control device

The control device enhances in-vehicle ECU security by isolating systems upon secure boot failures, preventing malfunctions and attack propagation through drive and communication protection mechanisms.

JP2026059600APending Publication Date: 2026-04-07DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing in-vehicle ECUs fail to adequately counter external attacks during secure boot failures, leading to potential system vulnerabilities and malfunctions.

Method used

A control device with a secure boot unit that verifies control applications, and upon abnormal verification, initiates drive system protection by disconnecting drive units and communication system protection by restricting communication, thereby enhancing security against external attacks.

Benefits of technology

The control device effectively prevents device malfunctions and reduces the risk of external attacks spreading by isolating affected systems, improving overall security and safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026059600000001_ABST
    Figure 2026059600000001_ABST
Patent Text Reader

Abstract

To provide a control device that can improve safety. [Solution] The control device includes a control application storage unit 121 that stores a control application for realizing a desired function, a secure boot unit 302 that performs a secure boot when the control device is started, an application execution unit 201 that starts executing the control application if the verification result by the secure boot unit 302 is normal, a drive control unit 51 that controls a drive unit corresponding to a desired function based on instructions from the control application, and a protection processing unit 304 that performs protection processing if the verification result is abnormal. The protection processing includes drive system protection processing that disconnects the electrical connection between the drive control unit and the drive unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The disclosure in this specification relates to a control device.

Background Art

[0002] Patent Document 1 discloses an in-vehicle ECU that executes fail-safe processing when there is an application that cannot be started due to the verification result of secure boot. More specifically, in secure boot, the in-vehicle ECU verifies the integrity of each of a plurality of applications. For applications with a positive verification result, it is executed, while applications with a negative verification result are not executed. As fail-safe processing, the in-vehicle ECU executes a process of outputting an alternative signal corresponding to an application with a negative verification result.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Software verification failures in secure boot can be caused more by external attacks rather than accidental causes. That is, a failure in secure boot suggests that the system is under external attack. When the verification of secure boot fails, in Patent Document 1, only an alternative signal is output, and no countermeasures such as system stop or network interruption are taken against external attacks. From the perspective of improving security (in other words, safety), further improvement is required for in-vehicle devices.

[0005] One object of the disclosure is to provide a control device capable of improving safety.

Means for Solving the Problems

[0006] The first control device disclosed herein is A control device mounted on a mobile vehicle, A control application storage unit (121) that stores control applications for realizing desired functions, A secure boot unit (302) performs a secure boot to verify the integrity of the control application when the control device is started, If the verification result by the Secure Boot unit is normal, the application execution unit (201) starts executing the control application, A drive control unit (51) controls a drive unit corresponding to a desired function based on instructions from a control application, The system includes a protection processing unit (304) that performs protection processing if the verification result by the secure boot unit is abnormal, The protection process includes a drive system protection process that disconnects the electrical connection between the drive control unit and the drive unit.

[0007] The second control device disclosed herein is A control device mounted on a mobile vehicle, A control application storage unit (121) that stores control applications for realizing desired functions, A communication unit (41) that communicates with other control devices, A secure boot unit (302) performs a secure boot to verify the integrity of the control application when the control device is started, If the verification result by the Secure Boot unit is normal, the application execution unit (201) starts executing the control application, The system includes a protection processing unit (304) that performs protection processing if the verification result by the secure boot unit is abnormal, The protection process includes communication system protection processing that restricts communication between the communication unit and other control devices.

[0008] According to these procedures, if the verification results from the secure boot unit are abnormal, either the drive system protection process or the communication system protection process will be performed. In configurations where the drive system protection process is performed, the electrical connection between the application execution unit and the drive unit that realizes the desired function is cut off, thereby suppressing malfunctions of the device due to external attacks.

[0009] In a configuration where communication protection processing is performed, communication by the communication unit to other control devices is restricted. Therefore, the risk of a control device transmitting inappropriate data to other control devices due to an external attack is reduced. Furthermore, by restricting communication with other control devices, the risk of application malfunctions in one control device causing malfunctions in other control devices can be suppressed. These technologies prevent external attacks from spreading to devices connected to the control device if the verification results by the secure boot unit are abnormal.

[0010] Thus, according to the technology of this disclosure, in situations where there is a high probability of being subjected to an external attack, it is possible to suppress malfunctions of a desired function or at least one of other control devices, thereby improving security. [Brief explanation of the drawing]

[0011] [Figure 1] This diagram shows the configuration of the control device according to the embodiment. [Figure 2] This figure shows an example of a specific configuration of a communication interface and an input / output interface. [Figure 3] This diagram shows the multiple functional units built into the control unit, as well as the timing of each functional unit's operation. [Figure 4] This diagram shows the state transitions of the control device. [Figure 5] This flowchart shows an example of a series of processes performed in a control device. [Figure 6] Figure 5 is a flowchart showing an example of the details of the drive system protection process. [Figure 7] It is a flowchart showing an example of the details of communication system protection processing in the flowchart of FIG. 5. [Figure 8] It is a flowchart showing an example of the details of information storage processing in the flowchart of FIG. 5. [Figure 9] It is a flowchart showing an example of a series of processes executed in the control device in the protection processing state. [Figure 10] It is a diagram showing an application example of the control device. [Figure 11] It is a flowchart showing an example of a series of processes executed in the control device. [Figure 12] It is a flowchart showing an example of the details of drive system protection processing in the flowchart of FIG. 11. [Figure 13] It is a flowchart showing an example of a series of processes executed in the in-vehicle device in the protection processing state. [Figure 14] It is a flowchart showing an example of the details of drive system protection release processing in the flowchart of FIG. 13. [Figure 15] It is a diagram showing an application example of the control device. [Figure 16] It is a diagram showing an application example of the control device. [Figure 17] It is a diagram showing an application example of the control device.

Embodiments for Carrying Out the Invention

[0012] <Embodiment> Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the following description, members having the same function may be given the same name or the same reference numeral, and specific descriptions thereof may be omitted.

[0013] The control device 1 according to this embodiment is used mounted on a mobile body. The mobile body may be a vehicle such as an engine-driven vehicle, a hybrid vehicle, or an electric motor-driven vehicle, an aerial vehicle such as a drone, a ship, construction machinery, or agricultural machinery. In this embodiment, the control device 1 is used mounted on a vehicle. The vehicle to which the control device 1 of this embodiment is applied (hereinafter referred to as the applied vehicle) may be an electric vehicle such as an HV (Hybrid Vehicle) or a BEV (Battery Electric Vehicle). The applied vehicle may also be an engine-powered vehicle. The control device 1 controls equipment mounted on the vehicle. In one aspect, the control device 1 may be read as an on-board device.

[0014] The control device 1 in this embodiment is an ECU (Electronic Control Unit). The control device 1 may be used as any ECU, such as an engine ECU, motor ECU, battery ECU, brake ECU, shift-by-wire ECU, transmission ECU, steering ECU, HV-ECU, BEV-ECU, or autonomous driving ECU. Figure 1 shows an example of a schematic configuration of the control device 1.

[0015] As shown in Figure 1, the control device 1 includes a microcontroller (hereinafter referred to as "microcontroller") 10, a communication interface 40, and an input / output interface 50. The microcontroller 10 includes a processor 11, normal storage 12, secure storage 13, and RAM 14. RAM is an abbreviation for Random Access Memory. In addition to the components described above, the control device 1 may also include various other circuits. For example, the control device 1 may include a power supply circuit to supply power to each component.

[0016] The communication interface 40 is for communicating with other ECUs 2, 3, and 4 mounted in the vehicle via the in-vehicle LAN. Other ECUs 2, 3, and 4 are, for example, zone ECUs or body ECUs. Other ECUs 2, 3, and 4 can be any ECU. Other ECUs 2, 3, and 4 correspond to other control devices. Communication protocols such as CAN (registered trademark), LIN, FLEXRAY (registered trademark), and Ethernet can be used for communication via the in-vehicle LAN. CAN is an abbreviation for Controller Area Network. LIN is an abbreviation for Local Interconnect Network.

[0017] The input / output interface 50 is a circuit for the processor 11 to acquire sensor signals from outside the control device 1 and to output drive signals to the actuators that the control device 1 controls.

[0018] <Communication Interface> Figure 2 shows an example of the specific configuration of the communication interface 40 and the input / output interface 50. The communication interface 40 includes a communication IC 41 and a selector circuit 42. The communication IC 41 performs signal transmission and reception with the other ECUs 2, 3, and 4. The communication IC 41 is, for example, a CAN-compatible IC. In other embodiments, the communication IC 41 may be a communication IC compatible with FlexRay, Ethernet, or LIN. The communication IC 41 further includes a receiving circuit and a transmitting circuit. The receiving circuit is a circuit for receiving data signals. The transmitting circuit is a circuit for outputting data signals.

[0019] The selector circuit 42 is a circuit within the control device 1 that switches the target to which the communication IC 41 communicates. The selector circuit 42 receives data signals from the protection processing unit 304 (described later) and data signals from the application execution unit 201 (described later). The data signals are, for example, signals indicating the operating status of the application or actuator 6. The selector circuit 42 outputs one of the data signals to the communication IC 41. The operation settings of the selector circuit 42 are controlled by the microcontroller 10. The communication IC 41 transmits the data signals received from the selector circuit 42 to the other ECUs 2, 3, and 4.

[0020] The selector circuit 42 can selectively output data signals received by the communication IC 41 from other ECUs 2, 3, and 4 to the protection processing unit 304 or the application execution unit 201. The output destination of the received signals may also be switched by the protection processing unit 304.

[0021] When the first instruction signal is input to the communication IC 41 from the protection processing unit 304, the communication IC 41 only receives signals and does not transmit signals to the other ECUs 2, 3, and 4. Specifically, the communication IC 41 performs operations such as stopping the transmission circuit it has, or switching off the communication line switch for transmitting signals to the other ECUs 2, 3, and 4. The first instruction signal is a control signal that includes an instruction to restrict communication with the other ECUs 2, 3, and 4. For convenience, the state in which the control device 1's signal transmission function to the other ECUs 2, 3, and 4 is stopped either in hardware or software is also referred to as the communication system protection state.

[0022] In the communication system protection state, the receiving circuit of the communication IC 41 remains operational so that it can receive specific communication signals. When the communication IC 41 receives a first release signal from the protection processing unit 304, which includes an instruction to release the restriction on communication with other ECUs 2, 3, and 4, the communication IC 41 releases the communication system protection state. Specifically, the communication IC 41 performs processes such as activating its transmitting circuit or turning on the switch of the communication line for transmitting signals to other ECUs 2, 3, and 4.

[0023] When the selector circuit 42 receives a second instruction signal from the protection processing unit 304, it switches the target of communication between the communication IC 41 and the protection processing unit 304. The second instruction signal is a control signal that includes an instruction to switch the circuit state so that the communication IC 41 communicates with the protection processing unit 304. The circuit state of the selector circuit 42 before the second instruction signal is received from the protection processing unit 304 may be designed as appropriate. For example, the internal component of the control device 1 to which the communication IC 41 is connected during boot-up may be the protection processing unit 304 or the application execution unit 201.

[0024] When the selector circuit 42 receives a second release signal from the protection processing unit 304, the communication IC 41 switches the target of communication to the application execution unit 201. The second release signal is a control signal that includes an instruction to switch the circuit state to communicate with the application execution unit 201.

[0025] <Input / Output Interface> The input / output interface 50 includes a driver IC 51 and a selector circuit 52, as shown in Figure 2. The driver IC 51 is an IC that outputs a drive signal to the actuator 6 based on a drive request signal, which will be described later. The driver IC 51 is connected to the actuator 6 via a relay 53. The relay 53 may be any switching element such as a power MOSFET (Metal Oxide Semiconductor Field Effect Transistor) or an IGBT (Insulated Gate Bipolar Transistor). The driver IC 51 is configured to switch the conduction state (on / off) of the relay 53. The actuator 6 is a motor or a linear solenoid, etc. The actuator 6 corresponds to the drive unit.

[0026] The selector circuit 52 is a circuit within the control device 1 that switches the target to which the driver IC 51 communicates. The selector circuit 52 receives a drive request signal from the protection processing unit 304 and a drive request signal from the application execution unit 201. The selector circuit 52 outputs one of the drive request signals to the driver IC 51. The drive request signal is a signal that contains instructions for operating the actuator 6. For example, the drive request signal is a signal that contains instructions for starting or stopping the operation of the actuator 6. The driver IC 51, upon receiving the drive request signal, converts the drive request signal into a signal suitable for driving the actuator 6 and outputs the converted signal to the actuator 6 as a drive signal.

[0027] The operation settings of the selector circuit 52 are controlled by the microcontroller 10. The driver IC 51 transmits a drive signal to the actuator in accordance with the drive request signal received from the selector circuit 52. The driver IC 51 controls the on / off state of the relay 53 in the wiring that outputs the drive signal to the actuator 6. The relay 53 can be a high-voltage relay, a solenoid relay, a motor relay, etc.

[0028] When the driver IC 51 receives a third instruction signal from the protection processing unit 304, the driver IC 51 turns off the relay 53. The third instruction signal is a control signal that includes an instruction to disconnect the electrical connection with the actuator 6. The state in which the electrical connection with the actuator 6 is disconnected is called the drive system protection state. In the drive system protection state, when the driver IC 51 receives a third release signal from the protection processing unit 304, it controls the relay 53 to turn on. The state of the relay 53 before the third instruction signal is input from the protection processing unit 304 may be designed as appropriate.

[0029] When the selector circuit 52 receives a fourth instruction signal from the protection processing unit 304, it stops outputting a drive request signal from the application execution unit 201. The fourth instruction signal is a control signal that includes an instruction to switch the circuit state so that the driver IC 51 can communicate with the protection processing unit 304. At this time, a setting may be applied that outputs a drive request signal from the protection processing unit 304 to the driver IC 51. The circuit state of the selector circuit 52 before the fourth instruction signal is received from the protection processing unit 304 may be designed as appropriate. For example, the internal component of the control device 1 to which the driver IC 51 is connected during booting may be the protection processing unit 304 or the application execution unit 201.

[0030] Furthermore, when the selector circuit 52 receives a fourth release signal from the protection processing unit 304, it outputs a drive request signal from the application execution unit 201. The fourth release signal is a control signal that includes an instruction to switch the circuit state to communicate with the application execution unit 201.

[0031] <Microcontroller> The processor 11 is an arithmetic core for performing calculations. The processor 11 may be a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit). The processor 11 reads control applications, protection processing programs, boot programs, and secure boot programs stored in the normal storage 12 and secure storage 13, loads them into RAM 14, and executes them. The processor 11 can also construct multiple functional units, which will be described later, by executing each program.

[0032] The microcontroller 10 has a watchdog counter (not shown). The processor 11 keeps the watchdog counter of the communication IC 41 running even when the communication system is protected. This prevents the control device 1 from being forcibly restarted due to the watchdog counter stopping.

[0033] Normal storage 12 and secure storage 13 are implemented using non-volatile storage media. Normal storage 12 is a storage area accessible by various applications. Normal storage 12 may be an area where data is stored without encryption.

[0034] Secure storage 13 is an area separated from normal storage 12 and possessing a certain level of confidentiality and integrity. Secure storage 13 may be a storage area physically separated from normal storage 12. Secure storage 13 may be a storage area accessible only to a specific kernel / application. In other embodiments, secure storage 13 may be a storage area virtually separated from normal storage 12.

[0035] The normal storage 12 has a control application storage unit 121, which is a memory area that stores control applications for realizing desired functions. The control application is, for example, an application that communicates with other ECUs 2, 3, and 4 via the in-vehicle LAN to realize a desired function, or an application that outputs signals to control the actuator 6 corresponding to a desired function. The desired function is, for example, a function to control the motor as the driving source for the vehicle.

[0036] The control application storage unit 121 may be read as the control application memory area. The control application storage unit 121 is a rewritable area. The control application may be rewritten by an external tool that can be connected to the control device 1 or by update data transmitted via OTA (Over The Air).

[0037] The secure storage 13 includes a boot program storage unit 131, a secure boot program storage unit 132, an encryption key storage unit 133, a protection processing program storage unit 134, a verification history storage unit 135, and an termination information storage unit 136.

[0038] The boot program storage unit 131 is a memory area that stores the boot program that is executed when the microcontroller 10 starts up. The boot program storage unit 131 may be read as the boot program memory area. The boot program is a program for performing a predetermined startup process (boot process). The boot process includes processes such as hardware initialization (such as RAM 14 initialization) and reading the OS (Operating System) from a predetermined storage and starting the OS. The boot process includes the process of starting the secure boot program.

[0039] The secure boot program storage unit 132 is a memory area that stores the secure boot program. The secure boot program storage unit 132 may be read as the secure boot program memory area. The secure boot program is a program for performing secure boot on a control application. Secure boot is a process that verifies the legitimacy of software and executes the software after its legitimacy has been confirmed.

[0040] The encryption key storage unit 133 is a memory area that stores encryption data such as encryption keys. The encryption key storage unit 133 may be read as the encryption key storage area. The encryption key is used for initiating and deactivating protection processing, which will be described later. The encryption key may be a unique device number assigned to the control device 1.

[0041] The protection processing program storage unit 134 is a memory area that stores the protection processing program, which is a program for performing protection processing. The protection processing program storage unit 134 may be read as the protection processing program storage area. Protection processing includes drive system protection processing, communication system protection processing, and information storage processing. The protection processing program includes the communication system protection processing program, the drive system protection processing program, and the information storage processing program.

[0042] The drive system protection processing program is a program for performing drive system protection processing, which is the process of disconnecting the electrical connection between the driver IC 51 and the actuator 6. The drive system protection processing can be understood as the process of leading the control device 1 into a drive system protection state. The driver IC 51 corresponds to the drive control unit. The drive system protection processing can be reinterpreted as hardware protection processing.

[0043] The communication protection processing program is a program for performing communication protection processing, which is the process of restricting communication between the communication IC 41 and the other ECUs 2, 3, and 4. Communication protection processing can be understood as the process of leading the control device 1 into a communication protection state. The communication IC 41 corresponds to the communication unit. Communication protection processing can be rephrased as software protection processing.

[0044] The information storage processing program is a program for performing information storage processing, which involves saving verification history information, which is information indicating the state of the control device 1 at the time the verification result by the secure boot unit 302 (described later) became abnormal, to the verification history storage unit 135. The information storage processing may be rephrased as attack information storage processing or attack information protection processing. Verification history information is data related to the control application stored in the normal storage 12 or secure storage 13. Specific examples of verification history information will be described later.

[0045] The verification history storage unit 135 is a storage area for storing verification history information. The verification history storage unit 135 may be read as the verification history information storage area. Until verification history information is stored, the verification history storage unit 135 is empty.

[0046] The termination information storage unit 136 is a storage area for storing termination information. The termination information storage unit 136 may be read as the termination information storage area. Termination information is information indicating that the verification result by the secure boot unit 302 has become abnormal.

[0047] The boot program storage unit 131, the secure boot program storage unit 132, the encryption key storage unit 133, and the protection processing program storage unit 134 are areas that are prohibited from being rewritten, either by software or hardware. In other words, boot-related programs and encryption keys may be stored in a manner that prevents rewriting. Verification history information or termination information may also be stored in a manner that prevents rewriting.

[0048] <Functional Section> The following explanation will describe the timing of each program's operation, the functional units built into the control device 1 by each program, and the roles of each functional unit, with reference to Figures 3 and 4.

[0049] When the power is turned on from the power-off state (ST1), the control device 1 executes a process to start the boot program. The processor 11 reads the boot program from the boot program storage unit 131 and loads it into the RAM 14, thereby constructing the boot unit 301 as a functional unit in the control device 1. The state in which the boot program is running (the state in which the boot unit 301 is running) is called the boot state (ST2). When the power is turned on, the control device 1 transitions from the power-off state (ST1) to the boot state (ST2), as shown in Figure 4.

[0050] The constructed boot unit 301 performs the boot process. Before executing the secure boot program (before performing secure boot), the boot unit 301 determines whether or not termination information is stored in the termination information storage unit 136. If the boot unit 301 determines that termination information is not stored, it executes the secure boot program as one of the boot processes. On the other hand, if the boot unit 301 determines that termination information is stored, it starts the protection processing unit 304 to begin the protection process. Details of the protection processing unit 304 will be described later.

[0051] The processor 11 reads the secure boot program from the secure boot program storage unit 132 and loads it into the RAM 14, thereby constructing the secure boot unit 302 as a functional unit in the control device 1. The constructed secure boot unit 302 verifies the integrity of the control application.

[0052] An example of how the Secure Boot Unit 302 verifies the control application is described below. The Secure Boot Unit 302 generates a hash value for the control application's data. The control application's data may be the program itself, i.e., the code. The Secure Boot Unit 302 also obtains a hash value for the valid control application's data by decrypting the digital signature associated with the control application using an encryption key. If the two hash values ​​match, the Secure Boot Unit 302 considers the control application to be valid and complete, and determines that the control application is normal. On the other hand, if the two hash values ​​do not match, the Secure Boot Unit 302 determines that the control application is abnormal. The Secure Boot Unit 302 may also verify the integrity of the control application by other methods.

[0053] Thus, when the verification result by the Secure Boot Unit 302 is normal, it means that the verification determined that the control application program is normal, and therefore, that Secure Boot was successful. On the other hand, when the verification result by the Secure Boot Unit 302 is abnormal, it means that the verification of the control application determined that the control application program is abnormal, in other words, that Secure Boot failed. When the control application is abnormal, it means that the integrity of the software could not be confirmed, or that there is a possibility that it has been tampered with. In the following, the verification result of the control application software by the Secure Boot Unit 302 will also be simply referred to as the verification result. Furthermore, software verification in the following means verifying the integrity of the control application by the Secure Boot Unit 302.

[0054] The secure boot unit 302 executes the control application if the verification result is normal. That is, the processor 11 reads the secure boot program from the control application storage unit 121 and loads it into the RAM 14. As a result, the application execution unit 201 is constructed as a functional unit in the control device 1. The constructed application execution unit 201 executes the control application. Upon successful startup of the control application, the control device 1 transitions from the boot state (ST2) to the normal operation state (ST3) in which the control application is executed. Subsequently, when the power to the control device 1 is turned off, such as when the ignition of the control device 1 is turned off, the control device 1 transitions from the normal operation state (ST3) to the power-off state (ST1).

[0055] On the other hand, if the verification result of the secure boot unit 302 is abnormal, the processor 11 reads the protection processing program from the protection processing program storage unit 134 and loads it into the RAM 14, thereby constructing the protection processing unit 304 as a functional unit in the control device 1. The construction of the protection processing unit 304 also means that the drive system protection processing unit 342, the communication system protection processing unit 341, and the information storage processing unit 343 are constructed.

[0056] The drive system protection processing unit 342 includes a drive system protection activation unit and a drive system main unit. The drive system main unit performs drive system protection processing and is configured to be deactivated by an encryption key if the verification result is not found to be abnormal. The drive system protection activation unit is configured to obtain an encryption key from the encryption key storage unit 133 if the verification result is abnormal, and to activate the drive system main unit with the obtained encryption key.

[0057] The activated drive system unit sends a third instruction signal to the driver IC 51 and a fourth instruction signal to the selector circuit 52 as part of the drive system protection process. With this drive system protection process in place, the control device 1 transitions from the boot state (ST2) to the drive system protection state (ST42).

[0058] The communication system protection processing unit 341 includes a communication system protection activation unit and a communication system main unit. The communication system main unit performs communication system protection processing and is configured to be deactivated by an encryption key if the verification result is not found to be abnormal. The communication system protection activation unit is configured to obtain an encryption key from the encryption key storage unit 133 if the verification result is abnormal, and to activate the communication system main unit with the obtained encryption key.

[0059] The activated communication system unit sends a first instruction signal to the communication IC 41 and a second instruction signal to the selector circuit 42 as part of the communication system protection process. With this communication system protection process in place, the control device 1 transitions from the boot state (ST2) to the communication system protection state (ST41).

[0060] The information storage processing unit 343 includes a storage function activation unit and an information storage main unit. The information storage main unit performs information storage processing and is configured to be deactivated by an encryption key if the verification result is not found to be abnormal. The storage function activation unit is configured to obtain an encryption key from the encryption key storage unit 133 if the verification result is abnormal, and to activate the information storage main unit with the obtained encryption key.

[0061] The activated information storage unit, as part of its information storage process, saves verification history information when the verification result is abnormal to the verification history storage unit 135. Specifically, the information storage unit obtains an encryption key from the encryption key storage unit 133, encrypts the verification history information using the encryption key, and saves it to the verification history storage unit 135. The information storage unit may also save a log of the state of the control device 1 within a predetermined time before and after the time when secure boot failed as verification history information.

[0062] The verification history information may be information related to the results of verification by the secure boot unit 302. The verification history information may also be information indicating the nature of the attack on the control device 1. Next, specific examples of verification history information are shown.

[0063] The verification history information may include a timestamp from the last time software verification was successful or from the time a verification result indicating that the control application was abnormal was obtained. These timestamps allow for the determination of the time of the attack. The verification history information may include the position coordinates of the moving object when the latest verification result was abnormal. The position coordinates of the moving object may be GPS (Global Positioning System) coordinates. This allows for the identification of the location of the attack. The verification history information may also include the number of times the verification result was abnormal.

[0064] If the code of a control application is divided into multiple sections, the verification of the control application may be performed section by section. The verification history information may include information about the section of the control application in which an anomaly was detected (i.e., which was modified). A section is a logical division of the program's memory space or the program itself. The section information may be the number, code, or memory address of the modified section of the control application. This makes it possible to identify what was modified under attack.

[0065] The verification history information may include information about the data stored in the control application storage unit 121 when the software verification was last successful and when a verification result indicating an abnormality was obtained. This makes it possible to identify the content that was modified by the attack. The verification history information may also include diagnostic trouble codes detected when a verification result indicating an abnormality was obtained. The diagnostic trouble codes make it possible to identify the system or component where the abnormality occurred.

[0066] The state in which the information saving process has been performed is referred to as the verification history information protection state (ST43). When the information saving process is performed, the control device 1 transitions from the boot state (ST2) to the verification history information protection state (ST43). Note that ST41, ST42, and ST43 are not mutually exclusive states, but can be adopted in parallel (in other words, they can coexist). In the following, the protection state (ST4) refers to at least one of the drive system protection state (ST42), the communication system protection state (ST41), and the verification history information protection state (ST43).

[0067] When the protection processing unit 304 has performed protection processing including drive system protection processing, communication system protection processing, and information storage processing, it stores termination information in the termination information storage unit 136.

[0068] When the protection processing unit 304 performs protection processing, the control device 1 transitions from the boot state (ST2) to the protected state (ST4). If the power to the control device 1 is turned off while in the protected state (ST4), it transitions from the protected state (ST4) to the power-off state (ST1).

[0069] In the protected state (ST4), if the protection processing unit 304 successfully authenticates the diagnostic tool, it releases the protected state (ST4) of the control unit 1 and transitions it to the normal operating state (ST3). The diagnostic tool is a specialized device used for diagnosing and detecting faults in automobiles. An example of a diagnostic tool is a diagnostic tester.

[0070] Specifically, the protection processing unit 304, upon receiving a specific communication signal from the diagnostic tool via the communication IC 41, authenticates the diagnostic tool using an encryption key. The diagnostic tool is a device used in dealerships and factories. The diagnostic tool is electrically connected to the control device 1 by mechanically connecting it to a connector provided in the vehicle. The diagnostic tool has a function to diagnose abnormalities in each ECU of the vehicle, for example. The diagnostic tool is considered an external device.

[0071] A specific communication signal is a signal containing communication data, including requests and responses to SID27. SID stands for Service Identifier. SID27 is one of the identification numbers for diagnostic services in the UDS (Unified Diagnostic Services) protocol. SID27 is an identification number that indicates a security access service.

[0072] Authentication may be performed using a shared key, a public key, a challenge-response authentication using a session key, or other methods. If authentication fails, the protection processing unit 304 maintains the protected state (ST4). If authentication is successful, the protection processing unit 304 releases the protected state. The protection processing unit 304 then initiates the execution of the control application.

[0073] If authentication is successful, the drive system protection processing unit 342 sends a third release signal to the driver IC 51 and a fourth release signal to the selector circuit 52. Also, if authentication is successful, the communication system protection processing unit 341 sends a first release signal to the communication IC 41 and a second release signal to the selector circuit 42. The information storage processing unit 343 decrypts the encrypted verification history information and stores it so that it can be accessed by the diagnostic tool.

[0074] If authentication fails, the drive system protection processing unit 342 may re-transmit the third instruction signal to the driver IC 51 and the fourth instruction signal to the selector circuit 52 in order to maintain the drive system protection state. Also, if authentication fails, the communication system protection processing unit 341 may re-transmit the first instruction signal to the communication IC 41 and the second instruction signal to the selector circuit 42. The information storage processing unit 343 does not decrypt the encrypted verification history information.

[0075] The drive system protection activation unit, the communication system protection activation unit, and the storage function activation unit correspond to the protection function activation unit. The drive system main unit, the communication system main unit, and the information storage main unit correspond to the main unit. The input / output terminals used by the protection processing unit 304 for communication with the selector circuit 42 may be physically different from the input / output terminals used by the application execution unit 201 for communication with the selector circuit 42. Similarly, the input / output terminals used by the protection processing unit 304 for communication with the selector circuit 52 may be different from the input / output terminals used by the application execution unit 201 for communication with the selector circuit 52. In other embodiments, the selector circuits 42 and 52 may be implemented inside the microcontroller 10.

[0076] <Processing Flow> Next, an example of a series of processes executed in the control device 1 when it is powered on or restarted by a reset will be explained with reference to the flowcharts in Figures 5, 6, 7, and 8. In the flowchart explanation, "S" means step. For example, the notation S11 may be replaced with step 11 or step S11.

[0077] In S11, the processor 11 constructs the boot unit 301 and executes the boot process. In S12, the processor 11 as the boot unit 301 determines whether or not termination information is stored in the termination information storage unit 136. If the answer in S12 is Yes, proceed to S15; otherwise, proceed to S13. In the processing flow, the processor 11 as a functional unit is also referred to simply as a functional unit. For example, the description "boot unit 301" may be replaced with "processor 11 as boot unit 301".

[0078] In S13, the boot unit 301 constructs the secure boot unit 302. The secure boot unit 302 performs secure boot verification. The secure boot unit 302 verifies whether the control application is normal or abnormal. In S14, if the verification result is normal, proceed to S29 if Yes, and to S15 if No.

[0079] In S19, the secure boot unit 302 constructs the application execution unit 201. The application execution unit 201 executes the control application and terminates the processing flow.

[0080] In S15, the secure boot unit 302 activates the protection processing unit 304, thereby constructing the drive system protection processing unit 342. The drive system protection processing unit 342 performs drive system protection processing (Figure 6).

[0081] In S31, the drive system protection processing unit 342 activates the drive system protection activation unit. The drive system protection activation unit obtains an encryption key from the encryption key storage unit 133. In S32, the drive system protection activation unit authenticates whether the obtained encryption key is correct. Specifically, the drive system protection activation unit determines whether the obtained encryption key matches an encryption key that the drive system protection activation unit has stored in advance. In S32, if the result is Yes, the process proceeds to S33; otherwise, the drive system protection process is terminated.

[0082] In S33, the drive system protection activation unit activates the drive system main unit using the acquired encryption key. In S34, the drive system main unit sends a third instruction signal to the driver IC 51 and a fourth instruction signal to the selector circuit 52. When the driver IC 51 receives the third instruction signal, it turns off the relay 53. When the selector circuit 52 receives the fourth instruction signal, it stops outputting a drive request signal from the application execution unit 201. After the processing in S34 is completed, the drive system protection process ends and the process proceeds to the communication system protection process in S16 of Figure 5.

[0083] In S16, the communication protection processing unit 341 performs communication protection processing (Figure 7). In S41, the communication protection processing unit 341 activates the communication protection activation unit. The communication protection activation unit obtains an encryption key from the encryption key storage unit 133. In S42, the communication protection activation unit authenticates whether the obtained encryption key is correct. Specifically, the communication protection activation unit determines whether the obtained encryption key matches an encryption key that the communication protection activation unit has stored in advance. In S42, if the result is Yes, the process proceeds to S43; otherwise, the communication protection processing is terminated.

[0084] In S43, the communication system protection activation unit activates the communication system main unit with the acquired encryption key. In S44, the communication system main unit sends a first instruction signal to the communication IC 41 and a second instruction signal to the selector circuit 42. Upon receiving the first instruction signal, the communication IC 41 stops its transmission circuit. Upon receiving the second instruction signal, the selector circuit 42 stops outputting data signals from the application execution unit 201. In response to the second instruction signal, the selector circuit 42 configures the circuit so that only the microcontroller 10, including the protection processing unit 34, can communicate data with the communication IC 41. After the processing in S44 is completed, the communication system protection process ends and the process proceeds to the information saving process in S17 of Figure 5.

[0085] In S17, the information storage processing unit 343 performs information storage processing (Figure 8). In S51, the information storage processing unit 343 activates the storage function activation unit. The storage function activation unit obtains an encryption key from the encryption key storage unit 133. In S52, the storage function activation unit authenticates whether the obtained encryption key is correct. Specifically, the storage function activation unit determines whether the obtained encryption key matches an encryption key that the storage function activation unit has stored in advance. In S52, if the result is Yes, the process proceeds to S53; otherwise, the information storage process ends.

[0086] In S53, the storage function activation unit activates the information storage main unit using the acquired encryption key. In S54, the information storage main unit, as part of the information storage process, encrypts the verification history information at the time the verification result became abnormal using the encryption key and stores it in the verification history storage unit 135. After the processing in S54 is completed, the information storage process is terminated and the process proceeds to S18 in Figure 5. In S18, the protection processing unit 304 stores termination information in the termination information storage unit 136 and terminates the processing flow.

[0087] Next, using Figure 9, an example of a series of processes executed by the control device 1 when the control device 1 is in a protected state will be explained.

[0088] In S21, the protection processing unit 304 determines whether or not a specific communication signal has been received (Figure 9). If the result in S21 is Yes, the process proceeds to S25; otherwise, the process proceeds to S22.

[0089] In S22, the drive system main unit maintains the drive system protection state. Specifically, the drive system main unit transmits a third instruction signal to the driver IC 51 and a fourth instruction signal to the selector circuit 52. Upon receiving the third instruction signal, the driver IC 51 maintains the state in which the relay 53 is turned off. Upon receiving the fourth instruction signal from the protection processing unit 304, the selector circuit 52 maintains a state in which it does not output a drive request signal from the application execution unit 201. At this time, the selector circuit 52 may also operate to transmit the drive request signal from the protection processing unit 304 to the driver IC 51.

[0090] In S23, the communication system main unit maintains the communication system protection state. For example, the communication system main unit may retransmit the first instruction signal to the communication IC 41 and the second instruction signal to the selector circuit 42. Upon receiving the first instruction signal, the communication IC 41 maintains a state in which its transmitting circuit is stopped. Upon receiving the first instruction signal, the communication IC 41 may update (or extend) the period in which it maintains the stopped state of its transmitting circuit. Upon receiving the second instruction signal, the selector circuit 42 continues to output a data signal from the protection processing unit 304 and does not output a data signal from the application execution unit 201. In S24, the information storage main unit maintains the verification history information stored in the verification history storage unit 135 in an encrypted state.

[0091] The above steps S22 to S24 correspond to the operation of the microcontroller 10 when no specific communication signal is received (S21 No). On the other hand, if a specific communication signal is received in S21 (S21 Yes), the protection processing unit 304 authenticates the diagnostic tool in S25 using the encryption key that is the source of the specific communication signal and determines whether authentication is successful or not. In S25, if authentication is successful (i.e., Yes), the process proceeds to S26. On the other hand, if authentication fails (i.e., No), steps S22 to S24 are executed.

[0092] In S26, the drive system protection processing unit 342 releases the drive system protection state. The drive system main unit sends a third release signal to the driver IC 51 and a fourth release signal to the selector circuit 52. When the driver IC 51 receives the third release signal, it turns on the relay 53. When the selector circuit 52 receives the fourth release signal, it outputs a drive request signal from the application execution unit 201 and stops outputting a drive request signal from the protection processing unit 304.

[0093] In S27, the communication system protection processing unit 341 releases the communication system protection state. The communication system main unit sends a first release signal to the communication IC 41 and a second release signal to the selector circuit 42. Upon receiving the first release signal, the communication IC 41 activates its transmission circuit. Upon receiving the second release signal, the selector circuit 42 outputs a data signal from the application execution unit 201 and stops outputting a data signal from the protection processing unit 304.

[0094] In S28, the information storage processing unit 343 releases the verification history information protection state. The information storage processing unit 343 and the verification history storage unit 135 decrypt the encrypted verification history information and store it so that it can be accessed by the diagnostic tool.

[0095] In S29, the protection processing unit 304 constructs the application execution unit 201. The application execution unit 201 executes the control application and terminates the processing flow.

[0096] In the above flow, the processes for confirming the completion information and saving the completion information may be omitted. Specifically, processes S12 and S18 may be omitted.

[0097] The order in which the drive system protection process, communication system protection process, and information storage process are performed can be determined arbitrarily. For example, the order of S15, S16, and S17 can be changed as appropriate, and each process can be performed in parallel.

[0098] The drive system protection process, communication system protection process, and information storage process do not all need to be performed. It is sufficient for at least one of the drive system protection process, communication system protection process, and information storage process to be executed. For example, processes S16, S17, S22, and S23 may be omitted.

[0099] <Summary of this embodiment> In the configuration of this embodiment, if the verification result is abnormal, drive system protection processing, communication system protection processing, and information storage processing are performed.

[0100] The drive system protection process disconnects the electrical connection between the application execution unit 201 and the actuator 6 that performs the desired function, thereby suppressing malfunctions of the actuator 6 due to external attacks.

[0101] The communication protection process restricts communication by the communication IC 41 to other ECUs 2, 3, and 4. This reduces the risk of the control device 1 transmitting inappropriate data to other ECUs 2, 3, and 4 due to an external attack. Furthermore, by restricting communication with other ECUs 2, 3, and 4, the risk of application malfunctions in the control device 1 causing malfunctions in other ECUs 2, 3, and 4 can be suppressed.

[0102] Through the information storage process, the verification history information at the point when the verification result became abnormal is stored in the verification history storage unit 135. This makes it possible to analyze the verification history information. For example, it becomes possible to analyze the details of an external attack.

[0103] In the configuration of this disclosure, the protection processing unit 304, upon receiving a specific communication signal from the diagnostic tool via the communication IC 41, authenticates the diagnostic tool using an encryption key. If authentication is successful, the protection processing unit 304 releases the protection processing state; if authentication fails, it continues the protection processing state. In the configuration of this disclosure, anyone who does not know the encryption key cannot release the protection state. Therefore, security is improved. On the other hand, anyone who possesses a diagnostic tool capable of transmitting the specific communication signal, such as a legitimate dealer, can release the protection state.

[0104] In the configuration of this disclosure, the protection processing unit 304 encrypts the verification history information and stores it in the verification history storage unit 135. When the communication IC 41 receives a specific communication signal, the protection processing unit 304 authenticates the diagnostic tool using the encryption key. If authentication is successful, the protection processing unit 304 decrypts the verification history information and stores it so that the diagnostic tool can access it. On the other hand, if authentication fails, the verification history information is not decrypted. This configuration prevents anyone without the encryption key from accessing the verification history information. Conversely, anyone with the encryption key, such as a legitimate dealer, can analyze the verification history information. This can improve the security of the system while ensuring the analyzability of the verification history information.

[0105] In the configuration of this disclosure, the drive system main unit, the communication system main unit, and the information storage main unit are disabled (in other words, encrypted) if the verification result is not abnormal. If the verification result is abnormal, the drive system protection activation unit, the communication system protection activation unit, and the storage function activation unit activate each main unit using the encryption key. In this way, each main unit is not activated (in other words, decrypted) unless the verification result is abnormal. Therefore, even if a third party gains unauthorized access to the control device 1, the risk of that third party obtaining knowledge of the contents of the main unit (e.g., code) is reduced. Consequently, the security of the system is improved.

[0106] If the verification result is abnormal, there is a high probability that an attack is underway. Therefore, if the verification result is abnormal even once, it is desirable that protection processing be performed before performing secure boot verification again. In the configuration of this disclosure, the boot unit 301 determines whether or not termination information is stored in the termination information storage unit 136 before performing secure boot verification. If the boot unit 301 determines that termination information is stored, it starts the protection processing unit 304 to start protection processing. With this configuration, if the verification result is abnormal even once, it is possible to start protection processing immediately before performing the next secure boot verification. In other words, if there is a high probability that an attack is underway, protection processing can be started immediately, improving security.

[0107] <First Application Example> In the following, an example in which the control device 1 is used as a shift-by-wire ECU will be explained using Figure 10. In Figure 10, the signal lines for which the protection processing unit 304 transmits the first instruction signal to the communication IC 41, the signal lines for which the protection processing unit 304 transmits the second instruction signal to the selector circuit 42, the signal lines for which the protection processing unit 304 transmits the third instruction signal to the driver ICs 511a, 512a, and 513a, and the signal lines for which the protection processing unit 304 transmits the fourth instruction signal to the selector circuits 521a, 522a, and 523a are omitted.

[0108] In the first application example, the other ECUs 2, 3, and 4 connected to the control device 1 are the automatic driving ECU 2a, HV-ECU 3a, and meter ECU 4a. The control application in the first application example outputs a drive signal to the motor 63a to switch the shift position in response to the driver's instruction to change the shift position using the shift lever. In other words, the motor 63a is a motor that switches the gear position.

[0109] In the first application example, the control device 1 is connected to a motor 63a, a shift indicator 7a, and a P-lock actuator 62a as controlled objects. The shift indicator 7a is a device that displays the shift position. The P-lock actuator 62a is an actuator used in the parking lock mechanism. The P-lock actuator 62a is used to fix the shift lever or shift position in the parking position or to release the fixed state. The P-lock actuator 62a and the motor 63a correspond to the actuator 6 described above.

[0110] The input / output interface 50 of the first application example includes driver ICs 511a, 512a, 513a and selector circuits 521a, 522a, 523a, as shown in Figure 10.

[0111] The driver IC 511a is connected to the shift indicator 7a via relay 531a. The shift indicator 7a switches its display based on the signal input from the driver IC 511a. The driver IC 511a controls the on / off state of relay 531a.

[0112] The driver IC 512a is connected to the P-lock actuator 62a via relay 532a. The P-lock actuator 62a mechanically locks or unlocks the shift lever in response to a drive signal input from the driver IC 512a.

[0113] The driver IC 513a is connected to the motor 63a via relay 533a. The motor 63a switches gear positions in response to the drive signal input from the driver IC 513a.

[0114] When the driver IC 512a receives a third instruction signal from the protection processing unit 304, it turns off the relay 532a. In the drive system protection state, when the driver IC 512a receives a third release signal from the protection processing unit 304, it controls the relay 532a to turn on. The state of the relay 532a before the third instruction signal is input from the protection processing unit 304 may be designed as appropriate.

[0115] When the driver IC 513a receives a third instruction signal from the protection processing unit 304, it turns off the relay 533a. In the drive system protection state, when the driver IC 513a receives a third release signal from the protection processing unit 304, it controls the relay 533a to turn on. The state of the relay 533a before the third instruction signal is input from the protection processing unit 304 may be designed as appropriate.

[0116] The selector circuit 521a is a circuit within the control device 1 that switches the target to which the driver IC 511a communicates. The selector circuit 521a receives an indicator drive request signal from the protection processing unit 304 and an indicator drive request signal from the application execution unit 201. The selector circuit 521a outputs one of these signals to the driver IC 511a. The indicator drive request signal is a signal that includes an instruction to operate the shift indicator 7a. For example, the indicator drive request signal is a signal that includes an instruction to light up the indicator that shows the current shift position. Upon receiving the indicator drive request signal, the driver IC 511a converts the indicator drive request signal into a signal suitable for driving the shift indicator 7a and outputs it to the shift indicator 7a.

[0117] The operation settings of the selector circuit 521a are controlled by the microcontroller 10. When the selector circuit 521a receives a fourth instruction signal from the protection processing unit 304, it stops outputting a drive signal from the application execution unit 201. At this time, a setting that outputs an indicator drive request signal from the protection processing unit 304 may be applied. In the drive system protection state, when the selector circuit 521a receives a fourth release signal from the protection processing unit 304, it outputs an indicator drive request signal from the application execution unit 201. The circuit state of the selector circuit 521a before the fourth instruction signal is input from the protection processing unit 304 may be designed as appropriate. For example, the internal component of the control device 1 to which the driver IC 511a is connected during boot may be the protection processing unit 304 or the application execution unit 201.

[0118] The selector circuits 522a and 523a are circuits within the control device 1 that switch the target to which the driver ICs 512a and 513a communicate. The selector circuits 522a and 523a receive a drive request signal from the protection processing unit 304 and a drive request signal from the application execution unit 201. The selector circuits 522a and 523a output either of the drive request signals to the driver ICs 512a and 513a.

[0119] The operation settings of selector circuits 522a and 523a are controlled by the microcontroller 10. When selector circuits 522a and 523a receive a fourth instruction signal from the protection processing unit 304, they stop outputting a drive request signal from the application execution unit 201. At this time, a setting that outputs a drive request signal from the protection processing unit 304 may also be applied. In the drive system protection state, when selector circuits 522a and 523a receive a fourth release signal from the protection processing unit 304, they start outputting a drive request signal from the application execution unit 201. The circuit state of selector circuits 522a and 523a before the fourth instruction signal is input from the protection processing unit 304 may be designed as appropriate. For example, the internal component of the control device 1 to which the driver ICs 512a and 513a are connected during boot may be the protection processing unit 304 or the application execution unit 201.

[0120] The drive system protection process in the first application example includes a process of performing a fixed control to fix the shift position to the parking position using the P lock actuator 62a, a process of turning off the relay 533a in the wiring that outputs a drive signal to the motor 63a, and a process of displaying the P position on the shift indicator 7a. Furthermore, the drive system protection process in the first application example may also include a process of turning off the relay 532a after locking the shift position with the P lock actuator 62a.

[0121] Specifically, as part of the drive system protection processing, the drive system protection processing unit 342 transmits a fourth instruction signal to selector circuits 521a, 522a, and 523a. In order to perform fixed control, the drive system protection processing unit 342 outputs a drive request signal to selector circuit 522a that includes an instruction to perform fixed control. The drive system protection processing unit 342 outputs an indicator drive request signal to selector circuit 42 so that the shift indicator 7a displays the P position. The drive system protection processing unit 342 transmits a third instruction signal to driver ICs 512a and 513a to turn off relays 532a and 533a.

[0122] <Processing Flow> Next, an example of a series of processes performed in the control device 1 when it is powered on or restarted by a reset in the first application example will be explained with reference to the flowcharts in Figures 11 and 12.

[0123] The control device 1 performs the processing shown in Figure 11. The processing from S101 to S104 is the same as the processing from S11 to S14. In S105, the secure boot unit 302 activates the protection processing unit 304, thereby constructing the drive system protection processing unit 342. The drive system protection processing unit 342 performs the drive system protection processing (Figure 12). The processing from S131 to S133 is the same as the processing from S31 to S33.

[0124] In S134, the drive system main unit performs fixed control. In S134, the drive system main unit transmits a fourth instruction signal to the selector circuit 522a. Upon receiving the fourth instruction signal, the selector circuit 522a outputs a drive request signal from the protection processing unit 304 and does not output a drive request signal from the application execution unit 201. The drive system main unit transmits a drive request signal to the selector circuit 522a that includes an instruction to perform fixed control. The selector circuit 522a outputs the drive request signal from the protection processing unit 304 to the driver IC 512a. The driver IC 512a outputs a drive signal corresponding to the drive request signal to the P-lock actuator 62a. Upon receiving the drive signal, the P-lock actuator 62a performs parking lock.

[0125] In S135, the drive system main unit controls the shift indicator 7a to display "P". Specifically, the drive system main unit transmits a fourth instruction signal to the selector circuit 521a. Upon receiving the fourth instruction signal, the selector circuit 521a outputs an indicator drive request signal from the protection processing unit 304 and does not output an indicator drive request signal from the application execution unit 201. The drive system main unit transmits an indicator drive request signal to the selector circuit 521a that includes an instruction to display the P position. The selector circuit 521a outputs the indicator drive request signal from the protection processing unit 304 to the driver IC 511a. The driver IC 511a outputs a signal corresponding to the indicator drive request signal to the shift indicator 7a. Upon receiving the signal, the shift indicator 7a displays the P position.

[0126] In S136, the drive system main unit performs the process of turning off relays 532a and 533a. Specifically, the drive system main unit sends a fourth instruction signal to selector circuits 522a and 523a. When selector circuits 522a and 523a receive the fourth instruction signal, they stop outputting drive request signals from the application execution unit 201. The drive system main unit sends a third instruction signal to driver ICs 512a and 513a. When driver IC 512a receives the third instruction signal, it turns off relay 532a. When driver IC 513a receives the third instruction signal, it turns off relay 533a.

[0127] Next, an example of a series of processes executed by the control device 1 when the control device 1 of the first application example is in a protected state will be explained using Figures 13 and 14. The process in S121 is the same as the process in S21.

[0128] In S122, the drive system main unit maintains the drive system protection state. Specifically, the drive system main unit transmits a third instruction signal to the driver ICs 512a and 513a, and a fourth instruction signal to the selector circuits 521a, 522a, and 523a.

[0129] When driver IC 512a receives the third instruction signal, it maintains the state in which relay 532a is OFF. When driver IC 513a receives the third instruction signal, it maintains the state in which relay 533a is OFF. When selector circuit 521a receives the fourth instruction signal, it outputs an indicator drive request signal from the protection processing unit 304 and does not output an indicator drive request signal from the application execution unit 201. When selector circuits 522a and 523a receive the fourth instruction signal, they maintain a state in which they do not output a drive request signal from the application execution unit 201. At this time, selector circuits 522a and 523a may also operate to transmit the drive request signal from the protection processing unit 304 to driver ICs 512a and 513a.

[0130] The processes in S123 to S125 are the same as those in S23 to S25. In S126, the drive system main unit performs the process of releasing the drive system protection state (Figure 14).

[0131] In S161, the drive system main unit performs a process to release the fixed control. The drive system main unit sends a drive request signal including an instruction to release the fixed control to the selector circuit 522a. The selector circuit 522a outputs the drive request signal from the protection processing unit 304 to the driver IC 512a. The driver IC 512a outputs a drive signal corresponding to the drive request signal to the P lock actuator 62a. When the P lock actuator 62a receives the drive signal, it unlocks the parking lock.

[0132] In S162, the drive system main unit transmits a third release signal to driver ICs 512a and 513a. When driver IC 512a receives the third release signal, it turns on relay 532a. When driver IC 513a receives the third release signal, it turns on relay 533a.

[0133] In S163, the drive system main unit transmits a fourth release signal to selector circuits 521a, 522a, and 523a. Upon receiving the fourth release signal, selector circuit 521a outputs an indicator drive request signal from the application execution unit 201 and does not output an indicator drive request signal from the protection processing unit 304. Upon receiving the fourth instruction signal, selector circuits 522a and 523a output a drive request signal from the application execution unit 201.

[0134] Once the process in S163 is completed, proceed to S127 in Figure 13. The processes in S127 to S129 are the same as those in S127 to S29.

[0135] <Summary of the first application example> The drivetrain protection process in the first application example includes a process for performing fixed control. This reduces the risk of the shift position being changed unintentionally, as the shift position will be fixed to parking even if subjected to an external attack.

[0136] The drive system protection process includes turning off the relay 532a in the wiring that outputs the drive signal to the P-lock actuator 62a. This prevents external attacks from being transmitted to the P-lock actuator 62a. Therefore, the risk of the parking lock being unlocked unintentionally can be reduced.

[0137] The drive system protection process includes a process to disconnect the relay 53a in the wiring that outputs the drive signal to the motor 63a. This prevents external attacks from being transmitted to the motor 63a. Therefore, the risk of unintentional gear position changes can be reduced. Note that the control application is not limited to software that controls the shift position in response to driver operations on the vehicle. The control application may also be an application that controls the shift position in response to a shift position change instruction received wirelessly from an external device that remotely controls the vehicle. Furthermore, the control application may be an autonomous driving system.

[0138] <Second Application Example> In the following, an example in which the control device 1 is used as a transmission ECU will be explained using Figure 15. In Figure 15, the signal lines for which the protection processing unit 304 transmits the first instruction signal to the communication IC 41, the signal lines for which the protection processing unit 304 transmits the second instruction signal to the selector circuit 42, the signal lines for which the protection processing unit 304 transmits the third instruction signal to the driver IC 51, and the signal lines for which the protection processing unit 304 transmits the fourth instruction signal to the selector circuit 52 are omitted.

[0139] In the second application example, the other ECUs 2, 3, and 4 connected to the control device 1 are the automatic driving ECU 2b, the engine ECU 3b, and the meter ECU 4b. The actuator 6 in the second application example is a solenoid 61b that switches the gear position of the vehicle's transmission. The solenoid 61b is, for example, a linear solenoid. The control application in the second application example is an application that outputs a drive signal to the solenoid 61b to switch the gear position. The drive system protection process in the second application example includes the process of turning off the relay 53 in the wiring that outputs the drive signal to the solenoid 61b. The relay 53 in the second application example is a solenoid relay.

[0140] The series of processes performed in the control device 1 when it is powered on or restarted by a reset in the second application example may be the same as the flow shown in Figure 5. The drive system protection process in the second application example includes the process of disconnecting the relay 53 of the wiring that outputs the drive signal to the solenoid 61b. This prevents external attacks from being transmitted to the solenoid 61b. Therefore, the risk of the transmission gear being shifted unintentionally can be reduced.

[0141] <Third Application Example> In the third application example, the vehicle on which the control device 1 is installed is a BEV. Below, an example in which the control device 1 is used as a BEV-ECU will be explained using Figure 16. The BEV-ECU is an ECU that comprehensively controls the battery 63c, motor 62c, inverter 61c, and charging system. In Figure 16, the signal lines for which the protection processing unit 304 transmits the first instruction signal to the communication IC 41, the signal lines for which the protection processing unit 304 transmits the second instruction signal to the selector circuit 42, the signal lines for which the protection processing unit 304 transmits the third instruction signal to the driver IC 51, and the signal lines for which the protection processing unit 304 transmits the fourth instruction signal to the selector circuit 52 are omitted.

[0142] In the third application example, the other ECUs 2, 3, and 4 connected to the control device 1 are the battery ECU2c, the autonomous driving ECU3c, the EPS-ECU4c, and the body ECU7c. EPS is an abbreviation for Electric Power Steering.

[0143] In the third application example, the actuator 6 is a motor 62c, which is the drive source of the vehicle. The control application in the third application example controls a relay 53 that switches whether or not a drive voltage is supplied to the motor 62c. The relay 53 in the third application example is a high-voltage relay.

[0144] In the third application example, the control device 1 is connected to the inverter 61c, motor 62c, and battery 63c via a relay 53. The battery 63c is a DC power source that powers the vehicle. The inverter 61c is a device that converts the DC voltage of the battery 63c into an AC voltage to drive the motor 62c. The drive system protection process in the third application example includes the process of turning off the relay 53.

[0145] The series of processes performed in the control device 1 when it is powered on or restarted by a reset in the third application example may be the same as the flow shown in Figure 5. The drive system protection process in the second application example includes a process to shut off the relay 53 that switches whether or not drive voltage is supplied to the motor 62c. This prevents external attacks from being transmitted to the motor 62c. Therefore, the risk of the vehicle moving unintentionally can be reduced.

[0146] <Fourth Application Example> In the fourth application example, the vehicle on which the control device 1 is installed is an HEV. Below, an example in which the control device 1 is used as an HEV-ECU will be explained using Figure 17. The HEV-ECU is an ECU that controls two power sources, the engine and the motor 62c. In Figure 17, the signal lines for which the protection processing unit 304 transmits the first instruction signal to the communication IC 41, the signal lines for which the protection processing unit 304 transmits the second instruction signal to the selector circuit 42, the signal lines for which the protection processing unit 304 transmits the third instruction signal to the driver IC 51, and the signal lines for which the protection processing unit 304 transmits the fourth instruction signal to the selector circuit 52 are omitted.

[0147] In the fourth application example, the other ECUs 2, 3, and 4 connected to the control device 1 are the engine ECU 2d, the autonomous driving ECU 3d, the EPS-ECU 4d, and the body ECU 7d.

[0148] In the fourth application example, the actuator 6 is the motor 62c, which is the drive source of the vehicle. The control application in the fourth application example controls a relay 53 that switches whether or not a drive voltage is supplied to the motor 62c. The relay 53 in the fourth application example is a high-voltage relay, similar to that in the third application example.

[0149] The control device 1 in the fourth application example is connected to the inverter 61c, motor 62c, and battery 63c via relay 53, similar to the third application example. The drive system protection process in the fourth application example includes a process to turn off relay 53, similar to the third application example.

[0150] The series of processes performed in the control device 1 when it is powered on or restarted by a reset in the fourth application example may be the same as the flow shown in Figure 5. The drive system protection process in the fourth application example includes a process to shut off the relay 53 that switches whether or not drive voltage is supplied to the motor 62c. This prevents external attacks from being transmitted to the motor 62c. Therefore, the risk of the vehicle moving unintentionally can be reduced.

[0151] The fourth application example shows an example in which the control device 1 is used as an HEV-ECU, but the control device 1 may also be used as an S-HEV-ECU. An S-HEV-ECU is an engine control unit for a strong hybrid electric vehicle.

[0152] <Variation> The configuration shown includes drive system protection processing, communication system protection processing, and information storage processing in the protection process, but it is not necessarily limited to this configuration. The protection process may not include any of the drive system protection processing, communication system protection processing, and information storage processing. For example, the protection process may not include drive system protection processing. Alternatively, the protection process may include any one of the drive system protection processing, communication system protection processing, and information storage processing.

[0153] Although the configuration shown for the control device 1 includes one microcontroller 10, it is not necessarily limited to this configuration. The control device 1 may also have a configuration that includes multiple microcontrollers 10.

[0154] The termination information storage unit 136 is shown as being included in the secure storage 13 implemented using a non-volatile storage medium, but the configuration is not necessarily limited to this. The termination information storage unit 136 may also be included in a storage area that stores data even when the control device 1 is powered off. For example, a battery-powered RAM may have a configuration that includes the termination information storage unit 136.

[0155] The drive system protection activation unit, the communication system protection activation unit, and the storage function activation unit may be integrated into a single activation unit used in common. In other words, a single activation unit may be configured to activate the drive system main unit, the communication system main unit, and the information storage main unit.

[0156] The encryption keys used by the drive system protection activation unit, the communication system protection activation unit, and the storage function activation unit for authentication when activating each main unit may be different encryption keys.

[0157] The protection processing unit 304 may not include a drive system protection activation unit, a communication system protection activation unit, and a storage function activation unit. For example, the drive system protection processing unit 342 may not include a drive system protection activation unit. In this case, the drive system main unit does not need to be disabled by the encryption key. The drive system main unit may be operational from the time the drive system protection processing unit 342 is constructed.

[0158] The encryption key storage unit 133, verification history storage unit 135, and termination information storage unit 136 are shown as being included in the secure storage 13, but the configuration is not necessarily limited to this. The encryption key storage unit 133, verification history storage unit 135, and termination information storage unit 136 may also be included in an HSM (Hardware Security Module) or an external server.

[0159] The microcontroller 10 had two non-volatile storage media, a normal storage 12 and a secure storage 13, but it is not necessarily required to have two storage media. For example, the microcontroller 10 may be configured to have only the secure storage 13. In this case, the secure storage 13 may have a control application storage unit 121.

[0160] The control device 1 may be configured to use at least two different processing areas, a normal world and a secure world, in conjunction with TrustZone® technology. The normal world is the normal area where the operating system and applications are executed. The secure world is an area isolated from the normal world. In the secure world, a secure operating system and applications for processes requiring security are executed. Access from the normal world to the secure world is restricted by the functions of the processor 11. Therefore, the existence of the secure world is not recognized from the normal world, and the security of processes executed in the secure world and information stored in the secure world is ensured. The control device 1 may be configured to execute boot processing and control applications in the normal world, and to perform secure boot and protection processing in the secure world.

[0161] The storage area where data is stored in the normal world (Untrusted Storage) may be the normal storage 12. Similarly, the storage area used for data storage in the secure world (Trusted Storage) may be the secure storage 13. The control device 1 uses functions such as context switching to separate the resources necessary for application execution into the normal world and the secure world. The RAM 14 may also be physically or logically divided into a secure area and a normal area.

[0162] The secure boot unit 302 may be configured to repeatedly perform software verification if it obtains a verification result indicating an abnormality, until it obtains a verification result indicating a normal state. The protection process may be set to be performed when the number of times the secure boot unit 302 determines that an abnormality has occurred in the control application exceeds a certain threshold. In other words, the control device 1 may be configured so that the protection process is not executed as long as the number of times an abnormality in the control application has been detected is less than the threshold. The threshold number may be set to any number, such as 5 or 10.

[0163] In a configuration where verification by the secure boot unit 302 is performed repeatedly, the verification history information may be a timestamp of the latest verification result among multiple abnormal verification results. The time when an abnormal verification result is obtained may be the time when the latest verification result among multiple abnormal verification results is obtained.

[0164] There are two possible causes for secure boot failure: an external attack and a malfunction of control unit 1. A malfunction of control unit 1 is unlikely to cause consecutive abnormal verification results from the secure boot unit 302. On the other hand, an external attack can cause consecutive abnormal verification results from the secure boot unit 302. If the system is configured to perform protection processing when the number of abnormal verification results exceeds a certain threshold, then protection processing will not be performed in the case of a secure boot failure due to a malfunction of control unit 1, but will be performed when there is a high probability of an external attack. In other words, protection processing will be performed appropriately when it should be performed. [Explanation of Symbols]

[0165] 1...Control device, 2...Other ECU (other control device), 3...Other ECU (other control device), 4...Other ECU (other control device), 6...Actuator, 11...Processor, 12...Normal storage, 13...Secure storage, 14...RAM, 41...Communication IC (Communication unit), 42...Selector circuit, 50...Input / output interface, 51...Driver IC (Drive control unit), 52...Selector circuit, 53...Relay, 121...Control application storage unit, 133...Encryption key storage unit, 135...Verification history storage unit, 136...Termination information storage unit, 201...Application execution unit, 302...Secure boot unit, 301...Boot unit, 304...Protection processing unit

Claims

1. A control device mounted on a mobile vehicle, A control application storage unit (121) that stores control applications for realizing desired functions, A secure boot unit (302) that performs a secure boot to verify the integrity of the control application when the control device is started, If the verification result by the secure boot unit is normal, the application execution unit (201) starts the execution of the control application, A drive control unit (51) controls a drive unit corresponding to the desired function based on instructions from the control application, If the verification result by the secure boot unit is abnormal, the system includes a protection processing unit (304) that performs protection processing, The protection process includes a control device that performs a drive system protection process to disconnect the electrical connection between the drive control unit and the drive unit.

2. A control device mounted on a mobile vehicle, A control application storage unit (121) that stores control applications for realizing desired functions, A communication unit (41) that communicates with other control devices, A secure boot unit (302) that performs a secure boot to verify the integrity of the control application when the control device is started, If the verification result by the secure boot unit is normal, the application execution unit (201) starts the execution of the control application, If the verification result by the secure boot unit is abnormal, the system includes a protection processing unit (304) that performs protection processing, The protection process includes a control device that includes a communication system protection process that restricts communication between the communication unit and the other control devices.

3. It further includes a communication unit (41) that communicates with other control devices, The control device according to claim 1, wherein the protection process includes a communication system protection process that restricts communication between the communication unit and the other control device.

4. The control device according to claim 2 or 3, wherein the communication protection process includes a process to control the communication unit so as not to transmit signals to other control devices.

5. The control device according to any one of claims 1 to 3, wherein the protection process further includes an information storage process that stores verification history information indicating the state of the control device at the time the verification result by the secure boot unit became abnormal in a verification history storage unit (135).

6. The system further includes an encryption key storage unit (133) that stores the encryption key, The protection process further includes an information storage process that stores verification history information indicating the state of the control device when the verification result by the secure boot unit becomes abnormal in the verification history storage unit (135). The aforementioned protective processing unit is The encryption key is obtained from the encryption key storage unit, The verification history information is encrypted using the aforementioned encryption key and stored in the verification history storage unit. Upon receiving a specific communication signal from an external device, the communication unit authenticates the external device using the encryption key. If the authentication is successful, the encrypted verification history information is decrypted and stored in a way that allows it to be accessed by an external device. The control device according to claim 2 or 3, which is configured not to decrypt the encrypted verification history information if the authentication fails.

7. The control device according to claim 5, wherein the verification history information includes (i) a timestamp when the verification result by the secure boot unit was last successful, (ii) a timestamp when the verification result by the secure boot unit was abnormal, (iii) the position coordinates of the moving object when the verification result by the secure boot unit was abnormal, (iv) the number of times the verification result by the secure boot unit was abnormal, (v) information on the rewritten section of the control application, (vi) data stored in the control application storage unit when the verification result by the secure boot unit was last successful and when a verification result indicating an abnormality was obtained by the secure boot unit, and (vii) at least one of the diagnostic trouble codes detected when the verification result by the secure boot unit was abnormal.

8. If the secure boot unit determines that the control application is abnormal, it will repeatedly verify the control application until it determines that the control application is normal. The control device according to any one of claims 1 to 3, wherein the protection processing unit is configured to execute the protection process when the number of times the secure boot unit determines that the control application is abnormal during verification exceeds a certain number of times.

9. The system further includes an encryption key storage unit (133) that stores the encryption key, The aforementioned protective processing unit is Including the protection function activation unit and the main unit, The main body is, The protection process described above is performed by, The system is configured to be invalidated by the encryption key if the verification result by the secure boot unit is not found to be abnormal. The aforementioned protection function activation unit is: If the verification result by the secure boot unit is abnormal, the encryption key is obtained from the encryption key storage unit. The control device according to any one of claims 1 to 3, configured to activate the main unit with the acquired encryption key.

10. The aforementioned protective processing unit is Upon receiving a specific communication signal from an external device via the aforementioned communication unit, the external device is authenticated using an encryption key. If the authentication is successful, the protection processing state will be released. The control device according to claim 2 or 3, which is configured to continue the protection processing state if the authentication fails.

11. The control device according to claim 10, wherein the authentication is one of the following: authentication using a common key, authentication using a public key, or challenge-response authentication using a session key.

12. The control device further includes a boot unit (301) that performs startup processing when the control device is started. The aforementioned startup process includes a process for starting the secure boot unit, When the protection processing unit has performed the protection processing, it stores the termination information in the termination information storage unit (136). The boot unit described above is Before the secure boot unit verifies the control application, it is determined whether or not the termination information is stored in the termination information storage unit. The control device according to any one of claims 1 to 3, wherein, if it is determined that the termination information has been saved, the protection processing unit is activated to start the protection process without verifying the control application by the secure boot unit.

13. The aforementioned moving object is a vehicle, The aforementioned drive unit is a motor that switches the shift position of the vehicle, The control application is an application that outputs a drive signal to the motor to control the shift position, The aforementioned drive system protection process is, A process to perform a lock control to fix the shift position to parking, The control device according to claim 1 or 3, further comprising the process of turning off a relay in the wiring that outputs the drive signal to the motor.

14. The aforementioned moving object is a vehicle, The drive unit is a solenoid that switches the gear position of the vehicle's transmission, The control application is an application that outputs a drive signal to the solenoid to switch the gear position, The aforementioned drive system protection process is, The control device according to claim 1 or 3, further comprising the process of turning off the relay in the wiring that outputs the drive signal to the solenoid.

15. The aforementioned mobile body is an electric vehicle, The drive unit is a motor which is the drive source for the moving body, The control application is an application that controls a high-voltage relay that switches whether or not a drive voltage is supplied to the motor, The control device according to claim 1 or 3, wherein the drive system protection process includes a process to turn off the high-voltage relay.

Citation Information

Patent Citations

  • In-vehicle ECU, program, and method for fail-safe

    JP2022074461A