Digital key issuance method and program

The digital key issuance method addresses the challenge of generating keys in a separated secure element by implementing authentication and verification processes, enabling efficient combination and secure control between a communication device and electronic storage medium.

JP2026062784APending Publication Date: 2026-04-10DAI NIPPON PRINTING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
DAI NIPPON PRINTING CO LTD
Filing Date
2025-12-23
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing technical standards do not provide a clear processing procedure for generating a digital key when the secure element is separated from a communication device, such as an IC card, making it difficult to efficiently determine the combination of a control target object and the electronic information storage medium.

Method used

A digital key issuance method involving a communication device, a controlled object, and an electronic information storage medium, which includes authentication processes, time information verification, and data transmission to generate and verify digital keys, ensuring the secure element can function independently.

Benefits of technology

Enables the generation of digital keys in an electronic information storage medium separated from the communication device, efficiently determining the combination of the controlled object and the storage medium, allowing secure control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026062784000001_ABST
    Figure 2026062784000001_ABST
Patent Text Reader

Abstract

This invention provides a digital key issuance method and program that generate a digital key on an electronic information storage medium separated from the electronic device, and efficiently determine the combination of a controlled object such as a vehicle and the electronic information storage medium. [Solution] The electronic device 3 performs a first authentication process with the IC card 4 and a second authentication process with the vehicle 2. Upon receiving digital key generation data from the authenticated vehicle 2, it transmits the digital key generation data to the authenticated IC card 4. Upon receiving the digital key certificate and intermediate CA certificate generated by the IC card 4, it transmits the received digital key certificate and intermediate CA certificate to the authenticated vehicle 2.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of systems for generating digital keys necessary for controlling a controlled object such as a vehicle.

Background Art

[0002] Conventionally, as disclosed in Patent Document 1 for example, an in-vehicle communication system capable of locking and unlocking a vehicle door and starting an engine using a digital key stored in an electronic device such as a smartphone is known. Such a method for issuing a digital key is defined in, for example, a technical standard (Car Connectivity Consortium Digital Key Release 2) published by the Car Connectivity Consortium (registered trademark). In such a technical standard, it targets an electronic device in which a digital key framework that communicates with a server to generate a digital key and a secure element that stores the generated digital key are integrally mounted.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, the above-mentioned technical standard does not stipulate the processing procedure when only the secure element part is independently separated from a communication device such as an electronic device as an electronic information storage medium such as an IC (Integrated Circuit) card that can be carried by a user.

[0005] Therefore, the present invention has been made in view of the above points, and aims to provide a digital key issuance method and program that can generate a digital key in an electronic information storage medium separated from a communication device, and efficiently determine the combination of a control target object such as a vehicle and the electronic information storage medium. [Means for solving the problem]

[0006] To solve the above problems, the invention described in claim 1 is a digital key issuance method performed by a controlled object, a communication device separated from the controlled object and capable of communicating with the controlled object, and an electronic information storage medium separated from the controlled object and the communication device, capable of communicating with the communication device and portable by a user, comprising: an authentication step of performing a first authentication process between the communication device and the electronic information storage medium; a step of the communication device transmitting time information for validity period verification to the electronic information storage medium authenticated by the first authentication process; a step of the electronic information storage medium receiving the time information from the communication device; a step of performing a second authentication process between the communication device or the electronic information storage medium authenticated by the first authentication process and the controlled object; a step of the communication device receiving data for generating a digital key necessary to control the controlled object, which includes a controlled object certificate describing the validity period and signed with the private key of the controlled object manufacturer, from the controlled object authenticated by the second authentication process; and the communication device The steps include: transmitting the data received from the controlled object to the electronic information storage medium authenticated by the first authentication process; the electronic information storage medium receiving the data from the communication device; the electronic information storage medium verifying the signature of the controlled object certificate contained in the data received from the communication device with the public key of the controlled object manufacturer, and verifying whether the expiration date of the controlled object certificate has expired based on the time information received from the communication device; the electronic information storage medium, upon successful verification of the signature of the controlled object certificate and successful verification of the expiration date of the controlled object certificate, transmitting a response indicating successful completion to the communication device; the communication device receiving the response from the electronic information storage medium; the communication device transmitting the response received from the electronic information storage medium to the controlled object authenticated by the second authentication process; the communication device receiving a command indicating a digital key generation command from the controlled object that received the response; and the communication deviceThe method is characterized by including the steps of: transmitting the command received from the controlled object to the electronic information storage medium authenticated by the first authentication process; when the electronic information storage medium receives the command from the communication device, generating and storing the digital key based on the data received from the communication device; the electronic information storage medium transmitting to the communication device a first certificate, which is a certificate of the stored digital key and is signed with a private key previously stored in the electronic information storage medium, and a second certificate, which includes a public key paired with the private key; the communication device receiving the first certificate and the second certificate from the electronic information storage medium; and the communication device transmitting the first certificate and the second certificate received from the electronic information storage medium to the controlled object authenticated by the second authentication process.

[0007] The invention described in claim 2 is a digital key issuance method according to claim 1, further comprising the steps of: the communication device acquiring authentication information of an operator operating the communication device; and the communication device performing an authentication process for the operator based on the authentication information, wherein in the authentication step, if the operator is authenticated, a first authentication process is performed between the communication device and the electronic information storage medium.

[0008] The invention described in claim 3 is a communication device that is separated from a controlled object and capable of communicating with the controlled object, and the computer included in the communication device, which is separated from a user-portable electronic information storage medium and capable of communicating with the electronic information storage medium, comprises: a first authentication means that performs a first authentication process with the electronic information storage medium; a time information transmission means that transmits time information for validity period verification to the electronic information storage medium authenticated by the first authentication process; a first receiving means that receives data from the controlled object, which is data for generating a digital key necessary to control the controlled object, and which includes a controlled object certificate that describes an expiration date and is signed with the private key of the controlled object manufacturer; and a program that causes the data received by the first receiving means to function as a first transmission means that transmits the data to the electronic information storage medium authenticated by the first authentication process, wherein the electronic information storage medium verifies the signature of the controlled object certificate included in the data received from the communication device with the public key of the controlled object manufacturer, and based on the time information received from the communication device, the previous The program verifies whether the expiration date has not expired, and if the verification of the signature of the control object certificate is successful and the verification of the expiration date of the control object certificate is successful, it sends a response indicating successful completion to the communication device, and the program comprises the computer, a response receiving means for receiving the response from the electronic information storage medium, a response transmitting means for transmitting the response received from the electronic information storage medium to the control object, a command receiving means for receiving a command indicating a digital key generation command from the control object that received the response, a command transmitting means for transmitting the command received from the control object to the electronic information storage medium authenticated by the first authentication process, and a second receiving means for receiving from the electronic information storage medium a first certificate, which is a certificate of the digital key generated based on the data by the electronic information storage medium that has been authenticated by the first authentication process and received the command, and which is stored in the electronic information storage medium and is signed with a private key previously stored in the electronic information storage medium, and a second certificate, which includes a public key paired with the private key,The second receiving means is further configured to function as a second transmitting means for transmitting the first certificate and the second certificate received by the second receiving means to the controlled object.

[0009] The invention described in claim 4 is characterized in that, in the program described in claim 3, an acquisition means for acquiring authentication information of an operator operating the communication device, an operator authentication means for performing an authentication process for the operator based on the authentication information, and the first authentication means performs a first authentication process with the electronic information storage medium when the operator is authenticated by the operator authentication means.

[0010] The invention described in claim 5 is characterized in that, in the program described in claim 3, the computer further functions as a second authentication means for performing a second authentication process with the controlled object, and the first receiving means receives the data from the controlled object authenticated by the second authentication process.

[0011] The invention described in claim 6 is characterized in that, in the program described in claim 4, when the first certificate and the second certificate are transmitted to the controlled object by the second transmission means, the computer is further made to function as a recording means for recording a log including the operator's authentication information. [Effects of the Invention]

[0012] According to the present invention, a digital key can be generated in an electronic information storage medium that is separated from the communication device, and the combination of a controlled object such as a vehicle and the electronic information storage medium can be efficiently determined. [Brief explanation of the drawing]

[0013] [Figure 1] This diagram shows an example of the overall configuration of the digital key issuance system S. [Figure 2] This figure shows an example of the general configuration of the ECU installed in vehicle 2. [Figure 3] This figure shows an example of the general configuration of electronic device 3. [Figure 4] This figure shows an example of the general configuration of IC card 4. [Figure 5] This is a sequence diagram showing an example of the processing procedure performed in the digital key issuance operation of the digital key issuance system S in Example 1. [Figure 6] This is a sequence diagram showing an example of the processing procedure performed in the digital key issuance operation of the digital key issuance system S in Example 2. [Modes for carrying out the invention]

[0014] Embodiments of the present invention will be described in detail below with reference to the drawings. The embodiments described below are examples of the present invention applied to a digital key issuance system that includes a vehicle (an example of a controlled object), an electronic device (an example of a communication device) that can communicate with the vehicle, and an IC card (an example of an electronic information storage medium) that can communicate with the electronic device and is portable by the user. However, the present invention can also be applied to controlled objects other than vehicles, such as a control device for locking and unlocking the doors of a house, a control device for locking and unlocking the doors of a locker that stores articles, or a control device for restricting the destination floor of an elevator with a key. The issuance of a digital key means that a digital key becomes available for controlling the vehicle 2.

[0015] [1. Overview of the Digital Key Issuance System S] First, the general configuration of the digital key issuance system S according to this embodiment will be described with reference to Figure 1, etc. Figure 1 is a diagram showing an example of the general configuration of the digital key issuance system S. The digital key issuance system S is composed of a management server 1, a vehicle 2, an electronic device 3, and an IC card 4, and a digital key is issued through processing procedures between these components. At this time, the electronic device 3 plays the role of determining the combination of the vehicle 2 and the IC card 4. Note that the issuance of a digital key means that the digital key becomes available for use in controlling the vehicle 2. The electronic device 3 is separated from the vehicle 2 as an independent unit. The IC card 4 is also separated from the vehicle 2 and the electronic device 3 as an independent unit.

[0016] Management server 1 and vehicle 2, and management server 1 and electronic device 3, are each able to communicate via a network NW. The network NW consists of, for example, the internet, mobile communication networks, and their wireless base stations. Vehicle 2 and electronic device 3 are able to communicate via a dedicated line such as OBD2 (On Board Diagnosis second generation) or CAN (Controller Area Network). The dedicated line can be wired or wireless (the same applies hereinafter). Electronic device 3 and IC card 4 are able to communicate wirelessly (contactless communication). Technologies such as NFC (Near field communication), Bluetooth (registered trademark), ZigBee, RoLa, or UWB (Ultra Wide Band) are used for wireless communication. An example of management server 1 is a vehicle manufacturer's server.

[0017] FIG. 2 is a diagram showing a schematic configuration example of an ECU (Electronic Control Unit) mounted on the vehicle 2. The ECU is mounted, for example, inside the center console of the vehicle 2. As shown in FIG. 2, the ECU includes a first communication unit 21, a second communication unit 22, a storage unit 23, a control unit 24, and the like. The first communication unit 21 is a communication device connected to the network NW and performing communication with the management server 1. The second communication unit 22 is connected to a dedicated line such as OBD2 or CAN and has a communication function for performing communication with the electronic device 3. Note that the second communication unit 22 may perform wireless communication (contactless communication) with the electronic device 3.

[0018] The storage unit 23 stores an operating system (OS), applications, and the like. Further, the storage unit 23 stores in advance a vehicle certificate and a secret key (the secret key of the vehicle) that forms a pair with the public key included in the vehicle certificate (that is, the public key of the vehicle). The control unit 24 includes a CPU (Central Processing Unit), a RAM (Random Access Memory), a ROM (Read Only Memory), and the like. The control unit 24 executes a process for issuing a digital key according to an application.

[0019] FIG. 3 is a diagram showing a schematic configuration example of the electronic device 3. In the present embodiment, it is assumed that the electronic device 3 is a personal computer (issuing PC) used for issuing a digital key in a factory, for example, but it may be a mobile terminal such as a smartphone. As shown in FIG. 3, the electronic device 3 includes a first communication unit 31, a second communication unit 32, a third communication unit 33, a storage unit 34, an operation unit 35, a display unit 36, a control unit 37, and the like. Note that the electronic device 3 has a clock function. The first communication unit 31 is a communication device connected to the network NW and performing communication with the management server 1. The second communication unit 32 is connected to a dedicated line such as OBD2 or CAN and has a communication function for performing communication with the vehicle 2 (ECU).

[0020] The third communication unit 33 is a communication device for performing wireless communication with the IC card 4. Note that the IC card 4 may be attached (for example, inserted into a slot) to the electronic device 3 only within the factory. In this case, the third communication unit 33 is electrically connected to the IC card 4 via an interface. Examples of such an interface include SPI (Serial Peripheral Interface), I2C (Inter-Integrated Circuit), and the interface of ISO / IEC 7816. The storage unit 34 stores an operating system and applications (including the program of the present invention). Note that a public key of the vehicle manufacturer may be stored in advance in the storage unit 34.

[0021] The operation unit 35 receives operation instructions from an operator. The display unit 36 displays various information on a display. The control unit 37 is configured to include a CPU, a RAM, a ROM, and the like. The control unit 37 executes a process for issuing a digital key according to an application. Note that the program of the present invention causes a computer (CPU) included in the control unit 37 to function as the first authentication means, the second authentication means, the third authentication means, the first reception means, the second reception means, the first transmission means, the second transmission means, the verification means, the acquisition means, and the recording means in the present invention.

[0022] Figure 4 shows an example of the general configuration of the IC card 4. As shown in Figure 4, the IC card 4 is composed of a communication unit 41, RAM 42, NVM (Nonvolatile Memory) 43, and CPU 44, etc. The communication unit 41 is a communication device for wireless communication with the electronic device 3. The communication unit 41 may be electrically connected to the IC card 4 via an interface. The NVM 43 stores the operating system and applications. The NVM 43 also pre-stores an intermediate CA (Certification Authority) certificate (an example of a second certificate) and a private key that pairs with the public key included in the intermediate CA certificate (i.e., the public key of the intermediate CA). In other words, the IC card 4 itself functions as an authority that issues digital certificates. The NVM 43 may also pre-store the public key of the vehicle manufacturer. The CPU 44 executes processing to issue digital keys according to the application.

[0023] In the above configuration, the electronic device 3 performs a first authentication process with the IC card 4 and a second authentication process with the vehicle 2. In the first authentication process, for example, a common key shared by the electronic device 3 and the IC card 4 is used, and a process is performed to determine whether encrypted data, in which random numbers have been encrypted with the common key of either the electronic device 3 or the IC card 4, can be decrypted with the common key of the other. In this case, for example, encrypted data generated by the IC card 4 is transmitted to the electronic device 3 via wireless communication. The authentication method in the first authentication process is not particularly limited, and various known authentication methods such as common key authentication methods may be adopted. Furthermore, the authentication in the first authentication process may be one-sided authentication (authentication of the IC card 4) or mutual authentication (authentication of the electronic device 3 and authentication of the IC card 4).

[0024] On the other hand, in the second authentication process, for example, parameters issued by the management server 1 and sent to the vehicle 2, and a password (a value different from the parameters) issued by the management server 1 and sent to the electronic device 3 are used, and a process is performed to determine whether the value from which the parameters originate and the value from which the password originates match. In this case, for example, the value from which the parameters originate is calculated by the vehicle 2 and sent to the electronic device 3 via a dedicated line. The authentication method in the second authentication process is not particularly limited, and various known authentication methods such as challenge / response authentication and password authentication may be adopted. Furthermore, the authentication in the second authentication process may be one-sided authentication (authentication of vehicle 2) or mutual authentication (authentication of vehicle 2 and authentication of electronic device 3).

[0025] If authentication is successful in the first authentication process and also successful in the second authentication process, vehicle 2 transmits data (hereinafter referred to as "digital key generation data") necessary to generate a digital key for controlling vehicle 2 (for example, locking / unlocking vehicle doors or starting the engine) to electronic device 3 via a dedicated line. Here, the digital key generation data includes, for example, a vehicle ID unique to vehicle 2. When electronic device 3 receives the digital key generation data from the authenticated vehicle 2 via the dedicated line, it transmits the received digital key generation data to the authenticated IC card 4 via wireless communication.

[0026] Here, vehicle 2 may transmit digital key generation data, signed with the vehicle manufacturer's private key stored in vehicle 2, to electronic device 3 via a dedicated line. In this case, the digital key generation data may include, for example, a vehicle certificate containing the vehicle 2's public key, and it is desirable that this vehicle certificate be signed with the vehicle manufacturer's private key. When electronic device 3 receives the digital key generation data signed with the vehicle manufacturer's private key from vehicle 2 via the dedicated line, it verifies the signature of the digital key generation data (vehicle certificate) with the vehicle manufacturer's public key pre-stored in electronic device 3. If the verification is successful, it transmits the verified digital key generation data to the authenticated IC card 4 via wireless communication.

[0027] When IC card 4 receives digital key generation data from electronic device 3, it generates a digital key necessary to control the authenticated vehicle 2 based on the received digital key generation data and stores it in NVM43. Here, the digital key consists of a key pair of a public key and a private key. IC card 4 also generates a certificate for the stored digital key (hereinafter referred to as the "digital key certificate"). Such a digital key certificate (an example of the first certificate) includes the public key in the digital key and is signed with the private key of the intermediate CA pre-stored in IC card 4. IC card 4 then transmits the signed digital key certificate and the intermediate CA certificate to electronic device 3 via wireless communication.

[0028] When electronic device 3 receives a signed digital key certificate and an intermediate CA certificate from IC card 4, it transmits the received digital key certificate and intermediate CA certificate to the authenticated vehicle 2 via a dedicated line. When vehicle 2 receives the signed digital key certificate and intermediate CA certificate from electronic device 3 via the dedicated line, it verifies the signature of the digital key certificate using the public key of the intermediate CA contained in the intermediate CA certificate. If the verification is successful, it stores the digital key certificate in storage unit 23. In this way, a digital key to be used by IC card 4 is issued, and the public key in the digital key of IC card 4 is registered with vehicle 2. As a result, IC card 4 can control vehicle 2 contactlessly using the digital key.

[0029] [2. Operation of the Digital Key Issuance System S] Next, the digital key issuance operation of the digital key issuance system S will be explained in two separate examples, Example 1 and Example 2. As a prerequisite for the issuance operation described below, the intermediate CA certificate and the intermediate CA's private key are written to and stored on the IC card 4 (NVM43) at the card manufacturing plant. Furthermore, a common key is written to and stored on both the USB (Universal Serial Bus) key inserted into the electronic device 3 and the IC card 4 (NVM43) at the card manufacturing plant. Here, the USB key serves as the key that enables the use of the electronic device 3 upon insertion.

[0030] Then, the USB key containing the common key for IC card 4, the IC card 4 containing the common key for electronic device 3, the intermediate CA certificate, and the intermediate CA's private key are shipped from the card manufacturing plant and delivered to the automobile factory. At the automobile factory, electronic device 3 is prepared as the issuing PC, and the USB key is inserted into electronic device 3. Also at the automobile factory, the vehicle 2 to be paired with IC card 4 is prepared. At the automobile factory, the management server 1, vehicle 2, and electronic device 3 are connected to each other so that they can communicate with one another, and electronic device 3 and IC card 4 are also connected to each other so that they can communicate with one another.

[0031] (Example 1) First, with reference to Figure 5, the digital key issuance operation of the digital key issuance system S in Embodiment 1 will be described. Figure 5 is a sequence diagram showing an example of the processing procedure performed in the digital key issuance operation of the digital key issuance system S in Embodiment 1. Embodiment 1 is an example in which the signature verification of the digital key generation data is performed by the electronic device 3, and the storage unit 34 of the electronic device 3 stores the vehicle manufacturer's public key.

[0032] The electronic device 3 obtains authentication information (e.g., user ID and password) entered by the operator (worker) operating the electronic device 3 from the operation unit 35, and performs authentication processing for the operator based on said authentication information (step S1). In this authentication processing, for example, the operator is authenticated if the acquired authentication information matches pre-registered authentication information. Once the operator is authenticated, the electronic device 3 becomes able to accept operation instructions from the operator. In other words, if the operator is authenticated, the electronic device 3 performs the first authentication processing with the IC card 4. If the operator cannot be authenticated, the electronic device 3 will not be able to accept operation instructions from the operator and will not proceed to the first authentication processing.

[0033] Then, when an authenticated operator issues an issuance command from the operation unit 35, the electronic device 3 sends an authentication command to the IC card 4 in response to the issuance command, thereby performing the first authentication process described above with the IC card 4 (step S2). If the authentication in the first authentication process is successful, a secure session is established between the electronic device 3 and the IC card 4, and it is preferable that encryption and message authentication be performed using the session key generated in the first authentication process during communication over this secure session.

[0034] When authentication between the electronic device 3 and the IC card 4 (for example, mutual authentication) is successful, authentication success information is sent from the electronic device 3 to the management server 1 via the network NW. Upon receiving the authentication success information, the management server 1 sends an authentication request including parameters to the vehicle 2 via the network NW (step S3). Next, the management server 1 sends an authentication request including a password to the electronic device 3 via the network NW (step S4).

[0035] When Vehicle 2 (ECU) receives an authentication request including parameters from Management Server 1, it sends a SELECT command (including Application ID) indicating the selection of an application for performing the second authentication process to Electronic Device 3 via a dedicated line (Step S5). Next, when Electronic Device 3 receives an authentication request including a password from Management Server 1 and also receives a SELECT command from Vehicle 2, it selects an application for performing the second authentication process and sends a response to the SELECT command to Vehicle 2 via a dedicated line (Step S6).

[0036] Next, when vehicle 2 receives a response from electronic device 3, it sends an authentication command to electronic device 3, thereby performing the second authentication process described above with electronic device 3 (step S7). If the authentication in the second authentication process is successful, a secure session is established between vehicle 2 and electronic device 3, and it is preferable that encryption and message authentication be performed using the session key generated in the second authentication process during communication over this secure session.

[0037] If authentication between vehicle 2 and electronic device 3 (e.g., mutual authentication) is successful, vehicle 2 sends a command (e.g., including a STORE DATA command) indicating the instruction to write and verify data for generating a digital key to electronic device 3 via a dedicated line (step S8). The data portion of such a command includes data for generating a digital key, which has a vehicle certificate describing, for example, the vehicle ID and expiration date. The vehicle certificate is also signed with the vehicle manufacturer's private key stored on the vehicle manufacturer's server.

[0038] Next, when the electronic device 3 receives a command from the vehicle 2 containing data for generating a digital key, it writes the data to the storage unit 34 and verifies the signature of the vehicle certificate contained in the digital key generation data with the vehicle manufacturer's public key (step S9). If the data length of the digital key generation data exceeds the data length that can be sent at once, the sending and receiving of the command indicating the write and verification instruction and its response are performed multiple times, and the verification is performed after all of the digital key generation data has been written. It is desirable that the verification include checking whether the vehicle certificate has expired based on the time information (year, month, day, and time) obtained by the clock function of the electronic device 3.

[0039] Then, if the electronic device 3 successfully verifies the signature of the vehicle certificate and the expiration date of the vehicle certificate, it sends a response indicating successful completion to the vehicle 2 via a dedicated line (step S10). On the other hand, if the above verification fails, an error response is sent to the vehicle 2. Next, when the vehicle 2 receives the response indicating successful completion from the electronic device 3, it sends a command indicating a digital key generation command (for example, including a GET DATA command) to the electronic device 3 via a dedicated line (step S11). Next, when the electronic device 3 receives the command indicating a digital key generation command from the vehicle 2, it sends a command indicating an intermediate CA certificate transmission command to the IC card 4 via wireless communication (step S12).

[0040] Next, when IC card 4 receives a command from electronic device 3 indicating a transmission instruction for an intermediate CA certificate, it reads the intermediate CA certificate from NVM 43 and transmits a response containing the intermediate CA certificate to electronic device 3 via wireless communication (step S13). Next, when electronic device 3 receives a response containing the intermediate CA certificate from IC card 4, it writes the intermediate CA certificate to storage unit 34 and transmits a command indicating a digital key generation instruction to IC card 4 via wireless communication (step S14). The data portion of this command contains the digital key generation data verified in step S9 above.

[0041] Next, when IC card 4 receives a command from electronic device 3 containing data for generating a digital key, it generates a digital key based on the data (step S15) and stores it in NVM 43. Then, IC card 4 generates a digital key certificate based on the public key in the digital key generated in step S15 and the intermediate CA certificate, and signs the digital key certificate with the intermediate CA's private key (step S16). For example, signature data is generated by encrypting the hash value of the digital key certificate with the intermediate CA's private key, and the digital key certificate is signed by attaching this signature data to the digital key certificate.

[0042] Next, IC card 4 transmits a response containing the digital key certificate generated and signed in step S16 to electronic device 3 via wireless communication (step S17). If the data length of the digital key certificate exceeds the data length that can be transmitted at once, IC card 4 transmits a response to electronic device 3 indicating the data length of the digital key certificate. Upon receiving this response, electronic device 3 sends a read command to IC card 4, causing IC card 4 to split the digital key certificate and transmit it to electronic device 3. In other words, the transmission and reception of the read command and its response are performed multiple times.

[0043] Alternatively, IC card 4 may transmit the public key in the digital key generated in step S15 to electronic device 3, which may then generate a digital key certificate based on the public key and the intermediate CA certificate. In this case, electronic device 3 transmits the generated digital key certificate to IC card 4, and IC card 4 signs the digital key certificate with the intermediate CA's private key and transmits it back to electronic device 3.

[0044] Next, when electronic device 3 receives a response from IC card 4 that includes a digital key certificate, it transmits a response (a response to a command indicating a digital key generation instruction) that includes the digital key certificate and the intermediate CA certificate to vehicle 2 via a dedicated line (step S18). Next, when vehicle 2 receives a response from electronic device 3 that includes a digital key certificate and the intermediate CA certificate, it verifies the signature of the digital key certificate using the public key of the intermediate CA contained in the intermediate CA certificate (step S19), and if the verification is successful, it stores the digital key certificate in storage unit 23 (step S20).

[0045] Next, the electronic device 3 records a log (work history data) including the number of digital keys issued, the date and time of issuance, the identifier of the electronic device 3, and the operator's authentication information, and transmits the log to the management server 1 via the network NW (step S21). Then, when the management server 1 receives the log from the electronic device 3, it records the log (step S22). In this way, the logs recorded by the electronic device 3 and the management server 1 make it possible to accurately identify the operator and the electronic device 3 involved in the issuance of the digital keys at a later date.

[0046] (Example 2) Next, with reference to Figure 6, the digital key issuance operation of the digital key issuance system S in Embodiment 2 will be described. Figure 6 is a sequence diagram showing an example of the processing steps performed in the digital key issuance operation of the digital key issuance system S in Embodiment 2. Embodiment 2 is an example in which the signature verification of the digital key generation data is performed by the IC card 4, and the NVM 43 of the IC card 4 stores the vehicle manufacturer's public key. Steps S31 to S35 shown in Figure 6 are the same as steps S1 to S5 shown in Figure 5.

[0047] When electronic device 3 receives an authentication request including a password from management server 1, it transmits the authentication request to IC card 4 via wireless communication (step S36). Protocol conversion may be performed by electronic device 3 at this time. Next, when electronic device 3 receives a SELECT command from vehicle 2, it transmits the SELECT command and time information (year, month, day, and time) for validity verification to IC card 4 via wireless communication (step S37).

[0048] Next, IC card 4 receives an authentication request including a password from electronic device 3, and also receives a SELECT command and time information from electronic device 3. Upon receiving this, IC card 4 selects an application for performing the second authentication process and transmits a response to the SELECT command to electronic device 3 via wireless communication (step S38). Upon receiving the response from IC card 4, electronic device 3 transmits the response to vehicle 2 via a dedicated line (step S39).

[0049] Next, when vehicle 2 receives a response from IC card 4 via electronic device 3, it sends an authentication command to IC card 4 via electronic device 3, thereby performing the second authentication process described above with IC card 4 (step S40). In other words, in the second authentication process in Embodiment 2, electronic device 3 is used to relay commands and responses transmitted and received between vehicle 2 and IC card 4. If authentication in the second authentication process is successful, a secure session is established between vehicle 2 and IC card 4, and it is preferable that encryption and message authentication be performed using the session key generated in the second authentication process during communication over this secure session.

[0050] If authentication between vehicle 2 and IC card 4 (e.g., mutual authentication) is successful, vehicle 2 sends a command indicating the writing and verification instruction for digital key generation data (e.g., including a STORE DATA command) to electronic device 3 via a dedicated line (step S41). The data portion of such a command includes digital key generation data, for example, a vehicle certificate that describes the vehicle ID and expiration date. The vehicle certificate is also signed with the vehicle manufacturer's private key stored on the vehicle manufacturer's server. Next, when electronic device 3 receives the command containing the digital key generation data from vehicle 2, it transmits the command to IC card 4 via wireless communication (step S42).

[0051] Next, when the IC card 4 receives a command from the electronic device 3 containing data for generating a digital key, it writes the data for generating the digital key to the NVM 43 and verifies the signature of the vehicle certificate contained in the data for generating the digital key using the vehicle manufacturer's public key (step S43). Here, as in Embodiment 1, if the data length of the data for generating the digital key exceeds the data length that can be sent at once, the sending and receiving of the command indicating the write and verification instruction and its response are performed multiple times, and the verification is performed after all of the data for generating the digital key has been written. It is desirable that the verification include checking whether the expiration date of the vehicle certificate has expired based on the time information received from the electronic device 3.

[0052] Then, when IC card 4 successfully verifies the signature on the vehicle certificate and the expiration date of the vehicle certificate, it transmits a response indicating successful completion to electronic device 3 via wireless communication (step S44). Next, when electronic device 3 receives the response indicating successful completion from IC card 4, it transmits the response to vehicle 2 via a dedicated line (step S45). Next, when vehicle 2 receives the response indicating successful completion from electronic device 3, it transmits a command indicating a digital key generation command to electronic device 3 via a dedicated line (step S46).

[0053] Next, when the electronic device 3 receives a command from the vehicle 2 indicating a command to generate a digital key, it transmits the command to the IC card 4 via wireless communication (step S47). Next, when the IC card 4 receives a command from the electronic device 3 indicating a command to generate a digital key, it generates a digital key based on the digital key generation data written in step S43 and stores it in the NVM 43 (step S48). Next, the IC card 4 generates a digital key certificate based on the public key in the digital key generated in step S48 and the intermediate CA certificate, and signs the digital key certificate with the private key of the intermediate CA (step S49).

[0054] Next, IC card 4 transmits a response containing the digital key certificate and intermediate CA certificate generated and signed in step S49 to electronic device 3 via wireless communication (step S50). If the data length of the response containing the digital key certificate and intermediate CA certificate exceeds the data length that can be transmitted at once, IC card 4 transmits a response to electronic device 3 indicating the data length of the digital key certificate and intermediate CA certificate. Upon receiving this response, electronic device 3 sends a read command to IC card 4, causing IC card 4 to split the digital key certificate and intermediate CA certificate and transmit them to electronic device 3. In other words, the transmission and reception of the read command and its response are performed multiple times. Note that the processing in steps S51 to S55 shown in Figure 6 is the same as in steps S18 to S22 shown in Figure 5.

[0055] As described above, according to the above embodiment, the electronic device 3 performs a first authentication process with the IC card 4 and a second authentication process with the vehicle 2. When it receives digital key generation data from the authenticated vehicle 2, it transmits the digital key generation data to the authenticated IC card 4. When it receives the digital key certificate and intermediate CA certificate generated by the IC card 4, it transmits the received digital key certificate and intermediate CA certificate to the authenticated vehicle 2. This configuration allows the IC card 4, which is separated from the electronic device 3, to generate a digital key, and efficiently determine the combination of the vehicle 2 and the IC card 4. [Explanation of symbols]

[0056] 1. Management Server 2 vehicles 3 Electronic Devices 4 IC cards 21. First Communications Department 22. Second Communications Department 23 Memory section 24 Control Unit 31. First Communications Department 32 Second Communications Department 33 Third Communications Department 34 Storage section 35 Control section 36 Display section 37 Control Unit 41 Communications Department 42 RAM 43 NVM 44 CPU NW Network S Digital Key Issuance System

Claims

1. A digital key issuance method performed by a controlled object, a communication device separated from the controlled object and capable of communicating with the controlled object, and an electronic information storage medium separated from the controlled object and the communication device, capable of communicating with the communication device and portable by a user, wherein An authentication step of performing a first authentication process between the communication device and the electronic information storage medium, The communication device transmits time information for validity period verification to the electronic information storage medium authenticated by the first authentication process, The electronic information storage medium receives the time information from the communication device, A step of performing a second authentication process between the communication device or the electronic information storage medium authenticated by the first authentication process and the controlled object, The communication device receives data from the controlled object authenticated by the second authentication process, which includes data for generating a digital key necessary to control the controlled object, and which includes a controlled object certificate that describes an expiration date and is signed with the controlled object manufacturer's private key. The communication device transmits the data received from the controlled object to the electronic information storage medium authenticated by the first authentication process, The electronic information storage medium receives the data from the communication device, The electronic information storage medium verifies the signature of the controlled object certificate contained in the data received from the communication device using the public key of the controlled object manufacturer, and verifies whether the expiration date of the controlled object certificate has expired based on the time information received from the communication device. The electronic information storage medium, upon successful verification of the signature of the controlled object certificate and successful verification of the expiration date of the controlled object certificate, transmits a response indicating successful completion to the communication device. The communication device receives the response from the electronic information storage medium, The communication device transmits the response received from the electronic information storage medium to the control object authenticated by the second authentication process, The communication device receives a command indicating a digital key generation command from the controlled object that received the response, The communication device transmits the command received from the controlled object to the electronic information storage medium authenticated by the first authentication process, When the electronic information storage medium receives the command from the communication device, it generates and stores the digital key based on the data received from the communication device. The electronic information storage medium transmits to the communication device a first certificate, which is a certificate of the stored digital key and is signed with a private key previously stored in the electronic information storage medium, and a second certificate, which includes a public key paired with the private key. The communication device receives the first certificate and the second certificate from the electronic information storage medium. The communication device transmits the first certificate and the second certificate received from the electronic information storage medium to the control object authenticated by the second authentication process, A digital key issuance method characterized by including the following:

2. The communication device obtains authentication information of the operator operating the communication device, The communication device performs an authentication process for the operator based on the authentication information. It further includes, The digital key issuance method according to claim 1, characterized in that, in the authentication step, if the operator is authenticated, the first authentication process is performed between the communication device and the electronic information storage medium.

3. A communication device that is separate from the controlled object and capable of communicating with said controlled object, and a computer included in a communication device that is separate from an electronic information storage medium that can be carried by the user and capable of communicating with said electronic information storage medium, A first authentication means that performs a first authentication process with the electronic information storage medium, A time information transmission means for transmitting time information for validity period verification to the electronic information storage medium authenticated by the first authentication process, A first receiving means that receives data from the controlled object, which includes data for generating a digital key necessary to control the controlled object, and which includes a controlled object certificate that describes an expiration date and is signed with the private key of the controlled object manufacturer. A program that causes the first transmitting means to function as a first transmitting means for transmitting the data received by the first receiving means to the electronic information storage medium authenticated by the first authentication process, The electronic information storage medium verifies the signature of the controlled object certificate contained in the data received from the communication device using the public key of the controlled object manufacturer, and verifies whether the expiration date of the controlled object certificate has expired based on the time information received from the communication device. If the verification of the signature of the controlled object certificate is successful and the verification of the expiration date of the controlled object certificate is successful, it sends a response indicating successful completion to the communication device. The aforementioned program controls the computer, A response receiving means for receiving the response from the electronic information storage medium, A response transmission means for transmitting the response received from the electronic information storage medium to the controlled object, A command receiving means that receives a command indicating a digital key generation command from the controlled object that received the response, Command transmission means for transmitting the command received from the controlled object to the electronic information storage medium authenticated by the first authentication process, A second receiving means for receiving from the electronic information storage medium a first certificate, which is a certificate of the digital key generated based on the data by the electronic information storage medium that has been authenticated by the first authentication process and received the command, and which is stored in the electronic information storage medium and is signed with a private key that has been previously stored in the electronic information storage medium, and a second certificate, which includes a public key that is paired with the private key, A program characterized in that it is further configured as a second transmission means for transmitting the first certificate and the second certificate received by the second receiving means to the controlled object.

4. A means for acquiring authentication information of an operator who operates the communication device, An operator authentication means that performs authentication processing for the operator based on the authentication information, Furthermore, The program according to claim 3, characterized in that the first authentication means performs a first authentication process with the electronic information storage medium when the operator is authenticated by the operator authentication means.

5. The computer is further configured to function as a second authentication means for performing a second authentication process with the controlled object. The program according to claim 3, characterized in that the first receiving means receives the data from the controlled object authenticated by the second authentication process.

6. The program according to claim 4, characterized in that when the first certificate and the second certificate are transmitted to the controlled object by the second transmission means, the computer is further made to function as a recording means for recording a log including the operator's authentication information.

Citation Information

Patent Citations

  • Vehicle control system

    JP2020197099A