Control device and control method
The control device integrates MILS and ZTA architectures to enhance vehicle security by allowing dynamic policy enforcement under specific conditions, addressing increased attack surfaces and maintaining real-time capabilities.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-24
- Publication Date
- 2026-04-03
AI Technical Summary
The integration of vehicle architecture increases attack points and attack paths, necessitating a security architecture that can improve security while maintaining real-time capabilities and flexibility in response to changes in vehicle status.
A control device integrating MILS and ZTA architectures, with a first access control unit enforcing static policies and a second access control unit compelling the use of dynamic policies under certain conditions, ensuring real-time and flexible communication access control.
The solution enables flexible control of communication access in response to vehicle status changes while ensuring real-time performance, enhancing security by mitigating strict policy management and compensating for real-time limitations.
Smart Images

Figure 2026057826000001_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a control device and a control method.
Background Art
[0002] There is known a security system for monitoring communication access within a vehicle (see, for example, Patent Document 1). The vehicle architecture applied to such a security system has been evolving from a conventional gateway architecture to a domain architecture and then to a zone architecture centered on a high-performance computer. By strengthening the cooperation between systems within the vehicle through the integration of the vehicle architecture, it becomes possible to realize more advanced functions.
[0003] In addition, with the progress of CASE (Connected, Autonomous, Shared, Electric) technology, the concept of so-called SDV (Software Defined Vehicle), which defines the functions of a vehicle by software, has been spreading. As a result, even after a user purchases a vehicle, it becomes possible to easily add or change the functions of the vehicle by updating the software.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, with the integration of the vehicle architecture, the attack points and attack paths (so-called attack surfaces) that can be targeted by external attacks increase, so there is a demand for realizing a security architecture capable of improving security. [[ID=4l]]
[0006] Therefore, this disclosure provides a control device and a control method that can improve security. [Means for solving the problem]
[0007] A control device according to one aspect of the present disclosure is a control device mounted on a vehicle system logically divided into a plurality of regions, comprising: a first access control unit that controls communication access between two of the plurality of regions based on a static policy; a determination unit that controls communication access between the two regions based on a dynamic policy; and a second access control unit that controls communication access between the two regions based on the control result of the determination unit, wherein the second access control unit compels the first access control unit to use the dynamic policy in place of a part of the static policy when certain conditions are met.
[0008] These comprehensive or specific embodiments may be implemented as a system, method, integrated circuit, computer program, or recording medium such as a computer-readable CD-ROM (Compact Disc-Read Only Memory), or as any combination of a system, method, integrated circuit, computer program, and recording medium. [Effects of the Invention]
[0009] According to one aspect of this disclosure, a control device, etc., can be used to improve security. [Brief explanation of the drawing]
[0010] [Figure 1] This is a block diagram showing the configuration of a vehicle system according to an embodiment. [Figure 2] This is a block diagram showing the configuration of the control device according to the embodiment. [Figure 3] This is a diagram illustrating the operation of the control device according to the embodiment. [Figure 4] This flowchart shows the operation flow of the control device according to the embodiment. [Modes for carrying out the invention]
[0011] (Technology 1) A control device mounted on a vehicle system logically divided into multiple regions, comprising: a first access control unit that controls communication access between two of the multiple regions based on a static policy; a determination unit that controls communication access between the two regions based on a dynamic policy; and a second access control unit that controls communication access between the two regions based on the control result of the determination unit, wherein the second access control unit compels the first access control unit to use the dynamic policy in place of a part of the static policy when predetermined conditions are met.
[0012] According to Technology 1, the second access control unit compels the first access control unit to use a dynamic policy in place of a portion of the static policy, only when certain conditions are met. In other words, the strict policy management in the first access control unit is mitigated by the flexible policy management in the determination unit and the second access control unit, and the lack of real-time capabilities in the determination unit and the second access control unit is compensated for by the real-time capabilities of the first access control unit. This allows for flexible control of communication access between the two domains in response to changes in the vehicle's status, while also ensuring real-time capabilities. As a result, security can be improved.
[0013] (Technology 2) The control device according to Technology 1, wherein the first access control unit further controls communication access to a resource in a specific area by a component in a specific area among the plurality of areas based on the static policy, the determination unit further controls communication access to a resource in a specific area by a component in a specific area based on the dynamic policy, and the second access control unit further controls communication access to a resource in a specific area by a component in a specific area based on the control result of the determination unit.
[0014] According to Technology 2, communication access within a specific area can be flexibly controlled in response to changes in the vehicle's condition, and real-time capabilities can be ensured. As a result, security can be improved.
[0015] (Technology 3) The control device according to Technology 1 or 2, further comprising a plurality of devices included in each of the plurality of regions, wherein the second access control unit authenticates the identity of the region or device that is the source of the communication access request, and the determination unit controls communication access between the two regions based on the dynamic policy, taking into consideration the authentication result of the identity of the source of the communication access request.
[0016] According to Technology 3, security can be further enhanced by authenticating the identity of the source requesting communication access.
[0017] (Technology 4) The control device according to Technology 3, wherein a different secret key or common key is assigned to each of the multiple areas or each of the multiple devices, the second access control unit has a public key or the common key corresponding to the secret key of the area or device corresponding to the second access control unit, and authenticates the identity of the requester of the communication access using the public key or the common key.
[0018] According to Technique 4, by authenticating the identity of the requester of communication access using a public key or a common key, security can be further enhanced.
[0019] (Technique 5) The second access control unit is the control device according to Technique 3, which further authenticates the identity of each area on the communication access path from the area of the originator of the communication access to the area of the recipient of the communication access.
[0020] According to Technique 5, by authenticating the identity of each area on the communication access path from the area of the originator of the communication access to the area of the recipient of the communication access, authentication can be hierarchized and security can be further enhanced.
[0021] (Technique 6) The determination unit is the control device according to any one of Techniques 1 to 5, which acquires vehicle status information regarding the status of the vehicle on which the vehicle system is mounted and controls communication access between the two areas based on the dynamic policy in consideration of the acquired vehicle status information.
[0022] According to Technique 6, communication access between two areas can be flexibly controlled according to the status of the vehicle indicated by the vehicle status information.
[0023] (Technique 7) The determination unit is the control device according to Technique 6, which changes the dynamic policy according to the status of the vehicle indicated by the vehicle status information.
[0024] According to Technique 7, communication access between two areas can be flexibly controlled according to the status of the vehicle indicated by the vehicle status information.
[0025] (Technique 8) The determination unit is the control device according to any one of Techniques 1 to 7, which acquires detection information indicating that an attack on the control device has been detected and changes the dynamic policy based on the detection information.
[0026] According to Technology 8, communication access between the two domains can be flexibly controlled in response to the detection results of an attack on the control device.
[0027] (Technology 9) The control device according to Technical Reference 8, wherein the determination unit further disables the dynamic policy and stops control of the second access control unit if the detection information indicates that an attack has been detected against the second access control unit.
[0028] According to Technology 9, if the second access control unit becomes compromised, communication access between the two domains can be reliably controlled by applying only the static policy of the first access control unit.
[0029] (Technology 10) The control device according to any one of the technologies 1 to 9, wherein the first access control unit controls communication access for tasks requiring real-time performance, and the second access control unit controls communication access for tasks not requiring real-time performance.
[0030] According to technology 10, real-time control of communication access can be ensured.
[0031] (Technology 11) The control device according to Technology 10, wherein the first access control unit prioritizes and controls communication access for high-priority tasks based on a priority indicating the degree to which real-time performance is required.
[0032] According to technology 11, real-time control of communication access can be ensured.
[0033] (Technology 12) The control device according to any one of the technologies 1 to 11, wherein the second access control unit caches the evaluation result of the determination unit regarding whether the requested communication access conforms to the dynamic policy, and when a request for communication access is made, the second access control unit controls the communication access based on the cached evaluation result if an evaluation result matching the requested communication access is cached, and (ii) when an evaluation result matching the requested communication access is not cached, it queries the determination unit to determine whether the requested communication access conforms to the dynamic policy.
[0034] According to technology 12, the evaluation time of the judgment unit can be shortened.
[0035] (Technology 13) The control device according to any one of the technologies 1 to 12, wherein the second access control unit calculates and caches the evaluation results of the determination unit for the frequently used policy items among the dynamic policies when the control device is started.
[0036] According to technology 13, the evaluation time of the judgment unit can be shortened.
[0037] (Technology 14) The control device according to technology 12 or 13, wherein the second access control unit assigns an electronic signature or MAC (Message Authentication Code) to the cached evaluation result.
[0038] According to Technique 14, the integrity of the cache can be guaranteed.
[0039] (Technology 15) The control device according to any one of the technologies 1 to 14, wherein the control device comprises a plurality of second access control units, each of which is arranged in the plurality of regions and is capable of communicating with the determination unit.
[0040] According to Technology 15, by distributing the second access control units in each region, the processing load on each second access control unit can be reduced. As a result, real-time control of communication access can be ensured.
[0041] (Technology 16) The control device according to Technical Reference 15, wherein the determination unit includes a master determination unit and a plurality of edge determination units, the master determination unit and the plurality of edge determination units are respectively arranged in the plurality of regions and are each capable of communicating with the plurality of second access control units, and the master determination unit is capable of communicating with each of the plurality of edge determination units.
[0042] According to Technology 16, by distributing the determination units (master determination unit and multiple edge determination units) across different regions, the processing load on each determination unit can be reduced. As a result, real-time control of communication access can be ensured.
[0043] (Technology 17) The control device according to Technical Reference 16, wherein each of the plurality of edge determination units transmits an evaluation result regarding whether the requested communication access conforms to the dynamic policy to the master determination unit.
[0044] According to Technology 17, evaluation results can be shared between the master determination unit and multiple edge determination units.
[0045] (Technology 18) The control device according to Technical Reference 17, wherein the master determination unit distributes information necessary for determining whether to allow or deny communication access based on the dynamic policy to each of the plurality of edge determination units.
[0046] According to Technology 18, information can be shared between the master determination unit and multiple edge determination units.
[0047] (Technology 19) The control device according to any one of the technologies 15 to 18, wherein two or more second access control units are arranged for each of the plurality of regions, the control device further comprises a plurality of microcontrollers, and the plurality of second access control units are arranged corresponding to each of the plurality of microcontrollers.
[0048] According to Technology 19, by distributing the second access control units in each region, the processing load on each second access control unit can be reduced. As a result, real-time control of communication access can be ensured.
[0049] (Technology 20) A control method for a control device mounted on a vehicle system logically divided into multiple regions, comprising: (a) controlling communication access between two of the multiple regions based on a static policy; (b) controlling communication access between the two regions based on a dynamic policy; (c) controlling communication access between the two regions based on the control result of (b); and (d) forcing the use of the dynamic policy in place of a part of the static policy in (a) when predetermined conditions are met.
[0050] According to Technology 20, similar to Technology 1, communication access between the two domains can be flexibly controlled in response to changes in the vehicle's condition, and real-time functionality can be ensured. As a result, security can be improved.
[0051] These comprehensive or specific embodiments may be implemented as a system, method, integrated circuit, computer program, or recording medium such as a computer-readable CD-ROM, or as any combination of a system, method, integrated circuit, computer program, or recording medium.
[0052] The embodiments will be described in detail below with reference to the drawings.
[0053] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, arrangement and connection configurations of components, steps, and the order of steps shown in the following embodiments are examples only and are not intended to limit this disclosure. Furthermore, among the components in the following embodiments, those not described in the independent claim representing the highest-level concept will be described as optional components.
[0054] (Embodiment) [1.Premise] The control device according to this embodiment is characterized by a security architecture that integrates the MILS (Multiple Independent Levels of Security) architecture and the ZTA (Zero Trust Architecture).
[0055] Before describing the control device according to the embodiment, we will now explain the problems that arise when the MILS architecture and ZTA are applied to a vehicle system individually.
[0056] [1-1. Application of MILS Architecture to Vehicle Systems] The MILS architecture is a security concept based on the premise of logically separating information and processes with different security levels.
[0057] The main component of the MILS architecture is the SK (Separation Kernel), which logically separates information and processes with different security levels and manages them to prevent interference with each other.
[0058] When such a MILS architecture is applied to a vehicle system, such as a domain architecture, the following problems arise.
[0059] The vehicle system is logically divided by SK into multiple partitions with different security levels. SK also controls communication access between the two partitions based on static policies.
[0060] However, since static policies are predetermined and unchangeable, they cannot be changed in response to changes in the vehicle's status (e.g., stopped, engine off, charging, and driving on a highway). Therefore, the MILS architecture faces the challenge of not being able to flexibly control communication access between the two partitions in response to changes in the vehicle's status.
[0061] [1-2. Application of ZTA to Vehicle Systems] ZTA is a security concept that assumes all communication access requests are constantly verified and authenticated.
[0062] The main components of ZTA are the PEP (Policy Enforcement Point) and the PDP (Policy Decision Point). The PEP is where dynamic policies are implemented, receiving communication access requests and sending them to the PDP. The PDP verifies whether to grant or deny the communication access requests received from the PDP based on the dynamic policy. Here, since the dynamic policy is a changeable policy, it can be modified as needed in response to changes in the vehicle's status, etc.
[0063] When such a ZTA is applied to a vehicle system, such as a domain architecture, the following problems arise.
[0064] Because the vehicle's status changes constantly, real-time performance is crucial for vehicle control systems. However, with ZTA, the constant verification of the acquisition or denial of all communication access requests via PDP causes delays, making it difficult to ensure real-time performance.
[0065] [1-3. Application of MILS Architecture and ZTA to Vehicle Systems] In the control device according to this embodiment, the MILS architecture and ZTA are integrated and applied to the vehicle system. That is, the strict policy management in the MILS architecture is mitigated by the flexible policy management in ZTA, and the lack of real-time capabilities in ZTA is compensated for by the real-time capabilities of the MILS architecture.
[0066] This allows for flexible control of communication access between the two partitions in response to changes in the vehicle's status, while also ensuring real-time performance. In other words, it solves the problems that arise when the MILS architecture and ZTA described above are applied to the vehicle system individually.
[0067] [2. Vehicle System Configuration] The configuration of the vehicle system 2 according to the embodiment will be described with reference to Figure 1. Figure 1 is a block diagram showing the configuration of the vehicle system 2 according to the embodiment.
[0068] As shown in Figure 1, the vehicle system 2 is configured, for example, in a domain architecture and is installed in a vehicle such as an automobile. The vehicle system 2 includes a body domain controller 4, a powertrain domain controller 6, an infotainment domain controller 8, a chassis domain controller 10, and a central gateway 12.
[0069] The body domain controller 4 is a function-integrated electronic control unit (ECU) for controlling the opening and closing of vehicle windows, etc. The body domain controller 4 includes microcontrollers (MCUs) 14, 16, a hypervisor 18, virtual machines (VMs) 20, 22 (an example of multiple devices), and an operating system (OS) 24.
[0070] The microcontrollers 14 and 16 are hardware components that provide an execution environment for multiple computer programs. The microcontrollers 14 and 16 are connected to each other via SPI (Serial Peripheral Interface) 25, enabling communication between them.
[0071] The hypervisor 18 is virtualization software that runs on the microcontroller 14 and controls the execution of virtual machines 20 and 22. This hypervisor 18 allows multiple different virtual machines 20 and 22 to be virtualized and deployed on a single microcontroller 14. The hypervisor 18 is a so-called Type 1 (bare metal) hypervisor.
[0072] Virtual machines 20 and 22 are virtual machines running on hypervisor 18, such as Linux (registered trademark).
[0073] Operating system 24 is an operating system that runs on the microcontroller 16.
[0074] The powertrain domain controller 6 is a function-integrated electronic control unit for controlling the vehicle's engine and other components. The powertrain domain controller 6 includes microcontrollers 26 and 28, an operating system 30, a hypervisor 32, and virtual machines 34 and 36 (an example of multiple devices).
[0075] Microcontrollers 26 and 28 are hardware that provides an execution environment for multiple computer programs. Microcontrollers 26 and 28 are connected to each other via SPI 37, enabling communication. Microcontroller 26 is also connected to the microcontroller 16 of the body domain controller 4 via CAN (Controller Area Network) bus 38, enabling communication.
[0076] Operating system 30 is an operating system that runs on the microcontroller 26.
[0077] The hypervisor 32 is virtualization software that runs on the microcontroller 28 and controls the execution of virtual machines 34 and 36. This hypervisor 32 allows multiple different virtual machines 34 and 36 to be virtualized and deployed on a single microcontroller 28. The hypervisor 32 is a so-called Type 1 hypervisor.
[0078] Virtual machines 34 and 36 are virtual machines running on hypervisor 32, such as Linux.
[0079] The infotainment domain controller 8 is a function-integrated electronic control unit for controlling a communication module that wirelessly connects the vehicle to a communication network such as the Internet. The infotainment domain controller 8 includes a microcontroller 40, a hypervisor 42, and virtual machines 44, 46, 48 (an example of multiple devices).
[0080] The microcontroller 40 is hardware that provides an execution environment for multiple computer programs.
[0081] The hypervisor 42 is virtualization software that runs on the microcontroller 40 and controls the execution of virtual machines 44, 46, and 48. This hypervisor 42 allows multiple different virtual machines 44, 46, and 48 to be virtualized and deployed on a single microcontroller 40. The hypervisor 42 is a so-called Type 1 hypervisor.
[0082] Virtual machines 44, 46, and 48 are virtual machines running on hypervisor 42, such as Linux.
[0083] The chassis domain controller 10 is a function-integrated electronic control unit for controlling the operation of the vehicle's brakes and other functions. The chassis domain controller 10 includes a microcontroller 50, a hypervisor 52, and virtual machines 54, 56, 58 (an example of multiple devices).
[0084] The microcontroller 50 is hardware that provides an execution environment for multiple computer programs.
[0085] Hypervisor 52 is virtualization software that runs on microcontroller 50 and controls the execution of virtual machines 54, 56, and 58. This hypervisor 52 allows multiple different virtual machines 54, 56, and 58 to be virtualized and deployed on a single microcontroller 50. Hypervisor 52 is a so-called Type 1 hypervisor.
[0086] Virtual machines 54, 56, and 58 are virtual machines running on hypervisor 52, such as Linux.
[0087] The central gateway 12 is connected to the microcontroller 14 of the body domain controller 4, the microcontroller 28 of the powertrain domain controller 6, the microcontroller 40 of the infotainment domain controller 8, and the microcontroller 50 of the chassis domain controller 10, all of which are communicated via Ethernet® 60.
[0088] [3. Control device configuration] Next, the configuration of the control device 61 according to the embodiment will be described with reference to Figure 2. Figure 2 is a block diagram showing the configuration of the control device 61 according to the embodiment.
[0089] As shown in Figure 2, the control device 61 is a security architecture that integrates the MILS architecture and ZTA, and is mounted on the vehicle system 2 described above.
[0090] The control unit 61 includes a plurality of SK62 (62a, 62b, 62c, 62d, 62e, 62f) (an example of a first access control unit) as components of the MILS architecture. The SK62 has, as static policies in the MILS architecture, (i) a static partition isolation policy, (ii) an immutable static access control policy, and (iii) a modifiable static access control policy.
[0091] Here, a static policy is a predetermined policy that, in principle, cannot be changed. That is, while static policies are unchangeable, exceptionally, only a portion of the static policy (a changeable static access control policy) can be changed, provided that certain conditions described later are met. Note that static policies are expressed in a format that can be understood by PDP66, which will be described later.
[0092] Among the static policies, the static partition isolation policy is a policy for logically dividing the vehicle system 2 into multiple partitions 64 (64a, 64b, 64c, 64d, 64e, 64f) (an example of multiple areas) with different security levels. In Figure 2, the multiple partitions 64 are shown with dashed outlines.
[0093] Furthermore, among the static policies, immutable static access control policies and modifiable static access control policies define (a) which components within partition 64 can access which resources within the same partition 64, and (b) which partition 64 is permitted to communicate with which other partition 64. In other words, among the static policies, immutable static access control policies and modifiable static access control policies are policies defined for communication access to all resources within each partition 64.
[0094] Based on a static policy (static partition isolation policy), SK62 logically divides the vehicle system 2 into multiple partitions 64 with different security levels (i.e., different policies). SK62 also appropriately allocates resources such as CPU (Central Processing Unit), memory, and I / O (Input / Output) to each of the multiple partitions 64.
[0095] Partition 64a includes a portion of the body domain controller 4. Partition 64b includes a portion of the body domain controller 4 and a portion of the infotainment domain controller 8. Partition 64c includes a portion of the body domain controller 4 and a portion of the powertrain domain controller 6. Partition 64d includes a portion of the powertrain domain controller 6. Partition 64e includes a portion of the infotainment domain controller 8 and a portion of the chassis domain controller 10. Partition 64f includes a portion of the chassis domain controller 10.
[0096] In this embodiment, communication access is possible between partition 64b and partition 64c, and between partition 64b and partition 64e. On the other hand, communication access is not possible between partition 64a and partition 64b, between partition 64c and partition 64d, and between partition 64e and partition 64f.
[0097] Here, SK62a is located in the hypervisor 18 of the body domain controller 4, positioned to straddle partition 64a and partition 64b. Also, SK62b is located in the operating system 24 of the body domain controller 4. Furthermore, SK62c is located in the operating system 30 of the powertrain domain controller 6. Furthermore, SK62d is located in the hypervisor 32 of the powertrain domain controller 6, positioned to straddle partition 64c and partition 64d. Furthermore, SK62e is located in the hypervisor 42 of the infotainment domain controller 8, positioned to straddle partition 64b and partition 64e. Furthermore, SK62f is located in the hypervisor 52 of the chassis domain controller 10, positioned to straddle partition 64e and partition 64f.
[0098] Furthermore, SK62 suppresses data leakage and unauthorized access by controlling communication access between two partitions 64 of multiple partitions 64 based on static policies (static access control policies that cannot be changed, and static access control policies that can be changed). Specifically, SK62 determines whether or not to allow communication access between two partitions 64 based on the static policy. If SK62 determines that communication access between the two partitions 64 should be allowed, it allows communication access between the two partitions 64. On the other hand, if SK62 determines that communication access between the two partitions 64 should not be allowed, it disconnects the communication access between the two partitions 64. As a result, each of the multiple partitions 64 is isolated from the influence of the other partitions 64 and operates independently.
[0099] Furthermore, SK62 controls communication access to resources within a specific partition 64 by components within that partition 64, based on static policies (static access control policies that cannot be changed, and static access control policies that can be changed). In this case as well, as described above, SK62 determines whether to allow or deny the communication access and controls the communication access based on the determination result.
[0100] Furthermore, the control device 61 includes, as components of the ZTA, a plurality of PDPs 66 (an example of a determination unit) and a plurality of PEPs 68 (68a, 68b, 68c, 68d, 68e, 68f) (an example of a second access control unit).
[0101] The PDP66 has a dynamic policy. The dynamic policy is a policy that can be changed even after the control device 61 has been shipped. In response to an inquiry from the PEP68, the PDP66 determines, based on the dynamic policy, whether to allow communication access between two of the multiple partitions 64 (i.e., it controls communication access between two partitions 64). The PDP66 also evaluates the context of the communication access request (e.g., the user's role, the device state, and the timing of the communication access) and applies an appropriate policy from the dynamic policies according to the evaluation result. Furthermore, in response to an inquiry from the PEP68, the PDP66 determines, based on the dynamic policy, whether to allow a component in a specific partition 64 to access resources within that specific partition 64 (i.e., it controls communication access to resources within a specific partition 64).
[0102] Multiple PDPs 66 include a master PDP 66a (an example of a master determination unit) and multiple edge PDPs 66b, 66c, and 66d (an example of edge determination units). The master PDP 66a and the multiple edge PDPs 66b, 66c, and 66d are arranged in each partition 64. Specifically, the master PDP 66a is located in partition 64c (the hypervisor 32 of the powertrain domain controller 6). The edge PDP 66b is located in partition 64b (the hypervisor 18 of the body domain controller 4). The edge PDP 66c is located in partition 64b (the hypervisor 42 of the infotainment domain controller 8). The edge PDP 66d is located in partition 64e (the hypervisor 52 of the chassis domain controller 10).
[0103] The master PDP 66a is communicated with each of the multiple edge PDPs 66b, 66c, and 66d. This allows the master PDP 66a to share information with each of the multiple edge PDPs 66b, 66c, and 66d. Specifically, the master PDP 66a aggregates information for the entire vehicle system 2, and distributes information necessary for determining whether to grant or deny communication access based on dynamic policy to each of the edge PDPs 66b, 66c, and 66d. Each of the edge PDPs 66b, 66c, and 66d also transmits an evaluation result to the master PDP 66a regarding whether the requested communication access conforms to the dynamic policy. The timing of information sharing between the master PDP 66a and each of the multiple edge PDPs 66b, 66c, and 66d may be, for example, (a) immediately after information acquisition, (b) periodically, (c) immediately in the case of information related to an attack, or (d) when the processing volume is below a certain amount, or a combination thereof.
[0104] Each PEP68 is located for each SK62. Specifically, multiple PEP68a-68f are each located for multiple SK62a-62f. Two PEP68s are located for each partition 64b, 64c, and 64e, with one PEP68 corresponding to each microcontroller 14, 16, 26, 28, 40, and 50. Furthermore, PEP68a and 68b are communicated to the edge PDP66b. PEP68c and 68d are communicated to the master PDP66a. PEP68e is communicated to the edge PDP66c. PEP68f is communicated to the edge PDP66d.
[0105] As a result, the functionality of the SK62 is extended, giving it not only the functionality of the SK62 in the MILS architecture, but also the functionality of the PEP68 in the ZTA.
[0106] When a request for communication access between two of the multiple partitions 64 occurs, PEP68 queries PDP66 to determine whether to allow the communication access. Based on the PDP66's determination (control result), PEP68 controls the communication access between the two partitions 64 to prevent data leakage and unauthorized access. If PDP66 determines that communication access between the two partitions 64 is permitted, PEP68 allows the communication access between the two partitions 64 to proceed. On the other hand, if PDP66 determines that communication access between the two partitions 64 is not permitted, PEP68 disconnects the communication access between the two partitions 64.
[0107] Furthermore, based on the determination result of the PDP66, the PEP68 controls communication access to resources within a specific partition 64 by components within that partition 64. In this case as well, similar to the above, the PEP68 queries the PDP66 to determine whether the communication access is permitted or not, and controls the communication access based on the determination result of the PDP66.
[0108] Furthermore, PEP68 is assigned communication access for tasks that do not require real-time processing, while SK62, as described above, is assigned communication access for tasks that do require real-time processing. As a result, PEP68 controls communication access for tasks that do not require real-time processing, while SK62 controls communication access for tasks that do require real-time processing. Note that SK62 may prioritize the control of communication access for higher-priority tasks based on a priority level indicating the degree to which real-time processing is required.
[0109] Furthermore, PEP68 monitors and logs each communication access. This information is used by the control unit 61 to detect and respond to security incidents.
[0110] Furthermore, PEP68 compels SK62 to use dynamic policies instead of static policies (modifiable static access control policies) only if certain conditions are met. PEP68 acquires vehicle status information, such as vehicle status (e.g., stopped, engine off, charging, and highway driving), and determines whether the predetermined conditions are met based on the vehicle status indicated by the acquired vehicle status information. Three use cases (Use Cases 1-3) for enforcing dynamic policies are described below.
[0111] First, let's explain Use Case 1. In Use Case 1, software for checking the charging status of the vehicle's battery on a smartphone is installed on the vehicle system 2, and the powertrain domain controller 6 is used to charge the vehicle's battery.
[0112] A static policy (a static access control policy that cannot be changed) prohibits communication access from partition 64b to partition 64c, while allowing periodic transmission of battery level information from partition 64c to partition 64b.
[0113] The dynamic policy allows communication access for requests to obtain information indicating the charging status from partition 64b to partition 64c, provided that the status of vehicle system 2 is connected to an EV (Electric Vehicle) charger and charging.
[0114] Therefore, PEP68 compels SK62 to use a dynamic policy, "Allow communication access for requests to obtain information indicating the charging status from partition 64b to partition 64c," instead of a static policy, "Prohibit communication access from partition 64b to partition 64c," only when the vehicle system 2 is connected to an EV charger and is charging, which is a predetermined condition.
[0115] Next, we will explain Use Case 2. In Use Case 2, maintenance of the vehicle system 2 is performed by the body domain controller 4.
[0116] A static policy (a static access control policy that cannot be changed) prohibits communication access from partition 64b to partition 64e.
[0117] The dynamic policy allows the transmission of maintenance commands from partition 64b to partition 64e, provided that the status of vehicle system 2 is connected to a maintenance tool and undergoing maintenance, and the vehicle is stationary.
[0118] Therefore, PEP68 forces SK62 to use a dynamic policy of "allowing the transmission of maintenance commands from partition 64b to partition 64e" instead of a static policy of "prohibiting communication access from partition 64b to partition 64e" only when the vehicle system 2 is connected to a maintenance tool and undergoing maintenance, and the vehicle is stationary, and certain conditions are met.
[0119] Next, we will explain Use Case 3. In Use Case 3, if an attacker intrusion is detected in partition 64b, a dynamic policy is implemented to prohibit communication access from partition 64b to the other partitions 64c and 64e.
[0120] In this case, even if the specified conditions described in Use Cases 1 and 2 above are met, the enforcement of the dynamic policy in Use Cases 1 and 2 will not be performed, and the dynamic policy in Use Case 3 will take precedence.
[0121] Furthermore, resource requests within partition 64b will also undergo additional authentication in addition to normal authentication. For example, integrity verification will be performed on the process being authenticated.
[0122] [4. Operation of the control device] Next, the operation of the control device 61 according to the embodiment will be described with reference to Figures 3 and 4. Figure 3 is a diagram illustrating the operation of the control device 61 according to the embodiment. Figure 4 is a flowchart showing the operation flow of the control device 61 according to the embodiment.
[0123] For the sake of clarity, the vehicle system 2 is assumed to comprise a microcontroller 70, a hypervisor 72, and virtual machines 74, 76, and 78, as shown in Figure 3. Furthermore, the vehicle system 2 is assumed to be logically divided into two partitions 64 (64g, 64h) with different security levels by the SK62 of the control device 61. Additionally, the SK62 of the control device 61, the PDP 66, and the PEP 68 are assumed to be located in the hypervisor 72.
[0124] As shown in Figure 4, first, a communication access request occurs between the two partitions 64g and 64h (S101). For example, a communication access request occurs from virtual machine 74 in partition 64g to virtual machine 76 in partition 64h.
[0125] If the communication access relates to a task requiring real-time performance (YES in S102) and does not meet the predetermined conditions (NO in S103), SK62 controls the communication access between the two partitions 64g and 64h based on a static policy (S104).
[0126] On the other hand, if the communication access relates to a task requiring real-time performance (YES in S102) and certain conditions are met (YES in S103), PEP68 compels SK62 to use a dynamic policy instead of a portion of the static policy (a modifiable static access control policy) (S105). As a result, SK62 controls communication access between the two partitions 64g and 64h based on the dynamic policy compelled by PEP68 instead of a portion of the static policy (S106).
[0127] Returning to step S102, if the communication access is not related to a task requiring real-time processing (NO in S102), PEP68 queries PDP66 for permission to access the communication (S107).
[0128] Next, in response to the inquiry from PEP68, PDP66 determines, based on the dynamic policy, whether or not to allow communication access between the two partitions 64g and 64h (S108).
[0129] Next, PEP68 controls communication access between the two partitions 64g and 64h based on the determination result of PDP66 (S109).
[0130] [5. Effects] As described above, the control device 61 according to the embodiment is a security architecture that combines the MILS architecture and ZTA, extending the SK62 based on the MILS architecture. Specifically, the PEP68 compels the SK62 to use a dynamic policy based on ZTA instead of a part of the static policy based on the MILS architecture, only when certain conditions are met.
[0131] In other words, the control device 61 mitigates the strict policy management in the MILS architecture with the flexible policy management in ZTA, and compensates for the lack of real-time capabilities in ZTA with the real-time capabilities of the MILS architecture. This allows for flexible control of communication access between the two partitions 64 in response to changes in the vehicle's condition, while also ensuring real-time capabilities. Therefore, for example, even if the software is updated to add or change vehicle functions using SDV as described in the background technology section, the updated software can be easily adapted.
[0132] As a result, a security architecture that can improve security can be realized.
[0133] [6. Various variations] The following describes various modified examples of the control device 61 according to the embodiment.
[0134] [6-1. Variation 1] PEP68 may authenticate the identity of the partition 64 or virtual machine requesting communication access. In this case, PDP66 may consider the authentication result of the identity requesting communication access and, based on a dynamic policy, determine whether or not to allow communication access between the two partitions 64. This can further enhance security.
[0135] Furthermore, different private or shared keys may be assigned to each of the multiple partitions 64 or each of the multiple virtual machines. In this case, PEP68 has a public or shared key corresponding to the private key of the partition 64 or virtual machine corresponding to PEP68, and may use the public or shared key to authenticate the identity of the person requesting communication access.
[0136] Furthermore, PEP68 may authenticate the identity of each partition 64 along the communication access path from the partition 64 that initiates the communication access to the partition 64 that requests the communication access (for example, partition 64c → partition 64b → partition 64e).
[0137] [6-2. Variation 2] The PDP66 may acquire vehicle status information regarding the vehicle's condition and, based on a dynamic policy that takes the acquired vehicle status information into account, determine whether or not to allow communication access between the two partitions 64. In this case, the PDP66 may appropriately modify the dynamic policy according to the vehicle's condition as indicated by the vehicle status information.
[0138] This allows for flexible control of communication access between the two partitions 64 according to the vehicle status indicated by the vehicle status information.
[0139] [6-3. Modification 3] The PDP66 may acquire detection information indicating that it has detected an attack on the control device 61, and may appropriately modify the dynamic policy based on the detection information.
[0140] Alternatively, if PDP66 detects that it has detected an attack on PEP68, it may disable the dynamic policy and suspend control of PEP68. This ensures that, in the event of PEP68 compromise, communication access between the two partitions 64 can be reliably controlled by applying only the static policy from SK62. In this case, a backup PEP68 may be prepared in advance, and a quick switch from the compromised PEP68 to the backup PEP68 may be made. This allows for the early restoration of the application of the dynamic policy.
[0141] [6-4. Modification 4] PEP68 may cache the evaluation results from PDP66 regarding whether the requested communication access conforms to the dynamic policy. When a communication access request is made, PEP68 may (i) control the communication access based on the cached evaluation result if an evaluation result matching the requested communication access is cached, or (ii) query PDP66 to determine whether the requested communication access conforms to the dynamic policy if an evaluation result matching the requested communication access is not cached. This can shorten the evaluation time of PDP66.
[0142] Furthermore, when the control device 61 is started, PEP68 may calculate and cache the evaluation results of the frequently used policy items among the dynamic policies, as calculated by PDP66.
[0143] Furthermore, PEP68 may affix an electronic signature or MAC (Message Authentication Code) to the cached evaluation results.
[0144] (Other variations) Although control devices relating to one or more embodiments have been described above based on the above embodiments, this disclosure is not limited to the above embodiments. Without departing from the spirit of this disclosure, various modifications that a person skilled in the art can conceive of may be applied to the above embodiments, and forms constructed by combining components from different embodiments may also be included within the scope of one or more embodiments.
[0145] In the above embodiment, multiple PDPs 66 are arranged in the vehicle system 2, but the invention is not limited to this, and only one PDP 66 may be arranged in the vehicle system 2.
[0146] Alternatively, one edge PDP may be deployed per partition or per domain controller, and information may be synchronized between each edge PDP and the master PDP. Alternatively, multiple PDP66 may be configured entirely with edge PDPs, omitting the master PDP. In this case, information is synchronized between the multiple edge PDPs.
[0147] Furthermore, the division of authentication and authorization for communication access between the two partitions 64 may be configured as follows: Authentication is mediated by SK62 (PEP68), but the actual authentication process may be performed by PDP66. In this case, authorization is performed by PDP66, which determines the necessary authority, and SK62 (PEP68) grants the authority.
[0148] Alternatively, authentication can be performed by SK62 (PEP68), and PDP66 can be not queried for authentication. In this case, PDP66 determines the necessary authority, and SK62 (PEP68) grants the authority.
[0149] Furthermore, adding virtual machines or other devices to partition 64, or creating a new partition 64, constitutes a change to the static partition isolation policy, and therefore the static policy needs to be modified. In this case, it is necessary to rewrite the static policy via OTA (Over The Air) and restart the control device 61. The same applies to the static access control policy.
[0150] Furthermore, resource allocation within partition 64 and the addition of communication between two partitions 64 can be handled by changing the dynamic access control policy, which can be done by modifying the dynamic policy.
[0151] In the above embodiment, each component may be implemented by dedicated hardware or by executing a computer program suitable for each component. Each component may also be implemented by a program execution unit such as a CPU (Central Processing Unit) or processor reading and executing a computer program recorded on a recording medium such as a hard disk or semiconductor memory.
[0152] Furthermore, some or all of the functions of the control device according to each of the above embodiments may be realized by a processor such as a CPU executing a computer program.
[0153] Some or all of the components constituting each of the above-described devices may consist of a removable IC card or a standalone module. The IC card or module is a computer system consisting of a microprocessor, ROM, RAM, etc. The IC card or module may also include the above-described multi-functional LSI. The microprocessor operates according to a computer program, thereby enabling the IC card or module to achieve its function. The IC card or module may also be tamper-resistant.
[0154] This disclosure may be the methods described above. It may also be a computer program that implements these methods using a computer, or a digital signal including the computer program. Furthermore, this disclosure may be a computer-readable, non-temporary recording medium, such as a flexible disk, hard disk, CD-ROM, MO, DVD, DVD-ROM, DVD-RAM, BD (Blu-ray® Disc), semiconductor memory, etc. It may also be the digital signal recorded on such a recording medium. Furthermore, this disclosure may involve transmitting the computer program or digital signal via telecommunications lines, wireless or wired communication lines, networks such as the Internet, data broadcasting, etc. Furthermore, this disclosure may be a computer system comprising a microprocessor and memory, wherein the memory stores the computer program, and the microprocessor operates according to the computer program. Furthermore, this disclosure may be implemented by another independent computer system by recording and transferring the computer program or digital signal on the recording medium, or by transferring the computer program or digital signal via the network, etc. [Industrial applicability]
[0155] The control device relating to this disclosure can be installed in, for example, a vehicle system such as a domain architecture. [Explanation of symbols]
[0156] 2 Vehicle System 4 Body Domain Controller 6. Powertrain Domain Controller 8. Infotainment Domain Controller 10 Chassis Domain Controllers 12 Central Gateway 14, 16, 26, 28, 40, 50, 70 Microcontrollers 18,32,42,52,72 Hypervisor 20,22,34,36,44,46,48,54,56,58,74,76,78 virtual machines 24,30 Operating Systems 25,37 SPI 38 CAN bus 60 Ethernet 61 Control device 62,62a,62b,62c,62d,62e,62f SK 64,64a,64b,64c,64d,64e,64f,64g,64h partitions 66 PDP 66a Master PDP 66b, 66c, 66d Edge PDP 68,68a,68b,68c,68d,68e,68f PEP
Claims
1. A control device mounted on a vehicle system that is logically divided into multiple regions, A first access control unit controls communication access between two of the plurality of regions based on a static policy, A determination unit that controls communication access between the two domains based on a dynamic policy, The system includes a second access control unit that controls communication access between the two regions based on the control result of the determination unit, The second access control unit compels the first access control unit to use the dynamic policy in place of a portion of the static policy when certain conditions are met. Control device.
2. The first access control unit further controls, based on the static policy, communication access to resources within a specific area by components within a specific area among the plurality of areas, The determination unit further controls communication access to resources within the specific region by components within the specific region based on the dynamic policy, The second access control unit further controls communication access to resources within the specific area by components within the specific area based on the control result of the determination unit. The control device according to claim 1.
3. The control device further comprises a plurality of devices, each included in the plurality of regions, The second access control unit authenticates the identity of the area or device that is the source of the communication access request, The determination unit, taking into consideration the authentication result of the identity of the communication access requester, controls communication access between the two domains based on the dynamic policy. The control device according to claim 1.
4. Each of the aforementioned multiple regions or each of the aforementioned multiple devices is assigned a different secret key or common key. The second access control unit has a public key or a common key corresponding to the secret key of the area or device corresponding to the second access control unit, and uses the public key or common key to authenticate the identity of the communication access requester. The control device according to claim 3.
5. The second access control unit further authenticates the identity of each area on the communication access path from the area of the communication access source to the area of the communication access request destination. The control device according to claim 3.
6. The determination unit acquires vehicle status information regarding the status of the vehicle on which the vehicle system is installed, and controls communication access between the two domains based on the dynamic policy which takes into account the acquired vehicle status information. The control device according to claim 1.
7. The determination unit changes the dynamic policy according to the status of the vehicle indicated by the vehicle status information. The control device according to claim 6.
8. The determination unit acquires detection information indicating that an attack on the control device has been detected, and modifies the dynamic policy based on the detection information. The control device according to claim 1.
9. Furthermore, if the determination unit determines that the detection information indicates an attack against the second access control unit, it disables the dynamic policy and stops control of the second access control unit. The control device according to claim 8.
10. The first access control unit controls communication access for tasks requiring real-time performance. The second access control unit controls communication access for tasks that do not require real-time processing. The control device according to claim 1.
11. The first access control unit prioritizes communication access for high-priority tasks based on a priority indicating the degree to which real-time performance is required. The control device according to claim 10.
12. The second access control unit caches the evaluation result from the determination unit regarding whether the requested communication access conforms to the dynamic policy. When a request for communication access is received, the second access control unit (i) controls the communication access based on the cached evaluation result if an evaluation result matching the requested communication access is cached, and (ii) queries the determination unit to determine whether the requested communication access conforms to the dynamic policy if an evaluation result matching the requested communication access is not cached. The control device according to claim 1.
13. The second access control unit calculates and caches the evaluation results of the determination unit for the frequently used policy items among the dynamic policies when the control device is started. The control device according to claim 1.
14. The second access control unit assigns an electronic signature or MAC (Message Authentication Code) to the evaluation results to be cached. The control device according to claim 12 or 13.
15. The control device comprises a plurality of the second access control units, The multiple second access control units are each arranged in the multiple regions and are capable of communicating with the determination unit. The control device according to claim 1.
16. The determination unit includes a master determination unit and a plurality of edge determination units. The master determination unit and the plurality of edge determination units are each arranged in the plurality of regions and are each capable of communicating with the plurality of second access control units. The master determination unit is capable of communicating with each of the plurality of edge determination units. The control device according to claim 15.
17. Each of the multiple edge determination units transmits an evaluation result regarding whether the requested communication access conforms to the dynamic policy to the master determination unit. The control device according to claim 16.
18. The master determination unit distributes information necessary for determining whether to grant or deny communication access based on the dynamic policy to each of the multiple edge determination units. The control device according to claim 17.
19. The second access control unit is arranged in pairs or more for each of the plurality of areas, The control device further comprises a plurality of microcontrollers, The plurality of second access control units are arranged in correspondence to each of the plurality of microcontrollers. The control device according to claim 15.
20. A control method for a control device mounted on a vehicle system that is logically divided into multiple regions, (a) A step of controlling communication access between two of the plurality of regions based on a static policy, (b) A step of controlling communication access between the two domains based on a dynamic policy, (c) A step of controlling communication access between the two regions based on the control result of (b), (d) The step of forcing the use of the dynamic policy in place of a part of the static policy in (a) if certain conditions are met. Control method.
Citation Information
Patent Citations
Secure telematics
JP2006521724A