Data management system and data management method
The data management system addresses the inefficiency and cost of SE replacement by using a control device and tamper-resistant storage device for secure data updates, ensuring secure communication and efficient data management.
Patent Information
- Application Number
- JP2024090658
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-04
- Publication Date
- 2025-12-16
AI Technical Summary
The replacement of secure elements (SEs) due to data leakage is costly and inefficient, as data such as key values, seed values, or certificates are vulnerable to malicious use if leaked.
A data management system comprising a control device (ECU) and a tamper-resistant storage device (SE) that perform mutual authentication using a session key, encrypt and decrypt data with the session key, and securely store the decrypted data, eliminating the need for SE replacement.
The system enables secure data updates without the cost and effort of replacing SEs, ensuring secure communication and efficient data management.
Smart Images

Figure 2025182905000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a data management system and a data management method. [Background technology]
[0002] Secure elements (SEs), which are tamper-resistant secure IC chips, are used in in-vehicle wireless charging and digital keys. SEs are used for cryptographic calculations for mutual authentication between devices (external devices) and vehicles, and these calculations use key values or seed values shared in advance between the device and vehicle. Certificates may also be used to prove the authenticity of devices and vehicles.
[0003] Patent Document 1 describes that an SE in a management device installed in a vehicle generates and updates keys. Patent Document 2 describes that a management server device outside the vehicle generates an initial key and distributes the initial key to the management device. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-188959 [Patent Document 2] Japanese Patent Application Laid-Open No. 2017-195631 Summary of the Invention [Problem to be solved by the invention]
[0005] Since data such as key values, seed values, or certificates are used for cryptographic calculations, if the data is leaked to a malicious third party, the third party may use the data for fraudulent purposes. Therefore, when the SE installed in a vehicle is manufactured, predetermined keys or certificates are stored in the SE, and the keys or certificates are used for cryptographic calculations.
[0006] When data stored in an SE needs to be updated, the entire SE is often replaced for security reasons, but replacing an SE requires a lot of cost and effort.
[0007] An object of the present invention is to provide a data management system and a data management method that can eliminate the cost and effort required for replacing a secure element. [Means for solving the problem]
[0008] The present invention is a data management system comprising a control device mounted on a vehicle and a tamper-resistant storage device mounted on the vehicle, wherein the control device comprises a first authentication unit that performs mutual authentication with the storage device by using a session key, an encryption processing unit that encrypts data with the session key, and an output unit that outputs the encrypted data to the storage device, and the storage device comprises a second authentication unit that performs mutual authentication with the control device by using the session key, a decryption unit that decrypts the encrypted data with the session key, and a storage unit that stores the decrypted data.
[0009] The present invention is a data management method that uses a control device mounted on a vehicle and a tamper-resistant storage device mounted on the vehicle, the data management method comprising an authentication step in which the control device and the storage device perform mutual authentication using a session key, an encryption step in which the control device encrypts data with the session key, an output step in which the control device outputs the encrypted data to the storage device, a decryption step in which the storage device decrypts the encrypted data with the session key, and a storage step in which the storage device stores the decrypted data in a memory unit. [Effects of the Invention]
[0010] According to the present invention, the data management system and data management method can eliminate the cost and effort required to replace a secure element. [Brief explanation of the drawings]
[0011] [Figure 1] 1 is a block diagram showing the configuration of a data management system according to an embodiment of the present invention; [Figure 2] FIG. 3 is a sequence diagram illustrating an example of processing executed by a data management system according to an embodiment of the present invention. [Figure 3] FIG. 3 is a sequence diagram illustrating an example of processing executed by a data management system according to an embodiment of the present invention. [Figure 4] FIG. 3 is a sequence diagram illustrating an example of processing executed by a data management system according to an embodiment of the present invention. [Figure 5] FIG. 3 is a sequence diagram illustrating an example of processing executed by a data management system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. Fig. 1 shows the configuration of a data management system 1 according to an embodiment of the present invention. The data management system 1 is mounted on a vehicle and has a communication device 10, an ECU (Electronic Control Unit) 11, and a secure element (SE) 12. The vehicle on which the data management system 1 is mounted may be a four-wheeled automobile or a motorcycle.
[0013] The communication device 10 communicates with an external device 2 disposed outside the vehicle. The communication device 10 may be disposed inside the body of the vehicle, or may be attached to the surface of the body.
[0014] The ECU 11 is a control device disposed inside the vehicle body. The ECU 11 has a first control unit 110, a first authentication unit 111, and a first encryption processing unit 112. The first control unit 110 controls each unit in the ECU 11. The first authentication unit 111 performs mutual authentication with the SE 12. The first encryption processing unit 112 performs encryption and decryption of data.
[0015] The ECU 11 may be realized by a processor such as a CPU (Central Processing Unit) executing a program recorded on a computer-readable recording medium. The ECU 11 may be realized by hardware (circuitry) such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array). The ECU 11 may also be realized by a combination of software and hardware.
[0016] The computer-readable recording medium may be a portable medium such as a flexible disk, a magneto-optical disk, a ROM, or a CD-ROM, or a storage unit such as a hard disk built into a computer system. The above-mentioned program may be a differential file (differential program). The function of the ECU 11 may be realized by combining a program already stored in the computer with the differential program.
[0017] The SE12 is a tamper-resistant storage device arranged inside the vehicle body. The SE12 has a second control unit 120, a second authentication unit 121, a second encryption processing unit 122, and a storage unit 123. The second control unit 120 controls each unit in the SE12. The second authentication unit 121 performs mutual authentication with the ECU 11. The second encryption processing unit 122 encrypts and decrypts data. The storage unit 123 is a storage medium that stores data. A user cannot directly access the data stored in the storage unit 123.
[0018] At least one of the second control unit 120, the second authentication unit 121, and the second crypto-processing unit 122 may be realized by a processor executing a program recorded on a computer-readable recording medium. At least one of the second control unit 120, the second authentication unit 121, and the second crypto-processing unit 122 may be realized by hardware (circuitry). At least one of the second control unit 120, the second authentication unit 121, and the second crypto-processing unit 122 may be realized by a combination of software and hardware.
[0019] 2 and 3 show an example of a process for updating a certificate stored in the storage unit 123 of the SE 12. The process executed by the data management system 1 for updating a certificate will be described using FIGS.
[0020] (Step S100) The external device 2 is a server, but may be a device other than a server. For example, the external device 2 is a certification authority (CA) that issues a CA certificate. The external device 2 may receive a CA certificate issued by the CA from the CA.
[0021] (Step S101) The external device 2 transmits the CA certificate to the communication device 10. The communication device 10 receives the CA certificate.
[0022] (Step S102) The communication device 10 outputs the CA certificate to the ECU 11. The first control unit 110 of the ECU 11 receives the CA certificate.
[0023] (Step S103) The first control unit 110 of the ECU 11 outputs a SELECT command including information specifying an application that uses the CA certificate to the SE 12. The second control unit 120 of the SE 12 receives the SELECT command.
[0024] (Step S104) The second control unit 120 selects the application specified by the SELECT command.
[0025] (Step S105) The second control unit 120 outputs the response to the ECU 11. The first control unit 110 of the ECU 11 receives the response.
[0026] (Step S106) The first control unit 110 generates a random number M and outputs the random number M to the SE 12. The second control unit 120 of the SE 12 receives the random number M. A mutual authentication command defined in the Global Platform may be used to output the random number M. Alternatively, a mutual authentication command uniquely defined in the selected application may be used to output the random number M.
[0027] (Step S107) The second cryptographic processing unit 122 generates a random number N different from the random number M, and generates a session key using the random numbers M and N. The session key is a common key. The second cryptographic processing unit 122 combines the random numbers M and N, and encrypts the combined random number with the session key to generate ciphertext A.
[0028] (Step S108) The second control unit 120 outputs the random number N and the ciphertext A to the ECU 11. The first control unit 110 of the ECU 11 receives the random number N and the ciphertext A.
[0029] (Step S109) The first cryptographic processing unit 112 generates a session key by using the random numbers M and N. The first cryptographic processing unit 112 generates ciphertext A by combining the random numbers M and N and encrypting the combined random number with the session key.
[0030] (Step S110) The first authentication unit 111 verifies the legitimacy of the SE12 by comparing the ciphertext A received from the SE12 in step S108 with the ciphertext A generated in step S109. If the two ciphertexts A match, the first authentication unit 111 determines that the SE12 is legitimate. If the two ciphertexts A do not match, the first authentication unit 111 determines that the SE12 is not legitimate. If the first authentication unit 111 determines that the SE12 is not legitimate, the first control unit 110 transmits a notification indicating that the certificate update has failed to the external device 2 via the communication device 10.
[0031] (Step S111) If the first authentication unit 111 determines that SE12 is legitimate, the first encryption processing unit 112 generates ciphertext B by combining the random numbers M and N and encrypting the combined random number with the session key.
[0032] (Step S112) First control unit 110 outputs ciphertext B to SE 12. Second control unit 120 of SE 12 receives ciphertext B. A mutual authentication command defined in the Global Platform may be used to output ciphertext B. Alternatively, a mutual authentication command uniquely defined in the selected application may be used to output ciphertext B.
[0033] (Step S113) The second cryptographic unit 122 generates ciphertext B by combining the random numbers M and N and encrypting the combined random number with the session key.
[0034] (Step S114) The second authentication unit 121 verifies the legitimacy of the ECU 11 by comparing the ciphertext B received from the ECU 11 in step S112 with the ciphertext B generated in step S113. If the two ciphertexts B match, the second authentication unit 121 determines that the ECU 11 is legitimate. If the two ciphertexts B do not match, the second authentication unit 121 determines that the ECU 11 is not legitimate.
[0035] (Step S115) The second control unit 120 outputs a response indicating the verification result to the ECU 11. The first control unit 110 of the ECU 11 receives the response. If the second authentication unit 121 determines that the ECU 11 is not valid, the first control unit 110 transmits a notification indicating that the certificate update has failed to the external device 2 via the communication device 10.
[0036] (Step S116) The first cryptographic processing unit 112 encrypts the CA certificate received in step S102 with a session key. The first cryptographic processing unit 112 also generates a message authentication code (MAC) by encrypting a hash value generated from a message with the session key. The first cryptographic processing unit 112 may also generate a MAC by encrypting a hash value generated from the encrypted CA certificate with the session key.
[0037] (Step S117) The first control unit 110 outputs the encrypted CA certificate, the MAC, and the message used to generate the MAC to the SE 12. The second control unit 120 of the SE 12 receives the CA certificate, the MAC, and the message.
[0038] (Step S118) The second cryptographic processing unit 122 generates a MAC by encrypting the hash value generated from the message received in step S117 with the session key. The second authentication unit 121 performs message authentication by comparing the generated MAC with the MAC received in step S117. If the two MACs match, the second authentication unit 121 determines that the message has not been tampered with. If the two MACs do not match, the second authentication unit 121 determines that the message has been tampered with.
[0039] (Step S119) The second encryption processing unit 122 decrypts the CA certificate received in step S117 using the session key.
[0040] (Step S120) The second control unit 120 stores the decrypted CA certificate in the storage unit 123.
[0041] (Step S121) The second cryptographic processing unit 122 encrypts the response with the session key. After the response is encrypted, the second cryptographic processing unit 122 deletes the session key. If the second authentication unit 121 determines in step S118 that the message has not been tampered with, the response indicates that the update of the CA certificate has been completed. If the second authentication unit 121 determines in step S118 that the message has been tampered with, the response indicates that the update of the CA certificate has not been completed.
[0042] (Step S122) The second control unit 120 outputs the response to the ECU 11. The first control unit 110 of the ECU 11 receives the response.
[0043] (Step S123) The first crypto-processing unit 112 decrypts the response with the session key, and after the response is decrypted, the first crypto-processing unit 112 deletes the session key.
[0044] (Step S124) If the response indicates that the CA certificate update has been completed, the second control unit 120 outputs a completion notification to the communication device 10. If the response indicates that the CA certificate update has not been completed, the first control unit 110 transmits a notification to the external device 2 via the communication device 10 indicating that the certificate update has failed.
[0045] (Step S125) The communication device 10 transmits a completion notification to the external device 2. The external device 2 receives the completion notification.
[0046] If the data length of the CA certificate is long, the first cryptographic processing unit 112 may divide the CA certificate into two or more divided data pieces in step S116. The first cryptographic processing unit 112 may encrypt each divided data piece with a session key. Steps S117 to S122 are executed for each divided data piece. The second control unit 120 generates the original CA certificate by combining the two or more decrypted divided data pieces and stores the CA certificate in the memory unit 123.
[0047] If the CA certificate is divided into two or more data segments, message authentication is performed for each data segment in step S118. If MAC verification is successful for all data segments, the CA certificate update is completed. If MAC verification fails for one or more data segments, the CA certificate update is aborted.
[0048] When the CA certificate is divided into two or more divided data, each encrypted divided data is transmitted from the ECU 11 to the SE 12. An identifier indicating whether or not each divided data is the last divided data is added to each divided data. The second encryption processing unit 122 decrypts the divided data to which the identifier indicating that it is the last divided data is added, and then deletes the session key.
[0049] Any protocol may be used for communication between the external device 2 and the communication device 10. Any protocol may be used for communication between the communication device 10 and the ECU 11 and between the ECU 11 and the SE 12.
[0050] 4 and 5 show an example of processing for updating the seed value stored in the storage unit 123 of the SE 12. Processing executed by the data management system 1 for updating the seed value will be described using Fig. 4 and Fig. 5. Description of processing that is the same as the processing shown in Fig. 2 and Fig. 3 will be omitted.
[0051] The external device 2 is a smartphone, an IC card, etc. Figures 4 and 5 show an example in which the external device 2 is a smartphone.
[0052] (Step S130) The external device 2 performs user authentication. For example, the external device 2 performs biometric authentication or password authentication. If the external device 2 does not have a user authentication function, step S130 may be omitted.
[0053] (Step S131) If the user authentication is successful, the user inputs a seed value into the external device 2. The external device 2 may generate the seed value internally.
[0054] (Step S101a) The external device 2 transmits a seed value to the communication device 10. The communication device 10 receives the seed value.
[0055] (Step S102a) The communication device 10 outputs the seed value to the ECU 11. The first control unit 110 of the ECU 11 receives the seed value.
[0056] Steps S103 to S115 are the same as steps S103 to S115 shown in FIGS. 2 and 3, respectively.
[0057] (Step S116a) First cryptographic processing unit 112 encrypts the seed value received in step S102a with the session key, and also generates a MAC by encrypting a hash value generated from a message with the session key.
[0058] (Step S117a) The first control unit 110 outputs the encrypted seed value, the MAC, and the message used to generate the MAC to the SE 12. The second control unit 120 of the SE 12 receives the seed value, the MAC, and the message.
[0059] Step S118 is the same as step S118 shown in FIG.
[0060] (Step S119a) The second encryption processing unit 122 decrypts the seed value received in step S117a with the session key.
[0061] (Step S120a) The second control unit 120 stores the decrypted seed value in the storage unit 123.
[0062] Steps S121 to S125 are the same as steps S121 to S125 shown in FIG.
[0063] Any protocol may be used for communication between the external device 2 and the communication device 10. The external device 2 and the communication device 10 may perform near field communication (NFC) to prevent erroneous recognition of each other. Any protocol may be used for communication between the communication device 10 and the ECU 11 and between the ECU 11 and the SE 12. Key value updating may be performed through processing similar to that shown in FIGS. 4 and 5.
[0064] As described above, the data management system 1 includes an ECU 11 (control device) mounted on a vehicle and a tamper-resistant SE 12 (storage device) mounted on the vehicle. A first authentication unit 111 of the ECU 11 performs mutual authentication with the SE 12 by using a session key. A first encryption processing unit 112 of the ECU 11 encrypts data with the session key. A first control unit 110 (output unit) of the ECU 11 outputs the encrypted data to the SE 12. A second authentication unit 121 of the SE 12 performs mutual authentication with the ECU 11 by using the session key. A second encryption processing unit 122 (decryption unit) of the SE 12 decrypts the encrypted data with the session key. A storage unit 123 of the SE 12 stores the decrypted data.
[0065] Secure communication between the ECU 11 and the SE 12 is possible, and data stored in the SE 12 can be updated. Therefore, the data management system 1 can eliminate the cost and effort required for replacing a secure element.
[0066] The communication device 10 receives data from the external device 2 and outputs the received data to the ECU 11. The communication device 10 can receive data from the external device 2 at any timing. After the communication device 10 receives the data from the external device 2, the ECU 11 can store the data in the SE 12 at any timing. For example, even if the vehicle is traveling through a tunnel or the like and the communication device 10 cannot communicate with the external device 2, the ECU 11 can store the data in the SE 12.
[0067] The first encryption processing unit 112 of the ECU 11 divides the data into two or more partial data and encrypts the partial data with a session key. The first control unit 110 of the ECU 11 outputs the encrypted partial data to the SE 12. The second encryption processing unit 122 of the SE 12 decrypts the encrypted partial data with the session key. The storage unit 123 of the SE 12 stores the decrypted partial data. If the data length is long, the data is divided into two or more partial data, and each partial data is encrypted with the same session key. Therefore, the ECU 11 and the SE 12 can securely communicate each partial data.
[0068] After the data is encrypted, the first cryptographic processing unit 112 of the ECU 11 deletes the session key. Alternatively, after the data is decrypted, the second cryptographic processing unit 122 of the SE 12 deletes the session key. This prevents a third party from using the session key illegally.
[0069] The above has described in detail an embodiment of the present invention with reference to the drawings, but the specific configuration is not limited to the above embodiment, and design changes and the like are also included within the scope that does not deviate from the gist of the present invention. [Explanation of symbols]
[0070] 1 data management system, 10 communication device, 11 ECU, 12 SE, 110 first control unit, 111 first authentication unit, 112 first encryption processing unit, 120 second control unit, 121 second authentication unit, 122 second encryption processing unit, 123 storage unit
Claims
1. A control device mounted on a vehicle and a tamper-resistant storage device mounted on the vehicle, The control device a first authentication unit that performs mutual authentication with the storage device by using a session key; an encryption processing unit that encrypts data with the session key; an output unit that outputs the encrypted data to the storage device; and The storage device a second authentication unit that performs the mutual authentication with the control device by using the session key; a decryption unit that decrypts the encrypted data using the session key; a storage unit that stores the decrypted data; A data management system having:
2. a communication device that receives the data from an external device and outputs the received data to the control device; The data management system of claim 1 .
3. the encryption processing unit divides the data into two or more partial data, and encrypts the partial data with the session key; the output unit outputs the encrypted partial data to the storage device; the decryption unit decrypts the encrypted partial data with the session key; The storage unit stores the data generated by combining the decoded partial data.
3. The data management system according to claim 1.
4. After the data is encrypted, the cryptographic processor deletes the session key.
3. The data management system according to claim 1.
5. After the data is decrypted, the decryption unit deletes the session key.
3. The data management system according to claim 1.
6. A data management method using a control device mounted on a vehicle and a tamper-resistant storage device mounted on the vehicle, comprising: an authentication step in which the control device and the storage device perform mutual authentication by using a session key; an encryption step in which the control device encrypts data with the session key; an output step in which the control device outputs the encrypted data to the storage device; a decryption step in which the storage device decrypts the encrypted data with the session key; a storage step in which the storage device stores the decrypted data in a storage unit; A data management method comprising:
Citation Information
Patent Citations
Management system, management device, management method, and computer program
JP2017188959A
Management device, management system, management method, and computer program
JP2017195631A