function of counting the number of times a random number has been generated. The microcomputer 100 updates the count value each time a random number is generated. This count value is the number of times the random number has been generated. The number of times the random number has been generated is written to NVM 22, which will be described later. In other words, the CPU 10 updates the number of times the random number has been generated stored in NVM 22 each time a random number is generated. At this time, the CPU 10 erases the number of times the random number has been generated from NVM 22 and writes a new number of times the random number has been generated to NVM 22. The count function may be included in the random number generation unit 12, or may be a functional block separate from the random number generation unit 12.
[0024] The upper limit check unit 13 checks (verifies) whether the number of times a random number has been generated has reached an upper limit. The upper limit check unit 13 compares the number of times a random number has been generated in NVM 22 with a predetermined upper limit. The upper limit check unit 13 then passes the check result, which is the result of comparing the number of times a random number has been generated with the upper limit, to the random number generation unit 12. The upper limit may be the number of times NVM 22 can be written (limit value), or the like. The upper limit is stored in ROM 21, NVM 22, or the like. In the drawings, the check result is represented as RST.
[0025] The check result is either a value indicating that the number of times a random number has been generated has reached the upper limit, or a value indicating that the number of times a random number has been generated has not reached the upper limit. A value indicating that the number of times a random number has been generated has reached the upper limit can also be said to be a check result of NG. A value indicating that the number of times a random number has not reached the upper limit can also be said to be a check result of OK.
[0026] Furthermore, in this embodiment, as an example, the microcomputer 100 is employed that can acquire diagnostic data. The diagnostic data is data for diagnosing a malfunction of the electronic control device 1. That is, the microcomputer 100 acquires sensor values output from each sensor as diagnostic data. The sensor values are stored in the NVM 22, which will be described later, or the like.
[0027] The ROM 21 is a read-only storage medium. Contents are written to the ROM 21 when the electronic control device 1 is manufactured. The contents written to the ROM 21 include device IDs and programs. The ROM 21 has multiple storage areas. It is preferable that the device IDs and programs are stored in different storage areas. In other words, the device IDs are managed separately from the programs.
[0028] The device ID is information that differs for each electronic control device 1. The device ID is a value that is unique to the electronic control device 1. In other words, the device ID is a value that is individual to each of multiple electronic control devices 1 that have the same configuration and the same functions. The device ID is, for example, the serial number of the electronic control device 1. The device ID includes the model number and manufacturing date. Therefore, the device ID can be said to be information that is unique. Furthermore, the device ID is written to ROM 21 at the time of manufacturing as described above, so its uniqueness can be guaranteed. The device ID corresponds to a unique value.
[0029] The unique value can also be considered as individual system data that differs for each electronic control unit 1. The ROM 21 can also be considered as PROM, which is an abbreviation for Programmable ROM. In the drawings, the device ID is represented as DID.
[0030] NVM 22 is a storage medium whose contents can be repeatedly erased and rewritten. The contents written to NVM 22 include the number of times a random number is generated. The number of times a random number is generated is a different value each time a random number is generated. In other words, the number of times a random number is generated is a unique value in the random number generation process in microcontroller 100. The number of times a random number is generated corresponds to a unique value. NVM 22 can be made of EEPROM (registered trademark) or flash memory. EEPROM is an abbreviation for Electrically Erasable Programmable ROM. In the drawings, the number of times a random number is generated is represented as RGN. The number of times a random number is generated and the device ID can also be considered generation information or generation data, which are information for generating random numbers.
[0031] The electronic control unit 1 may be configured to be reprogrammable. In this case, the program is stored in a reprogrammable storage medium. This allows the electronic control unit 1 to correct program defects and maintain the latest program.
[0032] On the other hand, it is preferable that the storage area in which the device ID is stored is an area that is not rewritten by reprogramming a program. This allows the electronic control device 1 to prevent the device ID from being erased. The microcomputer 100 may have an OTP function. In this case, the storage area in which the device ID is stored is located in an area different from the area to be reprogrammed. The microcomputer 100 can also OTP the storage area in which the device ID is stored to prevent rewriting in a hardware manner. OTP is an abbreviation for One Time Programming.
[0033] <Processing> Here, the processing operation of the electronic control unit 1 will be described with reference to Figures 3 and 4. As described above, the electronic control unit 1 communicates with the diagnostic tool 2 for fault diagnosis. At that time, the electronic control unit 1 performs challenge-and-response authentication using random numbers to authenticate the diagnostic tool 2. Therefore, here, the processing operation of the diagnostic tool 2 will also be described with reference to Figure 2. Note that the processing operation of the electronic control unit 1 is mainly the processing operation of the CPU 10.
[0034] The diagnostic tool 2 starts the flowchart of FIG. 2 in response to instructions from the operator.
[0035] In step S10, the diagnostic tool 2 requests authentication by transmitting a request signal to the electronic control unit 1.
[0036] In step S11, it is determined whether or not a random number has been received. If the diagnostic tool 2 determines that a random number has been received from the electronic control device 1, it proceeds to step S12, and if it determines that a random number has not been received, it repeats step S11. The diagnostic tool 2 receives a random number from the electronic control device 1 by making an authentication request.
[0037] In step S12, a hash value is calculated from the received random number and password (PW). The diagnostic tool 2 calculates a hash value, which is a response signal, using the received random number and a predetermined password. Note that a hash value is used here as an example of a response signal. However, the diagnostic tool 2 may be any tool that calculates a response signal using a random number.
[0038] The electronic control unit 1 may transmit a data string generated from a random number. In this case, the diagnostic tool 2 calculates a response signal using the data string. In other words, the electronic control unit 1 may authenticate the diagnostic tool 2 using a value correlated to the random number.
[0039] In step S13, the diagnostic tool 2 returns the hash value generated in step S12 to the electronic control unit 1 in response to the received random number.
[0040] In step S14, it is determined whether or not diagnostic data has been received. If the diagnostic tool 2 determines that diagnostic data has been received from the electronic control unit 1, it proceeds to step S15, and if it determines that diagnostic data has not been received, it repeats step S14. The diagnostic tool 2 receives diagnostic data from the electronic control unit 1 by returning a hash value. More specifically, the diagnostic tool 2 receives diagnostic data from the electronic control unit 1 when it is determined that the electronic control unit 1 is a legitimate communication partner through authentication using the hash value.
[0041] In step S15, the diagnostic tool 2 performs diagnostic processing on the electronic control unit 1 using the received diagnostic data. That is, the diagnostic tool 2 performs a fault diagnosis on the electronic control unit 1.
[0042] On the other hand, when an authentication request is made, the electronic control device 1 starts the flowchart of Fig. 3. The flowchart of Fig. 3 is a process executed by the CPU 10. Therefore, the CPU 10 starts the flowchart of Fig. 3 when the communication device receives a request signal.
[0043] In step S20, a random number generation process is performed. This random number generation process will be described in detail later. In this embodiment, as an example, the random number generation process is performed when an authentication request is received. However, the CPU 10 may perform the random number generation process at other times. For example, the CPU 10 may perform the random number generation process when the ignition switch is switched from off to on. Furthermore, the CPU 10 may perform the random number generation process when the supply of operating power to the electronic control device 1 is started.
[0044] In step S21, the random number is transmitted. The CPU 10 transmits the random number generated in step S20 to the diagnostic tool 2. At this time, the CPU 10 transmits the random number via a communication device.
[0045] In step S22, it is determined whether or not a hash value has been received. If the CPU 10 determines that a hash value has been received from the diagnostic tool 2, it proceeds to step S23, and if it determines that a hash value has not been received, it repeats step S22. The CPU 10 receives the hash value from the diagnostic tool 2 by transmitting a random number. The electronic control device 1 receives the hash value via a communication device. Then, the CPU 10 acquires the received hash value.
[0046] In step S23, authentication is performed using the hash value. The CPU 10 authenticates the diagnostic tool 2 using the received hash value. That is, the CPU 10 calculates a hash value using random numbers, just like the diagnostic tool 2. The CPU 10 authenticates the diagnostic tool 2 by comparing the received hash value with the calculated hash value.
[0047] In step S24, it is determined whether authentication is successful. If both hash values match, the CPU 10 determines that authentication is successful and proceeds to step S25. In other words, if both hash values match, the CPU 10 determines that the diagnostic tool 2 that sent the hash value is a valid communication partner. On the other hand, if both hash values do not match, the CPU 10 determines that authentication is unsuccessful and ends the flowchart of FIG. 3. In other words, if both hash values do not match, the CPU 10 determines that the diagnostic tool 2 that sent the hash value is not a valid communication partner.
[0048] In step S25, diagnostic communication is performed. The CPU 10 transmits diagnostic data to the diagnostic tool 2. The CPU 10 transmits the diagnostic data via the communication device.
[0049] Here, the random number generation process will be described with reference to FIG.
[0050] In step S30, the number of times a random number is generated is acquired (unique value acquisition unit). The CPU 10 (entropy source generation unit 11) acquires the number of times a random number is generated from the NVM 22. It can also be said that the CPU 10 refers to the number of times a random number is generated stored in the NVM 22. The number of times a random number is generated is the number of times a random number has been generated up to the current random number generation process.
[0051] In this way, the CPU 10 acquires the random number generation count for use in generating random numbers. The random number generation count is a unique value for each random number generated. Furthermore, the CPU 10 writes the generated random number to the NVM 22. The NVM 22 has a limited number of times it can be written. In other words, a finite limit can be placed on the random number generation itself. Therefore, the electronic control device 1 can reduce the probability that the random numbers it generates will match.
[0052] In step S32, a device ID is acquired (unique value acquisition unit). The CPU 10 (entropy source generation unit 11) acquires the device ID from the ROM 21. It can also be said that the CPU 10 refers to the device ID stored in the ROM 21. The CPU 10 may execute step S32 before step S30.
[0053] In step S34, it is determined whether the number of times the random number is generated is equal to or greater than the upper limit (determination unit). The CPU 10 (upper limit check unit 13) compares the number of times the random number is generated stored in the NVM 22 with the upper limit. The CPU 10 also compares the number of times the random number is generated with the upper limit to determine whether the number of times the random number is generated can be obtained.
[0054] If the CPU 10 determines that the number of times a random number is generated is less than the upper limit, it considers that it is possible to obtain the number of times a random number is generated, and proceeds to step S36. The fact that it is possible to obtain the number of times a random number is generated means that it is possible to obtain the number of times a random number is generated, which is a unique value for each random number generated. If the upper limit check unit 13 determines that the number of times a random number is generated is less than the upper limit, it passes a value indicating that the number of times a random number is generated has not reached the upper limit to the random number generation unit 12 as the check result.
[0055] On the other hand, if the CPU 10 determines that the number of random number generation times is equal to or greater than the upper limit, it considers that it is not possible to obtain the number of random number generation times and ends the flowchart of Figure 4. If the number of random number generation times has reached the upper limit, the number of random number generation times stored in the NVM 22 is not updated. Therefore, the CPU 10 cannot obtain the number of random number generation times, which is a unique value for each random number generation. In other words, the CPU 10 obtains the number of random number generation times, which is the same value as the upper limit.
[0056] Even if the CPU 10 generates random numbers using such a random number generation count, there is a risk that the random numbers generated will not have large variations. Therefore, if the random number generation count has reached the upper limit, the CPU 10 ends the flowchart in FIG. 4 without generating any more random numbers.
[0057] "Not being able to obtain the number of times a random number is generated" means that it is not possible to obtain the number of times a random number is generated, which is a unique value for each random number generated. In other words, "not being able to obtain the number of times a random number is generated" means that although the number of times a random number is generated can be obtained, the number of times the same value is obtained. If upper limit value check unit 13 determines that the number of times a random number is generated is greater than or equal to the upper limit value, it passes a value indicating that the number of times a random number is generated that has reached the upper limit value to random number generation unit 12 as the check result.
[0058] Furthermore, it is conceivable that an attacker may attempt to generate (attempt) random numbers in the electronic control device 1. The electronic control device 1 can limit the number of attempts by an attacker by setting an upper limit on the number of times random numbers can be generated. Note that the upper limit may be a value smaller than the number of times NVM 22 can be written. This allows the electronic control device 1 to further limit the number of attempts by an attacker.
[0059] In step S36, an entropy input is generated from the device ID and the number of random number generation times. The CPU 10 (entropy source generation unit 11) generates the entropy input from the number of random number generation times and the device ID acquired in steps S30 and S32. The entropy source generation unit 11 passes the generated entropy input to the random number generation unit 12.
[0060] The entropy source generation unit 11 generates the entropy input by combining a value indicating the number of times a random number has been generated and a value indicating a device ID. For example, the entropy input is generated by concatenating the value indicating the number of times a random number has been generated and the value indicating a device ID. Alternatively, the entropy input may be generated by performing an XOR (exclusive OR) operation on the value indicating the number of times a random number has been generated and the value indicating a device ID. However, the method of generating the entropy input is not limited to these. The entropy input generated from the number of times a random number has been generated and the device ID can be said to be a value that correlates with the number of times a random number has been generated and the device ID.
[0061] In step S38, a random number is generated from the entropy input (generation unit). The CPU 10 (random number generation unit 12) generates a random number using the entropy input generated in step S36. Note that the entropy source generation unit 11 and the random number generation unit 12 may be a single functional block.
[0062] The CPU 10 generates random numbers in accordance with a predetermined standard. That is, the CPU 10 creates a seed value from entropy input and generates random numbers using the seed value. In other words, the CPU 10 generates random numbers using a method with established security. However, the CPU 10 may generate random numbers using a method that differs from the standard.
[0063] As described above, CPU 10 executes steps S36 and S38 only if the number of times the random number has been generated has not reached the upper limit. In other words, CPU 10 generates entropy input and random numbers only if the number of times the random number has been generated has not reached the upper limit. It can also be said that CPU 10 generates entropy input and random numbers only if it can obtain a random number generation count that is a unique value for each random number generated.
[0064] It can also be said that the CPU 10 generates random numbers using a value correlated with the number of times the random number is generated and a value correlated with the device ID. It can also be said that the CPU 10 generates random numbers from entropy input including the number of times the random number is generated and the device ID.
[0065] The CPU 10 generates a random number to be used for authenticating the diagnostic tool 2. However, the CPU 10 may also generate in advance a plurality of random numbers to be used for different purposes (random number generation unit). For example, in step S38, the CPU 10 generates random numbers to be used for other purposes in addition to the random number to be used for authenticating the diagnostic tool 2. At this time, the CPU 10 generates random number data including a plurality of random numbers for different purposes and stores the data in the NVM 22, for example. Then, when using a random number, the CPU 10 reads out the random number according to the purpose from the NVM 22 and uses it. This allows the electronic control unit 1 to reduce the number of times the CPU 10 performs random number generation processing.
[0066] <Effects> In this way, the electronic control unit 1 generates a random number using the random number generation count, which is a unique value, and the device ID, which is a specific value. Therefore, the electronic control unit 1 can generate a different random number for a specific application each time it generates it. It can also be said that the electronic control unit 1 can generate random numbers with a large variance. In other words, the electronic control unit 1 can increase the variance for each random number it generates. It can also be said that the electronic control unit 1 can reduce the regularity of each random number it generates.
[0067] Furthermore, the device ID is different for each electronic control device 1. On the other hand, the random number generation count is a different value for each random number generation. Therefore, even if an attacker analyzes random numbers obtained from another electronic control device, it is difficult for the attacker to obtain the random number generation count or the device ID from the analysis information.
[0068] Furthermore, the electronic control unit 1 uses the generated random numbers to perform authentication between itself and the diagnostic tool 2. The electronic control unit 1 can generate random numbers with large variations, thereby improving confidentiality in authentication.
[0069] In this embodiment, an example is adopted in which only the number of times a random number is generated is used as an example of a unique value. However, the present disclosure can also use a unique value that combines the number of times a random number is generated with other values. As other values, values that are acquired by the electronic control unit 1 and that are different each time the electronic control unit 1 is started can be used. The CPU 10 acquires the acquired value in step S30. The acquired value is, for example, the number of times the ignition switch is turned on, the odometer value, time information, etc. Furthermore, in this embodiment, the acquired value can also be used as the unique value instead of the number of times a random number is generated.
[0070] (Variation) A modified example of the electronic control unit 1 will be described with reference to Fig. 5. As shown in Fig. 5, the CPU 10 may execute step S34a instead of step S34.
[0071] In step S34a, it is determined whether the random number generation count was successfully read (determination unit). If the CPU 10 determines that the random number generation count was successfully read, it considers that it is possible to obtain the random number generation count, and proceeds to step S36. If the CPU 10 determines that it was not possible to read the random number generation count, it considers that it is not possible to obtain the random number generation count, and ends the flowchart of FIG. 5. This also allows the electronic control device 1 to achieve the same effect as above.
[0072] (Second embodiment) An electronic control device 1a of the second embodiment will be described with reference to Figures 6 and 7. Here, the differences between the electronic control device 1a and the electronic control device 1 will be mainly described. The electronic control device 1 differs from the microcomputer 100 mainly in the configuration of the microcomputer 100a and the processing operation of the CPU 10a.
[0073] As shown in FIG. 6, the microcomputer 100a includes a free-running timer 30 in addition to the components of the microcomputer 100. The free-running timer 30 is cleared when the power is turned on or reset, and counts up. The free-running timer 30 outputs the counted-up timer value. In the drawing, the free-running timer 30 is represented as TMR, and the timer value is represented as TMV.
[0074] The microcomputer 100a also includes a CPU 10a instead of the CPU 10. The CPU 10a differs from the CPU 10 in that a timer value is input to the CPU 10a and in the processing operation.
[0075] Here, the random number generation process of the CPU 10a will be described with reference to Fig. 7. In Fig. 7, the same processes as those in Fig. 4 are assigned the same step numbers.
[0076] In step S33, the timer value is acquired (timer value acquisition unit). The CPU 10a acquires the timer value of the free-run timer. Note that the order in which the CPU 10a executes steps S30, S32, and S33 is not particularly limited.
[0077] In step S36a, an entropy input is generated from the device ID, the number of random number generation times, and the timer value. The CPU 10a (entropy source generation unit 11a) generates the entropy input from the number of random number generation times, the device ID, and the timer value acquired in steps S30, S32, and S33. The entropy source generation unit 11 passes the generated entropy input to the random number generation unit 12.
[0078] The entropy source generation unit 11 generates an entropy input by combining a value indicating the number of times a random number is generated, a value indicating a device ID, and a timer value. For example, the entropy input is generated by concatenating a value indicating the number of times a random number is generated, a value indicating a device ID, and a timer value. Alternatively, the entropy input is generated by performing an XOR operation on a value indicating the number of times a random number is generated, a value indicating a device ID, and a timer value. However, the method of generating the entropy input is not limited to this. The entropy input generated from the number of times a random number is generated, the device ID, and the timer value can be said to be a value correlated with the number of times a random number is generated, the device ID, and the timer value. The timer value can also be said to be generation information or generation data, which is information for generating random numbers.
[0079] In step S38a, a random number is generated from the entropy input (generation unit). The CPU 10a (random number generation unit 12) generates a random number using the entropy input generated in step S36a. The method of generating the random number is the same as in the first embodiment.
[0080] It can also be said that the CPU 10 generates random numbers using a value correlated with the number of times the random number is generated, a value correlated with the device ID, and a value correlated with the timer value.Furthermore, it can also be said that the CPU 10 generates random numbers from entropy input including the number of times the random number is generated, the device ID, and the timer value.
[0081] The electronic control device 1a can achieve the same effects as the electronic control device 1. Furthermore, the electronic control device 1a generates random numbers using a timer value. Therefore, the electronic control device 1a can generate random numbers with greater variance than the electronic control device 1. Note that, like the CPU 10, the CPU 10a may execute steps S36a and S38a only when the number of random number generation times has not reached the upper limit value.
[0082] Note that CPU 10a generates random numbers using only a portion of the random number generation count, device ID, and timer value, but may also generate random numbers using all of the random number generation count, device ID, and timer value by performing an input addition process (generation unit). That is, CPU 10a generates a seed value using only a portion of the random number generation count, device ID, and timer value, and generates random numbers from that seed value (basic generation unit). Then, CPU 10a performs an input addition process to generate a seed value by adding information for generation that is not used in the first generation unit among the random number generation count, device ID, and timer value, and generates random numbers from that seed value (additional generation unit). Note that "only a portion" refers to one of the random number generation count, device ID, and timer value, or two of the random number generation count, device ID, and timer value.
[0083] For example, the CPU 10a generates a seed value using only the timer value, and generates a random number from that seed value. Then, by performing an input addition process, the CPU 10a generates a seed value using the timer value, the random number generation count, and the device ID, and generates a random number from that seed value. The timer value can also be considered a first entropy input. On the other hand, the random number generation count and the device ID can also be considered additional entropy input. In this way, by performing the input addition process, the CPU 10a can generate a random number using all of the random number generation count, the device ID, and the timer value. In this embodiment, the device ID is stored in the ROM 21. However, the present disclosure is not limited to this. The device ID may be stored in the NVM 22. Also, a portion of the area in the ROM 21 may be allocated as a storage destination for the number of times a random number is generated.
[0084] The CPU 10a can also use CtrDRBG as the random number generation algorithm. In this case, the CPU 10a can generate random numbers using the first entropy input and the additional entropy input by executing the process defined by the Reseed Function.
[0085] Although the present disclosure has been described with reference to the embodiments, it is understood that the present disclosure is not limited to the embodiments or structures. The present disclosure also encompasses various modifications and modifications within the scope of equivalents. In addition, although various combinations and forms are shown in the present disclosure, other combinations and forms including only one element, more, or less than one element are also within the scope and spirit of the present disclosure.
[0086] (Disclosure of technical ideas) This specification discloses multiple technical ideas described in the following multiple clauses. Some clauses may be written in a multiple dependent form, with the subsequent clause referring to the preceding clause as an alternative. Furthermore, some clauses may be written in a multiple dependent form, referring to another multiple dependent clause. These multiple dependent clauses define multiple technical ideas.
[0087] (Technical thought 1) An electronic control device having a function of generating random numbers, a unique value acquisition unit (S30) that acquires a unique value that is unique for each generation of the random number; an eigenvalue acquisition unit (S32) that acquires an eigenvalue that is unique to the electronic control device; a generation unit (S38, S38a) that generates the random number using the unique value and the characteristic value.
[0088] (Technical thought 2) A timer value acquisition unit (S33) for acquiring a timer value of the free-run timer is further provided, The electronic control device according to Technical Idea 1, wherein the generation unit generates the random number using the timer value in addition to the unique value and the eigenvalue.
[0089] (Technical Thought 3) The electronic control device according to Technical Idea 1 or 2, wherein the unique value acquisition unit acquires the number of times the random number has been generated by the generation unit as the unique value.
[0090] (Technical Thought 4) The electronic control device according to any one of Technical Ideas 1 to 3, wherein the unique value acquisition unit acquires a different value as the unique value each time the electronic control device is started.
[0091] (Technical Thought 5) further comprising a determination unit (S34, 34a) that determines whether or not the unique value can be acquired by the unique value acquisition unit; 5. The electronic control device according to any one of Technical Ideas 1 to 4, wherein the generation unit stops generating the random number when it is determined that the unique value cannot be acquired.
[0092] (Technical Thought 6) The generation unit generates the random number using only a portion of the unique value, the eigenvalue, and the timer value, and by performing an input addition process, the electronic control device described in Technical Idea 2 generates the random number using all of the unique value, the eigenvalue, and the timer value.
[0093] (Technical Thought 7) a storage device that stores control software and the eigenvalues; The electronic control device according to any one of Technical Concepts 1 to 6, wherein the eigenvalue is written in the storage device during a manufacturing process of the electronic control device.
[0094] (Technical Thought 8) the software and the unique value are stored in different storage areas of the storage device; The electronic control device according to Technical Idea 7, wherein the storage area in which the unique value is stored is an area that is not rewritten by reprogramming the software.
[0095] (Technical Thought 9) The electronic control device according to any one of Technical Ideas 1 to 8, wherein the generating unit generates in advance a plurality of the random numbers to be used for different purposes.
[0096] (Technical Thought 10) 10. An electronic control device according to any one of Technical Ideas 1 to 9, which controls a motor as a controlled object.
[0097] (Technical Thought 11) The electronic control device is configured to be able to communicate with an external device provided outside the electronic control device, 11. The electronic control device according to any one of Technical Ideas 1 to 10, wherein authentication is performed between the electronic control device and the external device using the random number generated by the generating unit. [Explanation of symbols]
[0098] 1...Electronic control device, 10...CPU, 20...Storage device, 21...ROM, 22...NVM, 100...Microcontroller
Claims
1. An electronic control device having a function of generating random numbers, a unique value acquisition unit (S30) that acquires a unique value that is different each time the random number is generated; an eigenvalue acquisition unit (S32) that acquires an eigenvalue that is unique to the electronic control device; a generating unit (S38, S38a) that generates the random number using the unique value and the characteristic value.
2. A timer value acquisition unit (S33) for acquiring a timer value of the free-run timer is further provided, The electronic control device according to claim 1 , wherein the generating unit generates the random number by using the timer value in addition to the unique value and the inherent value.
3. The electronic control device according to claim 1 or 2, wherein the unique value acquisition unit acquires, as the unique value, the number of times the random number has been generated by the generation unit.
4. The electronic control device according to claim 1 or 2, wherein the unique value acquisition unit acquires a different value as the unique value each time the electronic control device is started.
5. The apparatus further includes a determination unit (S34, 34a) that determines whether or not the unique value can be acquired by the unique value acquisition unit, The electronic control device according to claim 1 or 2, wherein the generation unit stops generating the random number when it is determined that the unique value cannot be obtained.
6. The electronic control device described in claim 2, wherein the generation unit generates the random number using only a portion of the unique value, the eigenvalue, and the timer value, and by performing an input addition process, the random number is generated using all of the unique value, the eigenvalue, and the timer value.
7. a storage device that stores control software and the eigenvalues; 3. The electronic control device according to claim 1, wherein the eigenvalue is written in the storage device during a manufacturing process of the electronic control device.
8. the software and the unique value are stored in different storage areas of the storage device; 8. The electronic control device according to claim 7, wherein the storage area in which the unique value is stored is an area that is not rewritten by reprogramming the software.
9. The electronic control device according to claim 1 or 2, wherein the generating unit generates a plurality of the random numbers in advance to be used for different purposes.
10. 3. The electronic control device according to claim 1, wherein the electronic control device controls a motor as a controlled object.
11. The electronic control device is configured to be able to communicate with an external device provided outside the electronic control device, 3. The electronic control device according to claim 1, wherein authentication is performed between the electronic control device and the external device using the random number generated by the generating unit.
Citation Information
Patent Citations
Collecting entropy from diverse sources
JP2019531541A