Control device

The control device addresses the risk of key information loss by implementing a rewrite process based on vehicle usage metrics, ensuring secure and timely key information management.

JP2026001261APending Publication Date: 2026-01-07ASTEMO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024098419
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-19
Publication Date
2026-01-07

Smart Images

  • Figure 2026001261000001_ABST
    Figure 2026001261000001_ABST
Patent Text Reader

Abstract

To provide a control device capable of preventing loss of key information stored in a nonvolatile memory and appropriately managing the key information.SOLUTION: The control device 20 included in the vehicle system 10 includes the nonvolatile memory 38 that stores the key information 46, and the control unit 28 that executes the rewriting process of writing the copy information obtained by copying the key information 46 stored in the nonvolatile memory 38 to the nonvolatile memory 38 as the new key information 46.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a control device. [Background technology]

[0002] International Publication No. 2018 / 070242 discloses a hardware security module (HSM) that is provided in a vehicle's electronic control unit (ECU). The HSM securely stores information such as keys. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] International Publication No. 2018 / 070242 Summary of the Invention [Problem to be solved by the invention]

[0004] There is a demand for a control device that can appropriately manage key information.

[0005] The present disclosure aims to solve the above-mentioned problems. [Means for solving the problem]

[0006] An aspect of the present disclosure is a control device comprising a non-volatile memory that stores key information, and a control unit that can execute a rewrite process in which copy information of the key information stored in the non-volatile memory is written to the non-volatile memory as new key information. [Effects of the Invention]

[0007] According to the present disclosure, key information can be managed appropriately. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a block diagram showing the configuration of a vehicle system equipped with a control device according to a first embodiment. [Figure 2] FIG. 2 is a flowchart showing the operation of the control device. [Figure 3] 3A to 3C are schematic diagrams illustrating the key information rewrite process according to the first embodiment. [Figure 4] FIG. 4 is a block diagram showing the configuration of a vehicle system including a control device according to the second embodiment. [Figure 5] 5A to 5D are schematic diagrams illustrating the key information rewrite process according to the second embodiment. [Figure 6] FIG. 6 is a block diagram showing the configuration of a vehicle system including a control device according to the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] Key information used for encryption is stored in a nonvolatile memory. However, the amount of charge stored in the nonvolatile memory decreases over time. Therefore, there is a risk that the key information stored in the nonvolatile memory will be lost after a predetermined time has passed. The present disclosure can contribute to preventing the loss of key information and, ultimately, to the appropriate management of key information.

[0010] [1 First Embodiment] [1-1 Configuration] The configuration of a control device 20 according to the first embodiment will be described with reference to Fig. 1. Fig. 1 is a block diagram showing the configuration of a vehicle system 10 equipped with a control device 20 according to the first embodiment.

[0011] The vehicle system 10 is provided in a vehicle. The vehicle may be a gasoline vehicle, a diesel vehicle, a hybrid vehicle, an electric vehicle, a fuel cell vehicle, or the like. The vehicle may also be an autonomous vehicle. The vehicle system 10 includes a start switch 12, a rotation speed sensor 14, an open / close sensor 16, a communication module 18, and a control device 20.

[0012] The start switch 12 is a switch for starting the vehicle. The start switch 12 may be an ignition switch provided in a gasoline vehicle, a diesel vehicle, a hybrid vehicle, etc. The start switch 12 may also be a start switch provided in an electric vehicle, a fuel cell vehicle, etc. When the user operates the start switch 12, a start signal (determination information) indicating that the start switch 12 has been operated is transmitted to the control device 20.

[0013] The rotation speed sensor 14 detects, for example, the number of rotations of the vehicle's tires. The vehicle's travel distance can be calculated based on the number of tire rotations. When the vehicle travels, a travel distance signal (determination information) indicating the vehicle's travel distance (number of tire rotations) is transmitted from the rotation speed sensor 14 to the control device 20.

[0014] The opening / closing sensor 16 detects the opening / closing of a predetermined door provided on the vehicle. The opening / closing sensor 16 is provided at one or more locations on the vehicle. If the vehicle is a gasoline vehicle, a diesel vehicle, or a hybrid vehicle, the opening / closing sensor 16 may detect the opening / closing of a door provided on a fuel filler port. If the vehicle is an electric vehicle, the opening / closing sensor 16 may detect the opening / closing of a door provided on a power filler port. If the vehicle is a fuel cell vehicle, the opening / closing sensor 16 may detect the opening / closing of a door provided on a hydrogen supply port. The opening / closing sensor 16 may detect the opening / closing of a hood. The opening / closing sensor 16 may detect the opening / closing of at least one door of the driver's seat, passenger seat, and rear seat. When the predetermined door is opened or closed, an opening / closing signal (determination information) indicating that the door has been opened or closed is transmitted from the opening / closing sensor 16 to the control device 20.

[0015] The communication module 18 is a communication device used to communicate between the control device 20 and a communication device outside the vehicle. For example, the communication module 18 may be a TCU (Telematics Control Unit). The communication performed by the communication module 18 is, for example, encrypted communication, but is not limited to this.

[0016] The control device 20 is, for example, an ECU such as an engine control ECU or a motor control ECU, but may also be another ECU. Note that the control device 20 is not limited to an ECU.

[0017] The control device 20 includes a calculation unit 22. The calculation unit 22 may be configured with a processor such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit). That is, the calculation unit 22 may be configured with a processing circuitry. The calculation unit 22 may include an acquisition unit 24, a determination unit 26, a control unit 28, and a timing unit 30. The acquisition unit 24 acquires determination information supplied from outside the control device 20. The determination unit 26 determines whether a rewrite execution condition (described below) for the key information 46 is satisfied based on the determination information acquired by the acquisition unit 24. The control unit 28 is responsible for overall control of the control device 20, including the rewrite process (described below) of the key information 46. The timing unit 30 has a timer function for timing a predetermined time (determination information). For example, when timing the operating time of a vehicle, the timing unit 30 starts timing when the vehicle is started. The acquisition unit 24, the determination unit 26, the control unit 28, and the timing unit 30 can be realized by the calculation unit 22 executing a program stored in the storage unit 34.

[0018] The calculation unit 22 may further include a buffer 32 (another memory). The buffer 32 is a volatile memory that can temporarily store various types of information.

[0019] At least a portion of the acquiring unit 24, the determining unit 26, the control unit 28, the clocking unit 30, and the buffer 32 may be realized by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array). Also, at least a portion of the acquiring unit 24, the determining unit 26, the control unit 28, the clocking unit 30, and the buffer 32 may be configured by an electronic circuit including discrete devices.

[0020] The control device 20 includes a storage unit 34. The storage unit 34 includes a volatile memory 36 and a non-volatile memory 38. Examples of the volatile memory 36 include RAM (Random Access Memory). The volatile memory 36 is used as a working memory for the processor and can temporarily store data necessary for processing or calculation. Examples of the non-volatile memory 38 include, but are not limited to, ROM (Read Only Memory) and flash memory. The non-volatile memory 38 is used as a storage memory and stores programs, tables, maps, etc. At least a portion of the storage unit 34 may be included in the processor, integrated circuit, etc. described above.

[0021] In the first embodiment, the nonvolatile memory 38 includes a program holding area 40, a data holding area 42, and a hardware security module area (HSM area 44). The data holding area 42 and the HSM area 44 may be formed in a flash memory.

[0022] In the program holding area 40, an application program (not shown) for causing a computer to execute the series of processes shown in FIG. 2 is installed.

[0023] The data storage area 42 stores the number of times the vehicle has been started (hereinafter referred to as the number of times of starting) and a start-up count threshold (predetermined number of times) that is a threshold value for the number of times of starting. The number of times of starting is initialized when a rewrite process of the key information 46 is executed. The start-up count threshold is a fixed value that is stored in advance in the data storage area 42. The number of times of starting and the start-up count threshold are used to determine whether or not a rewrite process of the key information 46 needs to be executed.

[0024] The data storage area 42 stores the vehicle's travel distance (hereinafter referred to as travel distance) and a travel distance threshold (predetermined distance) that is a threshold value for the travel distance. The travel distance is initialized when the key information 46 is rewritten. The travel distance threshold is a fixed value that is pre-stored in the data storage area 42. The travel distance and the travel distance threshold are used to determine whether or not the key information 46 needs to be rewritten.

[0025] The data holding area 42 pre-stores the measured time measured by the timing unit 30 and a time threshold (predetermined time) that is a threshold for the measured time. The measured time is initialized when a rewrite process for the key information 46 is executed. The time threshold is a fixed value pre-stored in the data holding area 42. The measured time and the time threshold are used to determine whether or not a rewrite process for the key information 46 needs to be executed.

[0026] The number of times the door has been opened and closed (hereinafter referred to as the opening and closing count) and an opening and closing count threshold (predetermined number of times) that is a threshold for the number of times the door has been opened and closed are stored in advance in the data storage area 42. The opening and closing count is initialized when a rewrite process for the key information 46 is executed. The opening and closing count threshold is a fixed value that is stored in advance in the data storage area 42. The opening and closing count and the opening and closing count threshold are used to determine whether or not a rewrite process for the key information 46 needs to be executed.

[0027] The HSM area 44 is a storage area in which key information 46 can be safely stored. The key information 46 can be stored in the HSM area 44. The key information 46 stored in the HSM area 44 can be kept secret. The key information 46 is used by the control device 20 to perform encrypted communication with an external device via the communication module 18. Only specific components within the control device 20 can access the HSM area 44. In the first embodiment, only the control unit 28 of the calculation unit 22 can access the HSM area 44. In other words, only the control unit 28 can execute the process of rewriting the key information 46.

[0028] [1-2 Operation] Fig. 2 is a flowchart showing the operation of the control device 20. The calculation unit 22 executes a series of processes shown in Fig. 2 at predetermined time intervals. Steps S1 to S5 shown in Fig. 2 are processes for determining whether or not to execute a rewrite process (step S6) of the key information 46. The conditions for determining YES in each of steps S1 to S5 are the rewrite execution conditions.

[0029] In step S1, the determination unit 26 compares the startup count stored in the data storage area 42 of the nonvolatile memory 38 with the startup count threshold stored in the data storage area 42 of the nonvolatile memory 38. For example, when the startup switch 12 is operated, the acquisition unit 24 acquires a startup signal. Each time the acquisition unit 24 acquires a startup signal, it increments the startup count stored in the data storage area 42 by 1. The determination unit 26 compares the startup count stored in the data storage area 42 with the startup count threshold to determine whether the rewrite execution condition is met. If the startup count is equal to or greater than the startup count threshold (step S1: YES), the determination unit 26 determines that the rewrite execution condition is met. In this case, the process proceeds to step S6. On the other hand, if the startup count is less than the startup count threshold (step S1: NO), the process proceeds to step S2.

[0030] When the process proceeds from step S1 to step S2, the determination unit 26 compares the mileage stored in the data holding area 42 of the nonvolatile memory 38 with a mileage threshold stored in the data holding area 42 of the nonvolatile memory 38. For example, the acquisition unit 24 periodically acquires a mileage signal from the rotation speed sensor 14 and calculates the value of the distance traveled by the vehicle. The acquisition unit 24 adds the calculated value to the mileage stored in the data holding area 42 of the nonvolatile memory 38. The determination unit 26 determines whether the rewrite execution condition is satisfied by comparing the mileage stored in the data holding area 42 with the mileage threshold. If the mileage is equal to or greater than the mileage threshold (step S2: YES), the determination unit 26 determines that the rewrite execution condition is satisfied. In this case, the process proceeds to step S6. On the other hand, if the mileage is less than the mileage threshold (step S2: NO), the process proceeds to step S3.

[0031] When the process proceeds from step S2 to step S3, the determination unit 26 compares the measured time stored in the data holding area 42 of the nonvolatile memory 38 with the time threshold stored in the data holding area 42 of the nonvolatile memory 38. For example, the acquisition unit 24 acquires the time measured by the timer unit 30 and adds it to the measured time stored in the data holding area 42 of the nonvolatile memory 38. The determination unit 26 determines whether the rewrite execution condition is satisfied by comparing the measured time stored in the data holding area 42 with the time threshold. If the measured time is equal to or greater than the time threshold (step S3: YES), the determination unit 26 determines that the rewrite execution condition is satisfied. In this case, the process proceeds to step S6. On the other hand, if the measured time is less than the time threshold (step S3: NO), the process proceeds to step S4.

[0032] When the process proceeds from step S3 to step S4, the determination unit 26 compares the number of opening and closing times stored in the data holding area 42 of the nonvolatile memory 38 with the opening and closing count threshold stored in the data holding area 42 of the nonvolatile memory 38. For example, when the opening and closing sensor 16 detects the opening and closing of the door, the acquisition unit 24 acquires an opening and closing signal. Each time the acquisition unit 24 acquires an opening and closing signal, it increments the number of opening and closing times stored in the data holding area 42 by 1. The determination unit 26 compares the number of opening and closing times stored in the data holding area 42 with the opening and closing count threshold to determine whether the rewrite execution condition is satisfied. If the number of opening and closing times is equal to or greater than the opening and closing count threshold (step S4: YES), the determination unit 26 determines that the rewrite execution condition is satisfied. In this case, the process proceeds to step S6. On the other hand, if the number of opening and closing times is less than the opening and closing count threshold (step S4: NO), the process proceeds to step S5.

[0033] When the process moves from step S4 to step S5, the determination unit 26 determines whether the program stored in the program holding area 40 of the non-volatile memory 38 has been updated. The data holding area 42 stores a program update history. For example, the determination unit 26 determines that the program has been updated if a specific program has been updated within a predetermined time. If the program has been updated (step S5: YES), the determination unit 26 determines that the rewrite execution condition has been met. In this case, the process moves to step S6. On the other hand, if the program has not been updated (step S5: NO), the series of processes shown in FIG. 2 ends.

[0034] When the process proceeds from any one of steps S1 to S5 to step S6, the control unit 28 executes a process of rewriting the key information 46. The process of rewriting the key information 46 according to the first embodiment will be described with reference to FIG.

[0035] 3A to 3C are schematic diagrams illustrating the rewrite process of the key information 46 according to the first embodiment. The rewrite process of the key information 46 according to the first embodiment is a process of reflashing (refreshing) the HSM area 44.

[0036] 3A. Control unit 28 generates copy information 48 by copying key information 46 stored in HSM area 44 of nonvolatile memory 38. Control unit 28 writes copy information 48 to buffer 32 provided in calculation unit 22. At this time, control unit 28 also copies other information stored in HSM area 44 and writes the same to buffer 32.

[0037] Next, the control unit 28 executes the second process shown in Fig. 3B. The control unit 28 erases the key information 46 and other information stored in the HSM area 44. For example, the control unit 28 initializes the HSM area 44. This puts the HSM area 44 into a blank state. In other words, the HSM area 44 does not store any charge corresponding to the key information 46.

[0038] Next, the control unit 28 executes the third process shown in Fig. 3C. The control unit 28 writes (writes back) the copy information 48 temporarily stored in the buffer 32 to the HSM area 44 again. The copy information 48 written back to the HSM area 44 becomes new key information 46. At this time, the control unit 28 also writes (writes back) other information temporarily stored in the buffer 32 to the HSM area 44 again. When writing the copy information 48 to the HSM area 44, a voltage is applied to the HSM area 44. As a result, the HSM area 44 once again stores charge corresponding to the key information 46.

[0039] [2 Second embodiment] [2-1 Configuration] The configuration of the control device 20 according to the second embodiment will be described with reference to Fig. 4. Fig. 4 is a block diagram showing the configuration of a vehicle system 10 equipped with the control device 20 according to the second embodiment. Note that, with regard to the second embodiment, descriptions of parts common to the first embodiment will be omitted, and only parts different from the first embodiment will be described.

[0040] In the second embodiment, the HSM area 44 of the nonvolatile memory 38 includes a plurality of banks. Each bank is logically independent. For example, the HSM area 44 includes a first bank 44a and a second bank 44b. The first bank 44a and the second bank 44b can store key information 46. One of the first bank 44a and the second bank 44b is used as a main bank, and the other is used as a sub-bank. During encryption, the key information 46 stored in the main bank is used.

[0041] The data holding area 42 of the nonvolatile memory 38 stores bank information 50. The bank information 50 determines whether the first bank 44a or the second bank 44b is the main bank. The contents of the bank information 50 are rewritten every time the key information 46 is rewritten.

[0042] [2-2 Operation] The operation of the control device 20 according to the second embodiment is the same as that shown in the flowchart of Fig. 2, except for the processing content of step S6. The rewrite processing (step S6) according to the second embodiment differs from the rewrite processing according to the first embodiment.

[0043] 5A to 5D are schematic diagrams illustrating the rewrite process of the key information 46 according to the second embodiment. In the following description, the rewrite process of the key information 46 is executed in a state where the main bank is the first bank 44a and the sub-bank is the second bank 44b, as shown in FIG. 5A.

[0044] First, the control unit 28 executes the first process shown in FIG. 5A. The control unit 28 generates copy information 48 by copying key information 46 stored in a first bank 44a (main bank) of the HSM area 44. The control unit 28 writes the copy information 48 to a second bank 44b (sub-bank) of the HSM area 44. The control unit 28 may also copy other information stored in the first bank 44a and write it to the second bank 44b. When writing the copy information 48 to the second bank 44b, a voltage is applied to the second bank 44b. As a result, the second bank 44b again stores charge corresponding to the copy information 48.

[0045] Next, the control unit 28 executes the second process. The control unit 28 compares the key information 46 stored in the first bank 44a with the copy information 48 written to the second bank 44b. As shown in FIG. 5B, if the key information 46 stored in the first bank 44a and the copy information 48 written to the second bank 44b do not match, the control unit 28 executes the first process again.

[0046] On the other hand, as shown in FIG. 5C, if the key information 46 stored in the first bank 44a and the copy information 48 written to the second bank 44b match, the control unit 28 executes a third process. The control unit 28 rewrites the contents of the bank information 50 stored in the data holding area 42. Here, the control unit 28 rewrites the bank information 50 to designate the second bank 44b as the main bank and the first bank 44a as the sub-bank. As a result, as shown in FIG. 5D, the first bank 44a becomes the sub-bank and the second bank 44b becomes the main bank. As a result, the copy information 48 written to the second bank 44b becomes new key information 46.

[0047] The next time it is time to rewrite the key information 46, the control unit 28 will execute a process in which the first bank 44a is the main bank and the second bank 44b is the sub-bank. In this way, the control unit 28 repeatedly executes the process of writing the copy information 48 from one of the first bank 44a and the second bank 44b to the other. At the same time, the control unit 28 repeatedly executes the process of switching the main bank and the sub-bank.

[0048] [3 Third embodiment] 6 is a block diagram showing the configuration of a vehicle system 10 including a control device 20 according to the third embodiment. In the first embodiment, an HSM area 44 is formed in a nonvolatile memory 38 included in the storage unit 34. As shown in FIG. 6, the control device 20 may include an independent hardware security module 52 (HSM 52) separate from the nonvolatile memory 38 of the storage unit 34.

[0049] The HSM 52 includes a nonvolatile memory 54. The HSM 52 is a device that can securely store the key information 46. The key information 46 can be stored in the nonvolatile memory 54. The key information 46 stored in the nonvolatile memory 54 can be kept secret. Only specific components within the control device 20 can access the nonvolatile memory 54. In the third embodiment, only the control unit 28 of the calculation unit 22 can access the nonvolatile memory 54. In other words, only the control unit 28 can execute the process of rewriting the key information 46.

[0050] The operation of the control device 20 according to the third embodiment is generally the same as the operation of the control device 20 according to the first embodiment. In the third embodiment, the control unit 28 writes copy information 48, which is a copy of the key information 46 stored in the nonvolatile memory 54, into the buffer 32. The control unit 28 also writes (writes back) the copy information 48 temporarily stored in the buffer 32 to the nonvolatile memory 54 again.

[0051] [4. Benefits of this disclosure] According to the present disclosure, a process of rewriting the key information 46 is executed, which makes it possible to prevent the key information 46 stored in the nonvolatile memory 38 from being lost due to a decrease in the amount of charge stored in the nonvolatile memory 38 (nonvolatile memory 54) over time. As described above, according to the present disclosure, the key information 46 can be managed appropriately.

[0052] According to the present disclosure, the rewrite process of the key information 46 is executed every time a predetermined timing arrives, so that the rewrite process can be executed before the key information 46 is lost.

[0053] According to the present disclosure, only the control unit 28 can execute the process of rewriting the key information 46, so that it is possible to prevent the key information 46 from being rewritten by a malicious third party.

[0054] [5 Notes] The following additional notes are further disclosed regarding the above embodiment.

[0055] (Appendix 1) The control device (20) of the present disclosure includes a non-volatile memory (38, 54) that stores key information (46), and a control unit (28) that can execute a rewrite process to write copy information (48) that is a copy of the key information stored in the non-volatile memory as new key information into the non-volatile memory.

[0056] According to the above configuration, since the process of rewriting the key information is executed, it is possible to prevent the loss of the key information stored in the nonvolatile memory due to the decrease in the amount of charge stored in the nonvolatile memory over time. As described above, according to the above configuration, it is possible to appropriately manage the key information.

[0057] (Appendix 2) In the control device described in Appendix 1, the rewrite process may include a process of writing the copy information to another memory (32) different from the non-volatile memory, a process of erasing the key information stored in the non-volatile memory, and a process of writing the copy information written to the other memory as new key information to the non-volatile memory.

[0058] (Appendix 3) In the control device described in Appendix 1, the non-volatile memory may have a first storage area (44a) and a second storage area (44b), and the rewrite process may include a process of writing the copy information, which is a copy of the key information stored in the first storage area, into the second storage area as new key information.

[0059] (Appendix 4) The control device described in any one of Appendices 1 to 3 may include an acquisition unit (24) that acquires judgment information supplied from outside the control device, and a judgment unit (26) that judges whether or not a predetermined rewrite execution condition is met based on the judgment information acquired by the acquisition unit, and the control unit may execute the rewrite process when the judgment unit judges that the rewrite execution condition is met.

[0060] According to the above configuration, the rewrite process of the key information is executed every time a predetermined timing arrives, so that the rewrite process can be executed before the key information is lost.

[0061] (Appendix 5) In the control device described in Appendix 4, the control device may be provided in a vehicle, and the determination information may be a start count, which is the number of times a switch (12) for starting the vehicle has been operated, and the determination unit may determine that the rewrite execution condition has been met when the start count reaches a predetermined number.

[0062] (Appendix 6) In the control device described in Appendix 4 or 5, the control device may be provided in a vehicle, the judgment information may be the mileage of the vehicle, and the judgment unit may judge that the rewriting execution condition is satisfied when the mileage reaches a predetermined distance.

[0063] (Appendix 7) In the control device according to any one of Supplementary Notes 4 to 6, the determination unit may determine that the rewrite execution condition is satisfied when the time measured by a timer reaches a predetermined time.

[0064] (Appendix 8) In the control device described in any one of Appendices 4 to 7, the control device is provided in a vehicle, the judgment information is the number of times a hood, fuel filler cap, or power filler cap provided in the vehicle has been opened and closed, and the judgment unit may determine that the rewrite execution condition has been met when the number of times the opening and closing has reached a predetermined number.

[0065] (Appendix 9) In the control device according to any one of Supplementary Notes 4 to 8, the determination information may be predetermined information.

[0066] (Appendix 10) In the control device according to any one of Supplementary Notes 1 to 9, when a program installed in the control device is updated, the control unit may execute the rewrite process.

[0067] (Appendix 11) In the control device according to any one of Supplementary Notes 1 to 10, the non-volatile memory may be provided in a hardware security module (52).

[0068] (Appendix 12) In the control device according to any one of Supplementary Notes 1 to 10, only the control unit may be able to access the nonvolatile memory.

[0069] According to the above configuration, only the control unit can execute the process of rewriting the key information, so that it is possible to prevent a malicious third party from rewriting the key information.

[0070] Although the present disclosure has been described in detail, the present disclosure is not limited to the individual embodiments described above. Various additions, substitutions, modifications, partial deletions, etc. are possible in these embodiments without departing from the gist of the present disclosure or the spirit of the present disclosure derived from the content of the claims and their equivalents. These embodiments can also be implemented in combination. For example, in the above-described embodiments, the order of each operation and the order of each process are shown as examples and are not limited to these. The same applies when numerical values ​​or mathematical expressions are used in the description of the above-described embodiments. [Explanation of symbols]

[0071] 12...Start switch (switch) 20...Control device 24...Acquisition unit 26...Determination unit 28...Control unit 32...Buffer (other memory) 38, 54...Non-volatile memory 44a...First bank (first storage area) 44b...Second bank (second storage area) 46...Key information 48...Copy information 52...Hardware security module, HSM

Claims

1. a non-volatile memory that stores key information; a control unit that can execute a rewrite process of copying the key information stored in the nonvolatile memory and writing the copied information into the nonvolatile memory as new key information; A control device comprising:

2. 2. The control device according to claim 1, The rewrite process includes a process of writing the copy information to another memory different from the non-volatile memory, a process of erasing the key information stored in the non-volatile memory, and a process of writing the copy information written to the other memory as new key information to the non-volatile memory.

3. 2. The control device according to claim 1, the nonvolatile memory includes a first storage area and a second storage area; The control device, wherein the rewriting process includes a process of writing the copy of the key information stored in the first storage area to the second storage area as new key information.

4. 2. The control device according to claim 1, an acquisition unit that acquires determination information supplied from outside the control device; a determination unit that determines whether a predetermined rewrite execution condition is satisfied based on the determination information acquired by the acquisition unit; Equipped with The control unit executes the rewrite process when the determination unit determines that the rewrite execution condition is satisfied.

5. 5. The control device according to claim 4, The control device is provided in a vehicle, The determination information is a start count, which is the number of times a switch for starting the vehicle has been operated, The determination unit determines that the rewrite execution condition is satisfied when the number of activations reaches a predetermined number.

6. 5. The control device according to claim 4, The control device is provided in a vehicle, the determination information is a travel distance of the vehicle, The determination unit determines that the rewrite execution condition is satisfied when the travel distance reaches a predetermined distance.

7. 5. The control device according to claim 4, The control device, wherein the determination unit determines that the rewrite execution condition is satisfied when the time measured by a timer reaches a predetermined time.

8. 5. The control device according to claim 4, The control device is provided in a vehicle, the determination information is the number of times a hood, a fuel filler cap, or a power filler cap provided on the vehicle is opened and closed, The determination unit determines that the rewrite execution condition is satisfied when the number of times of opening and closing reaches a predetermined number.

9. 5. The control device according to claim 4, The control device, wherein the determination information is predetermined information.

10. 2. The control device according to claim 1, A control device, wherein the control unit executes the rewriting process when a program installed in the control device is updated.

11. The control device according to any one of claims 1 to 10, The control device, wherein the non-volatile memory is provided in a hardware security module.

12. The control device according to any one of claims 1 to 10, A control device, wherein only the control unit can access the nonvolatile memory.

Citation Information

Patent Citations

  • In-vehicle gateway and key management device

    WO2018070242A1