On-vehicle system, on-vehicle device, data restoration method, and data restoration program
The in-vehicle system uses environmental information to control data restoration and secure access, reducing illegal data acquisition by ensuring authorized conditions are met and data is erased when not needed.
Patent Information
- Application Number
- JP2024094127
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-11
- Publication Date
- 2025-12-23
AI Technical Summary
Existing in-vehicle systems face the risk of unauthorized access leading to fraudulent restoration of secret data.
An in-vehicle system that includes an acquisition device for environmental information, a judgment device to determine conditions, and a restoration device to acquire and restore distributed data when conditions are met, using a secret sharing scheme to secure data access.
Reduces the risk of illegal data acquisition by ensuring data restoration only occurs under authorized conditions, preventing unauthorized access and erasing data when conditions are no longer met.
Smart Images

Figure 2025185763000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an in-vehicle system, an in-vehicle device, a data restoration method, and a data restoration program. [Background technology]
[0002] Conventionally, techniques have been proposed that use secret sharing schemes to prevent data from being illegally obtained. For example, Patent Document 1 (International Publication No. 2017 / 065209) discloses the following information processing system. that is, the information processing system is an information processing system including M (M represents an integer equal to or greater than 2) storage devices, generating means for generating N (N represents an integer equal to or greater than 2 and equal to or less than M) pieces of shared data from secret data in accordance with a secret sharing scheme; selecting one device group, from a plurality of different device groups each associated with a plurality of different time points, associated with a time point included in a period between the current time point and a time point a predetermined time before the current time point, wherein each of the plurality of device groups includes C (C represents an integer equal to or greater than N and equal to or less than M) storage devices selected from the M storage devices, and storing the generated N pieces of shared data in the N storage devices included in the selected device group; executing a restoration process on one of the plurality of device groups, the restoration process including requesting the shared data from each of at least some of the N storage devices included in the device group, and restoring the secret data from provided data provided in response to the request in accordance with the secret sharing scheme, and if the restoration fails, restoring means for executing the restoration process on a device group, from the plurality of device groups, associated with a time point earlier than the time point associated with the device group that caused the failure. Equipped with. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] International Publication No. 2017 / 065209 Summary of the Invention [Problem to be solved by the invention]
[0004] In the technique described in Patent Document 1, there is a possibility that secret data may be fraudulently restored by unauthorized access to the device that generated the shared data or the transmission path of the shared data.
[0005] The present disclosure has been made to solve the above-mentioned problems, and its purpose is to provide an in-vehicle system, an in-vehicle device, a data recovery method, and a data recovery program that can reduce the risk of data in the in-vehicle system being illegally obtained. [Means for solving the problem]
[0006] The in-vehicle system of the present disclosure is an in-vehicle system mounted on a vehicle, and includes an acquisition device that acquires environmental information of the vehicle, a judgment device that performs a judgment process to determine whether the environmental information acquired by the acquisition device satisfies predetermined conditions, and a restoration device that, when the judgment device determines that the environmental information satisfies the predetermined conditions, acquires a plurality of distributed data for restoring predetermined target data, the plurality of distributed data being stored in a distributed manner in a plurality of storage devices, and restores the target data using the acquired plurality of distributed data.
[0007] One aspect of the present disclosure may be realized not only as an in-vehicle system including such a characteristic processing unit, but also as a program for causing a computer to execute steps of such characteristic processing. Furthermore, one aspect of the present disclosure may be realized not only as an in-vehicle device including such a characteristic processing unit, but also as a data restoration method including steps of such characteristic processing, or as a semiconductor integrated circuit that realizes part or all of the in-vehicle device. [Effects of the Invention]
[0008] According to the present disclosure, it is possible to reduce the risk of data in an in-vehicle system being illegally acquired. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a diagram showing a configuration of an in-vehicle system according to a first embodiment of the present disclosure. [Figure 2] FIG. 2 is a diagram illustrating a configuration of a relay device according to the first embodiment of the present disclosure. [Figure 3] FIG. 3 is a flowchart illustrating an example of an operation procedure when the relay device according to the first embodiment of the present disclosure distributes distributed data. [Figure 4] FIG. 4 is a flowchart illustrating an example of an operation procedure when the relay device according to the first embodiment of the present disclosure restores target data. [Figure 5] FIG. 5 is a flowchart illustrating an example of an operation procedure when the relay device according to the first embodiment of the present disclosure erases target data. [Figure 6] FIG. 6 is a diagram showing an example of a communication sequence in the in-vehicle system according to the first embodiment of the present disclosure. [Figure 7] FIG. 7 is a diagram showing a configuration of an in-vehicle system according to the second embodiment of the present disclosure. [Figure 8] FIG. 8 is a diagram illustrating a configuration of a relay device according to the second embodiment of the present disclosure. [Figure 9] FIG. 9 is a diagram illustrating an example of a correspondence table stored in a storage unit in a relay device according to the second embodiment of the present disclosure. [Figure 10] FIG. 10 is a flowchart illustrating an example of an operation procedure when a relay device according to the second embodiment of the present disclosure distributes distributed data. [Figure 11] FIG. 11 is a flowchart illustrating an example of an operation procedure when the relay device according to the second embodiment of the present disclosure erases target data. DETAILED DESCRIPTION OF THE INVENTION
[0010] First, the contents of the embodiments of the present disclosure will be listed and described. (1) An in-vehicle system according to an embodiment of the present disclosure is an in-vehicle system mounted on a vehicle, and includes: an acquisition device that acquires environmental information of the vehicle; a determination device that performs a determination process to determine whether the environmental information acquired by the acquisition device satisfies a predetermined condition; and a restoration device that, when the determination device determines that the environmental information satisfies the predetermined condition, acquires a plurality of distributed data for restoring predetermined target data, the plurality of distributed data being stored in a distributed manner in a plurality of storage devices, and restores the target data using the acquired plurality of distributed data.
[0011] With this configuration, it is possible to determine, for example, a situation in which the target data is expected to be used based on the environmental information, and restore the target data. Also, it is possible to prevent the target data from being restored through unauthorized access and illegally acquired in a situation in which the target data is not expected to be used, for example. Therefore, it is possible to reduce the risk of data being illegally acquired in the in-vehicle system.
[0012] (2) In the above (1), the acquisition device may acquire the environmental information indicating the current position of the vehicle, and the determination device may determine, in the determination process, whether the current position of the vehicle satisfies the specified condition that the current position is within a specified range.
[0013] With this configuration, when the current location of the vehicle is within an area where the target data is expected to be used, the target data can be restored.
[0014] (3) In (1) or (2) above, the acquisition device may acquire the environmental information indicating the current time, and the determination device may determine, in the determination process, whether the current time satisfies the specified condition that is within a specified range.
[0015] With this configuration, the target data can be restored when the current time is within the time period in which the target data is expected to be used.
[0016] (4) In any of (1) to (3) above, the in-vehicle system may further include an erasure device that erases the target data restored by the restoration device when the determination device determines that the environmental information does not satisfy the specified condition.
[0017] With this configuration, if the situation changes after the target data is restored and the target data is no longer expected to be used, the restored target data can be erased, thereby reducing the risk of the restored target data being obtained illegally.
[0018] (5) In any of (1) to (4) above, the determination device may calculate a security level of the vehicle, and the restoration device may acquire the plurality of distributed data and restore the target data using the acquired plurality of distributed data if the determination device determines that the environmental information does not satisfy the specified condition and the security level is equal to or greater than a specified value.
[0019] With this configuration, the target data can be restored when the security level is high even in situations where the use of the target data is not expected, thereby reducing the risk of the target data being obtained illegally and allowing the target data to be restored and used in exceptional cases even in situations where the use of the target data is not expected.
[0020] (6) In the above (5), the determination device may calculate the security level based on a predetermined correspondence relationship between the environmental information and the security level.
[0021] With this configuration, the security level can be calculated through simple processing.
[0022] (7) An on-board device according to an embodiment of the present disclosure is an on-board device mounted on a vehicle, and includes: an acquisition unit that acquires environmental information of the vehicle; a judgment unit that performs a judgment process to determine whether the environmental information acquired by the acquisition unit satisfies a predetermined condition; and a restoration unit that, when the judgment unit determines that the environmental information satisfies the predetermined condition, acquires a plurality of distributed data for restoring predetermined target data, the plurality of distributed data being stored in a distributed manner in a plurality of storage devices, and restores the target data using the acquired plurality of distributed data.
[0023] With this configuration, it is possible to determine, for example, a situation in which the target data is expected to be used based on the environmental information, and restore the target data. Also, it is possible to prevent the target data from being restored through unauthorized access and illegally acquired in a situation in which the target data is not expected to be used, for example. Therefore, it is possible to reduce the risk of data being illegally acquired in the in-vehicle system.
[0024] (8) A data restoration method according to an embodiment of the present disclosure is a data restoration method in an on-board system installed in a vehicle, and includes the steps of acquiring environmental information of the vehicle, performing a determination process to determine whether the acquired environmental information satisfies a predetermined condition, and, if the determination process determines that the environmental information satisfies the predetermined condition, acquiring a plurality of distributed data for restoring predetermined target data, the plurality of distributed data being distributed and stored in a plurality of storage devices, and restoring the target data using the acquired plurality of distributed data.
[0025] This method makes it possible to determine, for example, a situation in which the target data is expected to be used based on the environmental information, and to restore the target data. Furthermore, it is possible to prevent the target data from being restored through unauthorized access and illegally acquired in a situation in which the target data is not expected to be used, for example. Therefore, it is possible to reduce the risk of data being illegally acquired in the in-vehicle system.
[0026] (9) A data restoration program according to an embodiment of the present disclosure is a data restoration program used in an on-board device mounted in a vehicle, and is a program for causing a computer to function as an acquisition unit that acquires environmental information of the vehicle, a judgment unit that performs a judgment process to determine whether the environmental information acquired by the acquisition unit satisfies a predetermined condition, and a restoration unit that, when the judgment unit determines that the environmental information satisfies the predetermined condition, acquires a plurality of distributed data for restoring predetermined target data, the plurality of distributed data being stored in a distributed manner in a plurality of storage devices, and restores the target data using the acquired plurality of distributed data.
[0027] With this configuration, it is possible to determine, for example, a situation in which the target data is expected to be used based on the environmental information, and restore the target data. Also, it is possible to prevent the target data from being restored through unauthorized access and illegally acquired in a situation in which the target data is not expected to be used, for example. Therefore, it is possible to reduce the risk of data being illegally acquired in the in-vehicle system.
[0028] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the drawings, identical or corresponding parts are designated by the same reference numerals, and their description will not be repeated. Furthermore, at least some of the embodiments described below may be combined in any manner.
[0029] First Embodiment [Configuration and basic operation] Fig. 1 is a diagram showing a configuration of an in-vehicle system according to a first embodiment of the present disclosure. Referring to Fig. 1, an in-vehicle system 301 includes relay devices 101 and 201, a plurality of in-vehicle ECUs (Electronic Control Units) 111, and a plurality of in-vehicle ECUs 211. The in-vehicle system 301 is mounted on a vehicle 1. The relay devices 101 and 201 and the in-vehicle ECUs 111 and 211 are examples of in-vehicle devices.
[0030] The relay devices 101 and 201 are connected to each other via a transmission line 2. The relay device 101 and the in-vehicle ECU 111 are connected to each other via the transmission line 2. The relay device 201 and the in-vehicle ECU 211 are connected to each other via the transmission line 2. The transmission line 2 is, for example, an Ethernet (registered trademark) cable. Note that the transmission line 2 is not limited to an Ethernet cable and may be a communication line conforming to other standards such as CAN (Controller Area Network) (registered trademark) and FlexRay (registered trademark).
[0031] The relay device 101 is capable of communicating with the in-vehicle ECU 111 and the relay device 201. The relay device 201 is capable of communicating with the in-vehicle ECU 211 and the relay device 101. The relay devices 101 and 201 perform a relay process of relaying communication data transmitted and received in the in-vehicle system 301. More specifically, the relay devices 101 and 201 relay communication data transmitted and received between the in-vehicle ECUs 111, communication data transmitted and received between the in-vehicle ECUs 211, communication data transmitted and received between the in-vehicle ECUs 111 and 211, and communication data transmitted and received between the in-vehicle ECUs 111 and 211 and a communication device (not shown) outside the vehicle 1.
[0032] (Configuration of relay device) 2 is a diagram illustrating a configuration of a relay device according to a first embodiment of the present disclosure. Referring to FIG. 2, relay device 101 includes relay unit 11, distribution unit 12, acquisition unit 13, determination unit 14, restoration unit 15, deletion unit 16, and storage unit 17. Some or all of the functions of relay unit 11, distribution unit 12, acquisition unit 13, determination unit 14, restoration unit 15, and deletion unit 16 are implemented by, for example, a processing circuit including one or more processors. Storage unit 17 is, for example, a non-volatile memory included in the processing circuit.
[0033] The relay unit 11 performs relay processing. More specifically, the relay unit 11 receives a frame including communication data from the in-vehicle ECU 111, and transmits the frame to another in-vehicle ECU 111 or the relay device 201 according to destination information such as the destination IP address, MAC address, and message ID of the received frame. The relay unit 11 also receives a frame including communication data from the relay device 201, and transmits the frame to the in-vehicle ECU 111 according to the destination information of the received frame.
[0034] (Distribution of distributed data Dv1) The relay device 201 transmits a frame including target data D1 to the relay device 101. The target data D1 is highly confidential data. For example, the target data D1 is data that needs to be stored for a long period of time. As an example, the target data D1 is biometric information and personal information of a user of the vehicle 1.
[0035] The relay unit 11 receives a frame including target data D1 from the relay device 201 and outputs the received frame to the distribution unit 12.
[0036] The sharing unit 12 receives a frame from the relay unit 11 and acquires the target data D1 from the received frame. Based on the acquired target data D1, the sharing unit 12 generates multiple pieces of shared data Dv1 for restoring the target data D1, for example, according to a secret sharing scheme. More specifically, the sharing unit 12 generates n pieces of shared data Dv1 according to a (k, n) threshold scheme, which is an example of a secret sharing scheme. The target data D1 can be restored using at least k pieces of shared data Dv1 out of the n pieces of shared data Dv1. Here, n is an integer equal to or greater than 2. k is an integer equal to or greater than 2 and equal to or less than n. The sharing unit 12 may generate the shared data Dv1 according to a secret sharing scheme other than the (k, n) threshold scheme, such as the AONT (All Or Nothing Transformation) scheme. Instead of using a secret sharing scheme, the sharing unit 12 may generate multiple pieces of shared data Dv1 obtained by dividing the target data D1.
[0037] The distribution unit 12 distributes the generated distributed data Dv1 to the in-vehicle ECUs 111. More specifically, the distribution unit 12 selects m in-vehicle ECUs 111 to which the distributed data Dv1 is to be distributed from among the multiple in-vehicle ECUs 111 in the in-vehicle system 301, where m is an integer equal to or less than n. The distribution unit 12 generates n frames, each including n pieces of distributed data Dv1, and transmits the generated n frames to the selected m in-vehicle ECUs 111 via the relay unit 11. That is, the distribution unit 12 assigns one or more frames from the generated n frames to each selected in-vehicle ECU 111, and transmits the assigned frames to the corresponding in-vehicle ECU 111 via the relay unit 11. Note that the distribution unit 12 may distribute some of the n pieces of distributed data Dv1 to a server outside the vehicle 1.
[0038] The in-vehicle ECU 111 receives a frame including the distributed data Dv1 from the relay device 101, and acquires the distributed data Dv1 from the received frame. The in-vehicle ECU 111 stores the acquired distributed data Dv1 in a storage device of the in-vehicle ECU 111.
[0039] (Determining restoration conditions) For example, when an in-vehicle ECU 211 equipped with a door opening / closing application detects that a user has approached the vehicle 1, the in-vehicle ECU 211 transmits a target data request to the relay device 101 via the relay device 201, indicating that the target data D1 should be transmitted in order to perform user authentication using the target data D1.
[0040] The acquisition unit 13 acquires environmental information of the vehicle 1. More specifically, when the acquisition unit 13 receives a target data request from the in-vehicle ECU 211 via the relay device 201 and the relay unit 11, the acquisition unit 13 acquires the environmental information.
[0041] For example, the acquisition unit 13 acquires environmental information indicating the current position and current time of the vehicle 1. More specifically, the acquisition unit 13 receives GPS signals from GPS (Global Positioning System) satellites and detects the current position and current time of the vehicle 1 based on the received GPS signals. The acquisition unit 13 generates environmental information indicating the detected current position and current time and outputs the generated environmental information to the determination unit 14.
[0042] The determination unit 14 performs a determination process to determine whether or not the environmental information acquired by the acquisition unit 13 satisfies a predetermined restoration condition. More specifically, the determination unit 14 receives the environmental information from the acquisition unit 13 and determines whether or not the received environmental information satisfies the restoration condition. The restoration condition may be set in advance by the user of the vehicle 1, may be set in advance by the manufacturer of the vehicle 1, or may be set in advance by machine learning the relationship between the driving results of the vehicle 1 during a predetermined learning period and the usage results of the target data D1 in the in-vehicle system 301.
[0043] For example, in the determination process, the determination unit 14 determines whether or not the current location of the vehicle 1 indicated by the environmental information received from the acquisition unit 13 satisfies a restoration condition that is within a predetermined range. As an example, the determination unit 14 determines whether or not the current location of the vehicle 1 satisfies a restoration condition C1 that is within a home parking lot of the user of the vehicle 1.
[0044] Furthermore, for example, in the determination process, the determination unit 14 determines whether or not the current time indicated by the environmental information received from the acquisition unit 13 satisfies a restoration condition that is within a predetermined range. As an example, the determination unit 14 determines whether or not the current time satisfies restoration condition C2 that is a time between 6:00 AM and 9:00 AM.
[0045] If the current position of the vehicle 1 satisfies the restoration condition C1 and the current time satisfies the restoration condition C2, the determination unit 14 outputs a restoration instruction to the restoration unit 15. On the other hand, if the current position of the vehicle 1 does not satisfy the restoration condition C1 or the current time does not satisfy the restoration condition C2, the determination unit 14 does not output a restoration instruction to the restoration unit 15 and outputs a request discard instruction to the acquisition unit 13.
[0046] When the acquisition unit 13 receives a request discard instruction from the determination unit 14, it discards the target data request received from the in-vehicle ECU 211. This makes it possible to prevent the restoration data from being illegally acquired in a case where the target data request received by the acquisition unit 13 was illegally transmitted by unauthorized access to the in-vehicle system 301.
[0047] (Restoring target data D1) When the determination unit 14 determines that the environmental information satisfies the restoration condition, the restoration unit 15 acquires the plurality of distributed data Dv1 stored in a distributed manner in the plurality of storage devices. More specifically, the restoration unit 15 receives a restoration instruction from the determination unit 14 and collects the distributed data Dv1 from the m in-vehicle ECUs 111 to which the distributed data Dv1 is to be distributed. Specifically, the restoration unit 15 transmits a distributed data request indicating that the distributed data Dv1 should be transmitted to the m in-vehicle ECUs 111 via the relay unit 11.
[0048] When the in-vehicle ECU 111 receives a distributed data request from the relay device 101, it acquires the distributed data Dv1 from the storage device in the in-vehicle ECU 111 and transmits a frame including the acquired distributed data Dv1 to the relay device 101 in response to the distributed data request.
[0049] The relay unit 11 receives a frame including the distributed data Dv1 from the in-vehicle ECU 111 and outputs the received frame to the restoration unit 15.
[0050] The restoration unit 15 receives the frame from the relay unit 11 and obtains the distributed data Dv1 from the received frame.
[0051] The restoration unit 15 restores the target data D1 using the acquired multiple pieces of shared data Dv1. More specifically, when the restoration unit 15 collects k or more pieces of shared data Dv1 out of the n pieces of shared data Dv1 distributed to the in-vehicle ECU 111 by the distribution unit 12, the restoration unit 15 restores the target data D1 using the collected shared data Dv1 in accordance with the secret sharing scheme.
[0052] The restoration unit 15 stores the restored target data D1 in the storage unit 17. The restoration unit 15 also transmits a frame including the target data D1 to the in-vehicle ECU 211 that is the sender of the target data request via the relay unit 11 and the relay device 201.
[0053] The in-vehicle ECU 211 receives a frame including target data D1 from the relay device 101 via the relay device 201, and acquires the target data D1 from the received frame. The in-vehicle ECU 211 performs user authentication using the acquired target data D1. If the user authentication is successful, the in-vehicle ECU 211 performs door opening / closing processing to automatically open and close the doors of the vehicle 1.
[0054] (Deletion of target data D1) For example, after storing the target data D1 in the storage unit 17, the restoration unit 15 outputs an acquisition instruction to the acquisition unit 13.
[0055] The acquisition unit 13 starts an acquisition process of periodically acquiring environmental information upon receiving an acquisition instruction from the restoration unit 15. More specifically, the acquisition unit 13 acquires environmental information at a timing according to a predetermined acquisition period P1, and outputs the acquired environmental information to the determination unit 14.
[0056] The determination unit 14 performs a determination process upon receiving the environmental information from the acquisition unit 13. More specifically, as described above, the determination unit 14 determines whether the current position of the vehicle 1 satisfies the restoration condition C1 and whether the current time satisfies the restoration condition C2.
[0057] If the current position of the vehicle 1 does not satisfy the restoration condition C1 or if the current time does not satisfy the restoration condition C2, the determination unit 14 outputs an erasure instruction to the erasure unit 16. On the other hand, if the current position of the vehicle 1 satisfies the restoration condition C1 and the current time satisfies the restoration condition C2, the determination unit 14 does not output an erasure instruction to the erasure unit 16 and waits for the arrival of new environmental information from the acquisition unit 13.
[0058] When the determination unit 14 determines that the environmental information does not satisfy the restoration condition, the erasure unit 16 erases the target data D1 restored by the restoration unit 15. More specifically, when the erasure unit 16 receives an erasure instruction from the determination unit 14, it erases the target data D1 in the storage unit 17.
[0059] [Operation flow] FIG. 3 is a flowchart illustrating an example of an operation procedure when the relay device according to the first embodiment of the present disclosure distributes distributed data.
[0060] Referring to FIG. 3, first, relay device 101 receives target data D1 from relay device 201 (step S11).
[0061] Next, the relay device 101 generates n pieces of distributed data Dv1 based on the received target data D1 (step S12).
[0062] Next, the relay device 101 transmits the generated n pieces of distributed data Dv1 to m pieces of in-vehicle ECUs 111 (step S13).
[0063] 4 is a flowchart illustrating an example of an operation procedure when the relay device according to the first embodiment of the present disclosure restores target data. The relay device 101 executes the process shown in FIG. 4 when the target data D1 is not stored in the storage unit 17.
[0064] Referring to FIG. 4, first, relay device 101 waits for a target data request to arrive (NO in step S21), and when it receives a target data request from in-vehicle ECU 211 via relay device 201 (YES in step S21), it acquires environmental information (step S22).
[0065] Next, the relay device 101 performs a determination process to determine whether or not the environmental information satisfies the restoration conditions C1 and C2 (step S23).
[0066] Next, if the environmental information does not satisfy at least one of the restoration conditions C1 and C2 (NO in step S24), the relay device 101 waits for a new target data request to arrive (NO in step S21).
[0067] On the other hand, if the environmental information satisfies the restoration conditions C1 and C2 (YES in step S24), the relay device 101 collects the distributed data Dv1 from the m in-vehicle ECUs 111 to which the distributed data Dv1 is to be distributed (step S25).
[0068] Next, the relay device 101 restores the target data D1 using the collected shared data Dv1 in accordance with the secret sharing scheme (step S26).
[0069] Next, the relay device 101 transmits the restored target data D1 to the in-vehicle ECU 211 that is the sender of the target data request via the relay device 201. The relay device 101 also stores the target data D1 in the storage unit 17 (step S27).
[0070] 5 is a flowchart illustrating an example of an operation procedure when the relay device according to the first embodiment of the present disclosure erases target data. The relay device 101 executes the process shown in FIG. 5 in a state where the target data D1 is stored in the storage unit 17.
[0071] Referring to FIG. 5, first, relay device 101 waits for the arrival of acquisition timing according to acquisition cycle P1 (NO in step S31), and when the acquisition timing arrives (YES in step S31), it acquires environmental information (step S32).
[0072] Next, the relay device 101 performs a determination process to determine whether or not the environmental information satisfies the restoration conditions C1 and C2 (step S33).
[0073] Next, if the environmental information satisfies the restoration conditions C1 and C2 (NO in step S34), the relay device 101 waits for a new acquisition timing to arrive (NO in step S31).
[0074] On the other hand, if the environmental information does not satisfy at least one of the restoration conditions C1 and C2 (YES in step S34), the relay device 101 erases the target data D1 from the storage unit 17 (step S35).
[0075] FIG. 6 is a diagram showing an example of a communication sequence in the in-vehicle system according to the first embodiment of the present disclosure.
[0076] Referring to FIG. 6, first, relay device 201 transmits target data D1 to relay device 101 (step S41).
[0077] Next, the relay device 101 generates n pieces of distributed data Dv1 based on the target data D1 (step S42).
[0078] Next, the relay device 101 transmits the generated n pieces of distributed data Dv1 to m pieces of in-vehicle ECUs 111 (step S43).
[0079] Next, each in-vehicle ECU 111 stores the distributed data Dv1 received from the relay device 101 in a storage device (step S44).
[0080] Next, the in-vehicle ECU 211 transmits the target data request to the relay device 101 via the relay device 201 (step S45).
[0081] Next, the relay device 101 acquires environmental information (step S46).
[0082] Next, the relay device 101 performs a determination process to determine whether or not the environmental information satisfies the restoration conditions C1 and C2 (step S47).
[0083] Next, if the environmental information satisfies the restoration conditions C1 and C2, the relay device 101 transmits a distributed data request to the m in-vehicle ECUs 111 (step S48).
[0084] Next, each in-vehicle ECU 111 acquires the distributed data Dv1 from the storage device and transmits the acquired distributed data Dv1 to the relay device 101 (step S49).
[0085] Next, the relay device 101 restores the target data D1 using the distributed data Dv1 received from each in-vehicle ECU 111 (step S50).
[0086] Next, the relay device 101 transmits the restored target data D1 to the in-vehicle ECU 211 via the relay device 201. Furthermore, the relay device 101 stores the target data D1 in the storage unit 17 (step S51).
[0087] Next, the relay device 101 acquires and determines environmental information at the acquisition timing according to the acquisition period P1, and if the environmental information does not satisfy at least one of the restoration conditions C1 and C2, it erases the target data D1 from the memory unit 17 (step S52).
[0088] In the relay device 101 according to the first embodiment of the present disclosure, the determination unit 14 is configured to determine whether the current position of the vehicle 1 satisfies the restoration condition C1 and whether the current time satisfies the restoration condition C2 in the determination process, but this is not limited to this. The determination unit 14 may be configured not to perform either the determination regarding the restoration condition C1 or the determination regarding the restoration condition C2 in the determination process.
[0089] Furthermore, in the relay device 101 according to the first embodiment of the present disclosure, the acquisition unit 13 is configured to acquire environmental information indicating the current location and current time of the vehicle 1, but this is not limited thereto. The acquisition unit 13 may be configured to acquire environmental information indicating the weather at the current location of the vehicle 1.
[0090] Furthermore, in the relay device 101 according to the first embodiment of the present disclosure, when the acquisition unit 13 receives a target data request from the in-vehicle ECU 211 via the relay device 201 and the relay unit 11 while the target data D1 is not stored in the storage unit 17, the acquisition unit 13 acquires environmental information and outputs it to the determination unit 14. However, this is not limited to this. The acquisition unit 13 may acquire environmental information at a timing according to the acquisition period P1 regardless of the target data request and output it to the determination unit 14. In this case, the determination unit 14 performs a determination process every time it receives environmental information from the acquisition unit 13, and if the environmental information satisfies the restoration conditions C1 and C2, it outputs a restoration instruction to the restoration unit 15. Then, upon receiving the restoration instruction from the determination unit 14, the restoration unit 15 collects distributed data Dv1 and restores the target data D1, and stores the target data D1 in the storage unit 17. When the restoration unit 15 receives a target data request from the in-vehicle ECU 211 via the relay device 201 and the relay unit 11, the restoration unit 15 acquires the target data D1 from the storage unit 17 in accordance with the received target data request and transmits it to the in-vehicle ECU 211. This allows the target data D1 to be restored in advance before the target data request is received from the in-vehicle ECU 211 in a situation where the target data D1 can be used, so that the target data D1 can be transmitted to the in-vehicle ECU 211 promptly upon arrival of the target data request. As described above, after the restoration unit 15 stores the target data D1 in the storage unit 17, if the determination unit 14 determines that the environmental information does not satisfy the restoration condition, the erasure unit 16 erases the target data D1 restored by the restoration unit 15.
[0091] Furthermore, although the relay device 101 according to the first embodiment of the present disclosure is configured to include the erasing unit 16, this is not limitative. The relay device 101 may be configured not to include the erasing unit 16.
[0092] Furthermore, in the relay device 101 according to the first embodiment of the present disclosure, the restoration unit 15 is configured to restore the target data D1, which is the biometric information and personal information of the user of the vehicle 1, but this is not limited to this. The restoration unit 15 may also be configured to restore other target data, such as an encryption key used for communication between on-board devices, an encryption key used for communication between the on-board device and a device external to the vehicle 1, and information about a credit card owned by the user of the vehicle 1. Furthermore, the restoration unit 15 may also be configured to restore multiple types of target data.
[0093] In addition, in the in-vehicle system 301 according to the first embodiment of the present disclosure, the relay device 101 is configured to include the distribution unit 12, the acquisition unit 13, the determination unit 14, the restoration unit 15, and the deletion unit 16, but this is not limitative. In the in-vehicle system 301, the distribution unit 12, the acquisition unit 13, the determination unit 14, the restoration unit 15, and the deletion unit 16 may be distributed and arranged in multiple in-vehicle devices.
[0094] Next, other embodiments of the present disclosure will be described with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals and their description will not be repeated.
[0095] <Second embodiment> [Configuration and basic operation] This embodiment relates to an in-vehicle system 302 that is capable of restoring target data even when environmental information does not satisfy the restoration conditions, as compared with the in-vehicle system 301 according to the first embodiment. Except for the contents described below, the in-vehicle system 302 is the same as the in-vehicle system 301 according to the first embodiment.
[0096] 7 is a diagram illustrating a configuration of an in-vehicle system according to the second embodiment of the present disclosure. Referring to FIG. 7, in-vehicle system 302 includes relay device 102 instead of relay device 101, as compared with in-vehicle system 301.
[0097] (Configuration of relay device) 8 is a diagram illustrating a configuration of a relay device according to the second embodiment of the present disclosure. Referring to FIG. 8, relay device 102 includes a determination unit 18 instead of determination unit 14.
[0098] (Distribution of distributed data Dv2) The relay device 201 transmits a frame including the target data D2 to the relay device 102. The target data D2 is highly confidential data. As an example, the target data D2 is information about a credit card owned by the user of the vehicle 1.
[0099] The relay unit 11 receives a frame including target data D2 from the relay device 201 and outputs the received frame to the distribution unit 12.
[0100] The distribution unit 12 receives a frame from the relay unit 11 and acquires target data D2 from the received frame. For example, the distribution unit 12 generates n pieces of distributed data Dv2 based on the target data D2 according to a (k, n) threshold method.
[0101] The distribution unit 12 distributes the generated distributed data Dv2 to the in-vehicle ECUs 111. More specifically, the distribution unit 12 generates m frames, each including one or more pieces of distributed data Dv2, and transmits the generated m frames to the m in-vehicle ECUs 111 via the relay unit 11. Note that the distribution unit 12 may distribute some of the n pieces of distributed data Dv2 to a server outside the vehicle 1.
[0102] The in-vehicle ECU 111 receives the frame including the distributed data Dv2 from the relay device 102, and acquires the distributed data Dv2 from the received frame. The in-vehicle ECU 111 stores the acquired distributed data Dv2 in a storage device in the in-vehicle ECU 111.
[0103] (Determining restoration conditions) For example, in-vehicle ECU 211 having a card payment application transmits a target data request to relay device 102 via relay device 201 indicating that target data D2 should be transmitted in order to perform credit card payment using target data D2.
[0104] When the acquisition unit 13 receives a target data request from the in-vehicle ECU 211 via the relay device 201 and the relay unit 11, the acquisition unit 13 acquires environmental information in accordance with the received target data request. More specifically, as described above, the acquisition unit 13 detects the current position and current time of the vehicle 1 based on the GPS signal, and outputs environmental information indicating the detected current position and current time to the determination unit 18.
[0105] The determination unit 18 performs a determination process to determine whether or not the environmental information acquired by the acquisition unit 13 satisfies a predetermined restoration condition.
[0106] For example, in the determination process, the determination unit 18 determines whether or not the current location of the vehicle 1 indicated by the environmental information received from the acquisition unit 13 satisfies a restoration condition that the current location is within a predetermined range. As an example, the determination unit 18 determines whether or not the current location of the vehicle 1 satisfies a restoration condition C3 that the current location is within an area where a paid service is provided.
[0107] Furthermore, for example, in the determination process, the determination unit 18 determines whether or not the current time indicated by the environmental information received from the acquisition unit 13 satisfies a restoration condition that is within a predetermined range. As an example, the determination unit 18 determines whether or not the current time satisfies restoration condition C4 that is a time in the daytime.
[0108] 9 is a diagram illustrating an example of a correspondence table stored in a storage unit in a relay device according to the second embodiment of the present disclosure. Referring to FIG. 9, the storage unit 17 stores a correspondence table T1 indicating a predetermined correspondence relationship between environmental information and a security level SL. The security level SL is a value indicating the security level of the in-vehicle system 302.
[0109] For example, in the correspondence table T1, if the time zone to which the current time belongs is "morning" and the area to which the current location of the vehicle 1 belongs is an "area where paid services are provided," the value of the security level SL is "9." Also, for example, if the time zone to which the current time belongs is "daytime" and the area to which the current location of the vehicle 1 belongs is an "area where paid services are provided," the value of the security level SL is "10." In this way, in the correspondence table T1, the highest security level SL is set in a situation that satisfies the restoration conditions C3 and C4. The correspondence table T1 may be created in advance by the user of the vehicle 1, may be created in advance by the manufacturer of the vehicle 1, or may be created in advance by machine learning the relationship between the driving results of the vehicle 1 during a predetermined learning period and the usage results of the target data D2 in the in-vehicle system 302.
[0110] The determination unit 18 calculates the security level SL based on the correspondence table T1 in the storage unit 17. More specifically, the determination unit 18 determines, based on the environmental information, whether the time zone to which the current time belongs is "morning," "daytime," or "late night." The determination unit 18 also determines, based on the environmental information, whether the area to which the current location of the vehicle 1 belongs is an "area where paid services are provided" or an "area where paid services are not provided."
[0111] The determination unit 18 acquires the security level SL corresponding to the determined time period and the determined area from the correspondence table T1. If the acquired security level SL is "10", the determination unit 18 determines that the environmental information satisfies the restoration conditions C3 and C4, and outputs a restoration instruction to the restoration unit 15.
[0112] On the other hand, if the acquired security level SL is not "10," the determination unit 18 determines that the environmental information does not satisfy at least one of the restoration conditions C3 and C4. In this case, the determination unit 18 compares the security level SL with a predetermined threshold value Th1. The threshold value Th1 is a value less than 10.
[0113] When the security level SL is equal to or greater than the threshold value Th1, the determination unit 18 outputs a restoration instruction to the restoration unit 15. On the other hand, when the security level SL is less than the threshold value Th1, the determination unit 18 does not output a restoration instruction to the restoration unit 15, and outputs a request discard instruction to the acquisition unit 13.
[0114] (Restoring target data D2) When the determination unit 18 determines that the environmental information satisfies the restoration condition, the restoration unit 15 acquires the plurality of distributed data Dv2 stored in a distributed manner in the plurality of storage devices. Furthermore, when the determination unit 18 determines that the environmental information does not satisfy the restoration condition and the security level SL is equal to or greater than the threshold value Th1, the restoration unit 15 acquires the plurality of distributed data Dv2 stored in a distributed manner in the plurality of storage devices. More specifically, upon receiving a restoration instruction from the determination unit 18, the restoration unit 15 collects the distributed data Dv2 from the m in-vehicle ECUs 111 to which the distributed data Dv2 is to be distributed. Specifically, the restoration unit 15 transmits a distributed data request indicating that the distributed data Dv2 should be transmitted to the m in-vehicle ECUs 111 via the relay unit 11.
[0115] When the in-vehicle ECU 111 receives a distributed data request from the relay device 102, it acquires the distributed data Dv2 from the storage device in the in-vehicle ECU 111 and transmits a frame including the acquired distributed data Dv2 to the relay device 102 in response to the distributed data request.
[0116] The relay unit 11 receives a frame including the distributed data Dv2 from the in-vehicle ECU 111 and outputs the received frame to the restoration unit 15.
[0117] The restoration unit 15 receives the frame from the relay unit 11 and acquires the distributed data Dv2 from the received frame.
[0118] The restoration unit 15 restores the target data D2 using the acquired multiple pieces of shared data Dv2. More specifically, when the restoration unit 15 collects k or more pieces of shared data Dv2 out of the n pieces of shared data Dv2 distributed to the in-vehicle ECU 111 by the distribution unit 12, the restoration unit 15 restores the target data D2 using the collected shared data Dv2 in accordance with the secret sharing scheme.
[0119] The restoration unit 15 stores the restored target data D2 in the storage unit 17. The restoration unit 15 also transmits a frame including the target data D2 to the in-vehicle ECU 211 that is the sender of the target data request via the relay unit 11 and the relay device 201.
[0120] The in-vehicle ECU 211 receives the frame including the target data D2 from the relay device 102 via the relay device 201, and acquires the target data D2 from the received frame. The in-vehicle ECU 211 performs credit card payment using the acquired target data.
[0121] (Deletion of target data D2) For example, after storing the target data D2 in the storage unit 17, the restoration unit 15 outputs an acquisition instruction to the acquisition unit 13.
[0122] The acquisition unit 13 starts an acquisition process of periodically acquiring environmental information upon receiving an acquisition instruction from the restoration unit 15. More specifically, the acquisition unit 13 acquires environmental information at a timing according to a predetermined acquisition period P1, and outputs the acquired environmental information to the determination unit 18.
[0123] The determination unit 18 receives the environmental information from the acquisition unit 13, determines the time zone to which the current time belongs and the area to which the current location of the vehicle 1 belongs, as described above, and acquires the security level SL corresponding to the determined time zone and determined area from the correspondence table T1. The determination unit 18 compares the acquired security level SL with the threshold value Th1.
[0124] When the security level SL is less than the threshold value Th1, the determination unit 18 outputs an erasure instruction to the erasure unit 16. On the other hand, when the security level SL is equal to or greater than the threshold value Th1, the determination unit 18 does not output an erasure instruction to the erasure unit 16, and waits for new environmental information to arrive from the acquisition unit 13.
[0125] When the erasing unit 16 receives an erasure instruction from the determining unit 18, it erases the target data D2 in the storage unit 17.
[0126] After determining that the environmental information satisfies the restoration conditions C3 and C4 and outputting a restoration instruction to the restoration unit 15, the determination unit 18 may determine whether the environmental information satisfies the restoration conditions C3 and C4 instead of comparing the security level SL with the threshold value Th1 while the target data D2 is stored in the storage unit 17. In this case, if the determination unit 18 determines that the environmental information does not satisfy at least one of the restoration conditions C3 and C4, it outputs an erasure instruction to the erasure unit 16. On the other hand, if the determination unit 18 determines that the environmental information satisfies the restoration conditions C3 and C4, it does not output an erasure instruction to the erasure unit 16, but waits for new environmental information to arrive from the acquisition unit 13.
[0127] [Operation flow] 10 is a flowchart illustrating an example of an operation procedure when a relay device according to the second embodiment of the present disclosure distributes distributed data. The relay device 102 executes the process shown in FIG. 10 when the target data D2 is not stored in the storage unit 17.
[0128] Referring to FIG. 10, first, the relay device 102 waits for the arrival of a target data request (NO in step S61), and when it receives the target data request from the in-vehicle ECU 211 via the relay device 201 (YES in step S61), it acquires environmental information (step S62).
[0129] Next, the relay device 102 calculates the security level SL based on the correspondence table T1 in the storage unit 17 (step S63).
[0130] Next, if the security level SL is not "10" and is less than the threshold value Th1 (NO in step S64 and NO in step S65), the relay device 102 waits for a new target data request to arrive (NO in step S61).
[0131] On the other hand, if the security level SL is "10" (YES in step S64), the judgment unit 18 determines that the environmental information satisfies the restoration conditions C3 and C4, and collects the distributed data Dv2 from the m in-vehicle ECUs 111 to which the distributed data Dv2 is distributed (step S66).
[0132] In addition, if the security level SL is not "10" and is equal to or greater than the threshold value Th1 (NO in step S64 and YES in step S65), the judgment unit 18 collects the distributed data Dv2 from the m in-vehicle ECUs 111 to which the distributed data Dv2 is to be distributed (step S66).
[0133] Next, the relay device 102 uses the collected shared data Dv2 to restore the target data D2 according to the secret sharing scheme (step S67).
[0134] Next, the relay device 102 transmits the restored target data D2 to the in-vehicle ECU 211 that is the sender of the target data request via the relay device 201. The relay device 102 also stores the target data D2 in the storage unit 17 (step S68).
[0135] 11 is a flowchart illustrating an example of an operation procedure when the relay device according to the second embodiment of the present disclosure erases target data. The relay device 102 executes the process shown in FIG. 11 while the target data D2 is stored in the storage unit 17.
[0136] Referring to FIG. 11, first, relay device 102 waits for the arrival of acquisition timing according to acquisition cycle P1 (NO in step S71), and when the acquisition timing arrives (YES in step S71), it acquires environmental information (step S72).
[0137] Next, the relay device 102 calculates the security level SL based on the correspondence table T1 in the storage unit 17 (step S73).
[0138] Next, if the security level SL is equal to or greater than the threshold value Th1 (NO in step S74), the relay device 102 waits for a new acquisition timing to arrive (NO in step S71).
[0139] On the other hand, if the security level SL is less than the threshold value Th1 (YES in step S74), the relay device 102 erases the target data D2 from the storage unit 17 (step S75).
[0140] In the relay device 102 according to the second embodiment of the present disclosure, the determination unit 18 is configured to calculate the security level SL based on the correspondence table T1, but this is not limiting. The determination unit 18 may be configured to calculate the security level SL based on, for example, environmental information and the communication status in the in-vehicle system 302 without using the correspondence table T1.
[0141] Furthermore, in the relay device 102 according to the second embodiment of the present disclosure, the determination unit 18 is configured to output a request discard instruction to the acquisition unit 13 when the security level SL is less than the threshold value Th1, but this is not limited to this. When the security level SL is less than the threshold value Th1, the determination unit 18 may perform additional security processing, such as requesting the user of the vehicle 1 to enter a password. When the determination unit 18 receives a correct password from the user, it outputs a restoration instruction to the restoration unit 15. As a result, even if the environmental information does not satisfy the restoration conditions C3 and C4 and the security level SL is less than the threshold value Th1, the target data D2 can be restored and used if safety is confirmed by the additional security processing.
[0142] The above-described embodiments should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims.
[0143] Each process (each function) in the above-described embodiments is realized by a processing circuit including one or more processors. The processing circuit may be configured as an integrated circuit or the like that combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the processes. The one or more processors may execute each of the processes according to the program read from the one or more memories, or according to a logic circuit pre-designed to execute each of the processes. The processor may be various processors suitable for computer control, such as a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), a field programmable gate array (FPGA), and an application-specific integrated circuit (ASIC). Note that the physically separate processors may cooperate with each other to execute each of the processes. For example, the processors mounted on a plurality of physically separated computers may cooperate with each other to execute the above processes via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), the Internet, etc. The program may be installed into the memory from an external server device or the like via the network, or may be distributed in a state stored on a recording medium such as a CD-ROM (Compact Disc Read Only Memory), a DVD-ROM (Digital Versatile Disc Read Only Memory), or a semiconductor memory, and installed into the memory from the recording medium.
[0144] The above description includes the following additional features. [Appendix 1] An in-vehicle system mounted on a vehicle, an acquisition device for acquiring environmental information of the vehicle; a determination device that performs a determination process to determine whether the environmental information acquired by the acquisition device satisfies a predetermined condition; a restoration device that, when the determination device determines that the environmental information satisfies the predetermined condition, acquires a plurality of distributed data for restoring predetermined target data, the plurality of distributed data being stored in a distributed manner in a plurality of storage devices, and restores the target data using the acquired plurality of distributed data; An in-vehicle system, wherein the specified conditions are set by machine learning the relationship between the driving results of the vehicle over a specified learning period and the usage results of the target data in the in-vehicle system.
[0145] [Appendix 2] An in-vehicle device mounted on a vehicle, a processing circuit; The processing circuitry acquiring environmental information of the vehicle; performing a determination process to determine whether the acquired environmental information satisfies a predetermined condition; An in-vehicle device that, when it determines that the environmental information satisfies the specified conditions, acquires multiple distributed data for restoring specified target data, the multiple distributed data being stored in a distributed manner in multiple storage devices, and restores the target data using the acquired multiple distributed data. [Explanation of symbols]
[0146] 1 vehicle 2 Transmission Lines 11 Relay Section 12 Dispersion section 13 Acquisition Department 14,18 Judgment part 15 Restoration Section 16 Eraser 17 Memory section 101,102 Relay device 111,211 Automotive ECU 301,302 In-Vehicle Systems T1 compatible table
Claims
1. An in-vehicle system mounted on a vehicle, an acquisition device for acquiring environmental information of the vehicle; a determination device that performs a determination process to determine whether the environmental information acquired by the acquisition device satisfies a predetermined condition; An in-vehicle system comprising: a restoration device that, when the determination device determines that the environmental information satisfies the specified condition, acquires a plurality of distributed data for restoring specified target data, the plurality of distributed data being stored in a distributed manner in a plurality of storage devices, and restores the target data using the acquired plurality of distributed data.
2. the acquisition device acquires the environmental information indicating a current position of the vehicle; The in-vehicle system according to claim 1 , wherein the determination device determines whether the current position of the vehicle satisfies the predetermined condition of being within a predetermined range in the determination process.
3. the acquisition device acquires the environmental information indicating a current time; The in-vehicle system according to claim 1 , wherein the determination device determines whether the current time satisfies the predetermined condition of being within a predetermined range in the determination process.
4. The in-vehicle system further comprises:
4. The in-vehicle system according to claim 1, further comprising an erasure device that erases the target data restored by the restoration device when the determination device determines that the environmental information does not satisfy the predetermined condition.
5. The determination device calculates a security level of the vehicle, The restoration device, when the determination device determines that the environmental information does not satisfy the specified condition and the security level is equal to or higher than a specified value, acquires the plurality of distributed data and restores the target data using the acquired plurality of distributed data.
6. The in-vehicle system according to claim 5 , wherein the determination device calculates the security level based on a predetermined correspondence relationship between the environmental information and the security level.
7. An in-vehicle device mounted on a vehicle, an acquisition unit that acquires environmental information of the vehicle; a determination unit that performs a determination process to determine whether the environmental information acquired by the acquisition unit satisfies a predetermined condition; an in-vehicle device comprising: a restoration unit that, when the determination unit determines that the environmental information satisfies the specified condition, acquires a plurality of distributed data for restoring specified target data, the plurality of distributed data being stored in a distributed manner in a plurality of storage devices, and restores the target data using the acquired plurality of distributed data.
8. A data restoration method in an in-vehicle system installed in a vehicle, comprising: acquiring environmental information of the vehicle; performing a determination process to determine whether the acquired environmental information satisfies a predetermined condition; A data restoration method including the steps of: if it is determined in the determination process that the environmental information satisfies the specified condition, acquiring a plurality of distributed data for restoring specified target data, the plurality of distributed data being stored in a distributed manner in a plurality of storage devices, and restoring the target data using the acquired plurality of distributed data.
9. A data recovery program for use in an in-vehicle device mounted in a vehicle, Computer, an acquisition unit that acquires environmental information of the vehicle; a determination unit that performs a determination process to determine whether the environmental information acquired by the acquisition unit satisfies a predetermined condition; a restoration unit that, when the determination unit determines that the environmental information satisfies the predetermined condition, acquires a plurality of distributed data for restoring predetermined target data, the plurality of distributed data being stored in a distributed manner in a plurality of storage devices, and restores the target data using the acquired plurality of distributed data; A data recovery program to function as a
Citation Information
Patent Citations
Information processing system, information processing device, information processing method, and program
WO2017065209A1