Authentication system, server, in-vehicle device, authentication method, and authentication program
The authentication system addresses the increased processing load for vehicle data authentication by performing initial authentication and using code signatures to verify access rights, thereby reducing the load and ensuring secure data collection.
Patent Information
- Application Number
- JP2021198535
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-07
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-12-07
AI Technical Summary
The increased processing power of electronic control units in in-vehicle devices allows for the transmission of a wide range of vehicle data to the cloud, necessitating appropriate access rights for personal information protection. However, this leads to an increased processing load for authentication as the amount of vehicle data to be read grows.
An authentication system comprising multiple vehicle-mounted devices and a server, which performs authentication for access requests by determining security levels and generating code signatures using encryption keys. This system reduces the need for repeated authentication requests and data transmission, thereby decreasing the processing load.
The authentication system reduces the processing load for collecting vehicle data by performing authentication once before executing the data collection program and eliminating the need for repeated access requests and authentication, while ensuring legitimate access rights through code signature verification.
Smart Images

Figure 0007683472000001 
Figure 0007683472000002 
Figure 0007683472000003
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a technique for performing authentication for an access request. [Background technology]
[0002] Patent Document 1 describes an in-vehicle device that sets decryption conditions for decrypting encrypted vehicle data according to the country or region the vehicle is traveling in. As a result, the in-vehicle device described in Patent Document 1 can appropriately set data users permitted to read vehicle data even if the data users permitted to read vehicle data change as the country or region in which the vehicle is traveling changes. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2021-100153 A Summary of the Invention [Problem to be solved by the invention]
[0004] The improved processing power of the electronic control unit in the in-vehicle device makes it possible to transmit a wide range of vehicle data to the cloud at an appropriate time. In addition, as the amount of vehicle data to be read increases, it becomes necessary to set appropriate access rights for each vehicle data to be read from the legal standpoint of personal information protection, etc.
[0005] As a result of detailed investigation by the inventors, it was found that as the vehicle data to be read increases, the processing load of authentication performed to set appropriate access rights increases. The present disclosure aims to reduce the processing load of authentication for collecting vehicle data. [Means for solving the problem]
[0006] One aspect of the present disclosure is an authentication system (1) that includes a plurality of vehicle-mounted devices (2) and a server (3), and performs authentication for an access request that requests access to at least one of the plurality of vehicle-mounted devices.
[0007] The multiple on-board devices are mounted in the multiple vehicles, respectively, and configured to transmit vehicle data related to the vehicles they are mounted in. The server is installed outside the multiple vehicles, and configured to acquire the vehicle data from the multiple on-board devices by performing data communication with the multiple on-board devices.
[0008] The server includes a first security level determination unit (S70) and a first signature generation unit (S80, S90). The in-vehicle devices include a second security level determination unit (S230), a second signature generation unit (S450), an authentication unit (S420, S430, S460, S480), and an execution control unit (S490, S500).
[0009] The first security level determination unit is configured to determine a first security level for access to the collection target data based on the type of the access request source when receiving the data collection program from the access request source. The data collection program is a program that specifies at least one collection target data and at least one collection condition for each of the at least one collection target data, and transmits the collection target data corresponding to the collection condition to the server when the collection condition is established. The at least one collection target data is at least one vehicle data to be collected by the access request source that has made the access request.
[0010] The first signature generating unit is configured to generate a first code signature by encrypting a value related to the program of the data collection program with a first encryption key preset according to a first security level.
[0011] The second security level determination unit is configured to, upon receiving the data collection program from the server, determine, for each type of collection target data, a second security level regarding access to the collection target data, based on the type of at least one collection target data.
[0012] The second signature generation unit is configured to generate a second code signature for each type of data to be collected by encrypting a value related to the program of the data collection program with a second encryption key that is preset according to a second security level.
[0013] The authentication unit is configured to perform authentication for each type of collection target data by using the first code signature and the second code signature.
[0014] The execution control unit is configured to permit collection of the target data by executing the data collection program if authentication by the authentication unit is successful, and to prohibit collection of the target data by executing the data collection program if authentication is unsuccessful.
[0015] The authentication system of the present disclosure thus configured can perform authentication once before executing the received data collection program, and can transmit collection target data corresponding to the collection conditions defined in the data collection program from the in-vehicle device to the server each time the collection conditions are satisfied. In other words, the authentication system of the present disclosure eliminates the need for the access request source to transmit an access request to the server each time the collection conditions are satisfied, and eliminates the need to perform authentication each time the collection conditions are satisfied. Therefore, the authentication system of the present disclosure can reduce the processing load of authentication for collecting vehicle data.
[0016] Furthermore, since the authentication system disclosed herein performs authentication using a code signature generated by encryption with a cryptographic key, it is possible for each vehicle to verify whether the access requester has legitimate access rights to the data to be collected.
[0017] Another aspect of the present disclosure is a server of an authentication system, comprising a first security level determination unit and a first signature generation unit. The server of the present disclosure is a server provided in the authentication system of the present disclosure, and can obtain the same effects as the authentication system of the present disclosure.
[0018] Yet another aspect of the present disclosure is an in-vehicle device of an authentication system, comprising a second security level determination unit, a second signature generation unit, a level judgment unit, and an authentication unit. The in-vehicle device of the present disclosure is an in-vehicle device provided in the authentication system of the present disclosure, and can obtain the same effects as the authentication system of the present disclosure.
[0019] Yet another aspect of the present disclosure is an authentication method executed on a server of an authentication system, in which, upon receiving a data collection program from an access requester, a first security level for access to data to be collected is determined based on the type of the access requester, and a first code signature is generated by encrypting a value related to the data collection program with a first encryption key that is preset according to the first security level.
[0020] The authentication method of the present disclosure is a method executed in the authentication system of the present disclosure, and by executing this method, it is possible to obtain the same effects as the authentication system of the present disclosure. Yet another aspect of the present disclosure is an authentication program for causing a server computer to function as a first security level determination unit and a first signature generation unit.
[0021] A computer controlled by the authentication program of the present disclosure can constitute a part of the authentication system of the present disclosure, and can obtain the same effects as the authentication system of the present disclosure. Yet another aspect of the present disclosure is an authentication program for causing a computer of an in-vehicle device to function as a second security level determination unit, a second signature generation unit, an authentication unit, and an execution control unit.
[0022] A computer controlled by the authentication program of the present disclosure can constitute a part of the authentication system of the present disclosure, and can obtain the same effects as the authentication system of the present disclosure. [Brief description of the drawings]
[0023] [Figure 1] FIG. 1 is a block diagram showing a configuration of an authentication system. [Diagram 2] FIG. 2 is a block diagram showing a configuration of an in-vehicle device. [Diagram 3] FIG. 2 is a block diagram showing a configuration of an authentication server. [Figure 4] FIG. 2 is a functional block diagram showing the functional configuration of an in-vehicle device and an authentication server. [Diagram 5] 4A and 4B are diagrams illustrating table configurations of an in-vehicle device and an authentication server. [Figure 6] 13 is a flowchart showing a server authentication process. [Figure 7] FIG. 2 is a diagram showing the structure of a distribution package. [Figure 8] 13 is a flowchart showing a vehicle authentication process. [Figure 9] 13 is a flowchart showing a signature authentication process. [Figure 10] 13 is a flowchart showing a release process. [Figure 11] 13 is a flowchart showing an authentication failure process. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0024] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. An authentication system 1 of this embodiment includes a plurality of vehicle-mounted devices 2 and an authentication server 3, as shown in FIG.
[0025] The in-vehicle device 2 is mounted on a vehicle and has a function of performing data communication with an authentication server 3 via a wide area wireless communication network NW. The authentication server 3 has a function of performing data communication with the vehicle-mounted device 2 via the wide area wireless communication network NW.
[0026] A data collection website accessible via the wide area wireless communication network NW is installed on the authentication server 3. The data collection website provides a vehicle data collection service to a service recipient who accesses the data collection website using a communication device such as a personal computer or a tablet terminal.
[0027] 2, the in-vehicle device 2 includes a control unit 11, a CAN communication unit 12, a storage unit 13, and a communication unit 14. CAN is an abbreviation for Controller Area Network. CAN is a registered trademark.
[0028] The control unit 11 is an electronic control device mainly composed of a microcomputer including a CPU 21, a ROM 22, a RAM 23, etc. Various functions of the microcomputer are realized by the CPU 21 executing a program stored in a non-transient real recording medium. In this example, the ROM 22 corresponds to the non-transient real recording medium storing the program. Furthermore, the execution of this program executes a method corresponding to the program. Note that some or all of the functions executed by the CPU 21 may be configured in hardware using one or more ICs, etc. Also, the number of microcomputers constituting the control unit 11 may be one or more.
[0029] The CAN communication unit 12 is connected to a plurality of ECUs via a CAN bus so as to be able to perform data communication, and transmits and receives data according to a CAN communication protocol. The plurality of ECUs 111, 112, 113, 114, ... connected to the CAN communication unit 12 are specifically an engine ECU 111 that performs engine control, a brake ECU 112 that performs brake control, a steering ECU 113 that performs steering control, a meter ECU 114 that is provided on an instrument panel and controls meters that display various vehicle states, etc. In FIG. 2, only the ECUs 111, 112, 113, and 114 are shown as the ECUs connected to the CAN communication unit 12.
[0030] The storage unit 13 is a storage device for storing various data. The communication unit 14 performs data communication with the authentication server 3 via the wide area wireless communication network NW.
[0031] As shown in FIG. 3, the authentication server 3 includes a control unit 31, a communication unit 32, and a storage unit 33. The control unit 31 is an electronic control device mainly composed of a microcomputer including a CPU 41, a ROM 42, a RAM 43, etc. Various functions of the microcomputer are realized by the CPU 41 executing a program stored in a non-transitive substantial recording medium. In this example, the ROM 42 corresponds to the non-transitive substantial recording medium storing the program. Furthermore, the execution of this program executes a method corresponding to the program. Note that some or all of the functions executed by the CPU 41 may be configured in hardware using one or more ICs, etc. Also, the number of microcomputers constituting the control unit 31 may be one or more.
[0032] The communication unit 32 performs data communication with a plurality of vehicle-mounted devices 2 via the wide area wireless communication network NW. The storage unit 33 is a storage device for storing various data.
[0033] 4, the authentication server 3 includes, as functional blocks realized by the CPU 41 executing a program stored in the ROM 42, a program distribution control unit 51, a user information determination unit 52, a key determination unit 53, a signature generation unit 54, and a distribution package generation unit 55. The authentication server 3 also includes a user information table 56, a security level table 57, and a key table 58. These tables 56 to 58 are stored in the storage unit 33.
[0034] The in-vehicle device 2 includes a program execution control unit 71, a DID determination unit 72, a key determination unit 73, a signature verification execution unit 74, an execution right granting unit 75, and a data acquisition unit 76 as functional blocks realized by the CPU 21 executing a program stored in the ROM 22. The in-vehicle device 2 also includes a DID information table 77, a security level table 78, a key table 79, and a database 80. These tables 77 to 79 are stored in the storage unit 13. The database 80 stores vehicle data related to the vehicle in which the in-vehicle device 2 is mounted, and is provided in the storage unit 13.
[0035] The program distribution control unit 51 accepts a data collection request from the operator via the browser 4, and controls the distribution of a script file in which source code for collecting data from a vehicle is written in a script language (e.g., Python, JavaScript, Lua, etc.) based on the data collection request. Python is a registered trademark. JavaScript is a registered trademark. The program distribution control unit 51 may also control the distribution of a file written in a compiler language.
[0036] The browser 4 is software installed in a communication device (for example, a personal computer or a tablet terminal), and has a function of accessing the authentication server 3 via the wide area wireless communication network NW.
[0037] In this embodiment, an operator who operates a communication device to access the authentication server 3 via the browser 4 is classified as either an OEM or a third party. OEM is the vehicle manufacturer that manufactured the vehicle that is the subject of data collection (hereinafter, the collection target vehicle). OEM is an abbreviation for Original Equipment Manufacturer. A third party is a third party other than the owner of the collection target vehicle and the OEM. An example of a third party is a data utilization company that provides a service by collecting data from vehicles.
[0038] The user information determination unit 52 identifies the security level of the operator (hereinafter, referred to as the user security level) by referring to the user information table 56 based on the data collection request. The user security level is information indicating the level of the access right of the operator.
[0039] The key determination unit 53 refers to a security level table 57 based on the user security level to identify a private key for generating a code signature, which will be described later. The signature generating unit 54 obtains the specified private key by referring to the key table 58, and generates a code signature.
[0040] The distribution package generation unit 55 generates a distribution package, which will be described later. The program execution control unit 71 receives a process execution request from the authentication server 3, and controls the execution of a script file included in a distribution package added to the process execution request. The program execution control unit 71 may also control the execution of a file written in a compiler language.
[0041] The DID determination unit 72 refers to the DID information table 77 based on a process execution request to identify the security level of the data to be collected (hereinafter, referred to as data security level).
[0042] The key determination unit 73 refers to the security level table 78 based on the data security level to identify the private key for verifying the code signature. The signature verification execution unit 74 acquires the specified private key by referring to the key table 79, and executes verification of the code signature.
[0043] The execution right granting unit 75 grants execution rights to the script file included in the received distribution package based on the result of verification of the code signature. The data acquisition unit 76 acquires from the database 80 the data to be collected that is permitted based on the result of the verification of the code signature.
[0044] 5, the user information table 56 is a table that associates a user ID with a user security level. The user ID is information for identifying an operator. In the user information table 56 of this embodiment, for example, "ACompany" and "BCompany" are set as user IDs. The user IDs "ACompany" and "BCompany" correspond to "OEM" and "Third Party", respectively. The user IDs "ACompany" and "BCompany" correspond to security levels "1" and "2", respectively. In this embodiment, security level "1" is the highest level.
[0045] The DID information table 77 is a table that associates the data ID (hereinafter, DID) of the data to be collected with the security level. The data ID is information that identifies data. The data ID may be assigned to each data item, or may be assigned to a group or category of data items.
[0046] In the DID information table 77 of this embodiment, for example, "1", "2", and "3" are set as DIDs. DID "1" is information indicating that the data is related to a biometric device. DID "2" is information indicating that the data is related to vehicle location information. DID "3" is information indicating that the data is related to the operating status of a vehicle. DID "1", "2", and "3" are associated with security levels "1", "2", and "3", respectively.
[0047] The security level tables 57 and 78 are tables that associate security levels with key IDs. The key ID is information for identifying a private key. Security levels "1," "2," and "3" correspond to security policy information SP1, SP2, and SP3, respectively.
[0048] The security policy information SP1 indicates that reading and writing of the data of "biometric device", "location information" and "operational status" is permitted. Security policy information SP2 indicates that reading of "biometric device" data is prohibited, but reading of "location information" and "operational status" data is permitted.
[0049] Security policy information SP3 indicates that reading of the "biometric device" and "location information" data is prohibited, but reading of the "operational status" data is permitted.
[0050] The key tables 58 and 79 are tables that associate a key ID with a storage location of a private key. The private key is stored in an HSM provided in each of the signature generation unit 54 and the signature verification execution unit 74. HSM is an abbreviation for Hardware Security Module.
[0051] In the key tables 58 and 79 of this embodiment, the key IDs "1", "2", and "3" correspond to the HSM addresses "0x00000000", "0x11111111", and "0x22222222", respectively. In this embodiment, the encryption method of the private key stored at the address "0x00000000" is "RSA 512bit". The encryption method of the private key stored at the address "0x11111111" is "RSA 1024bit". The encryption method of the private key stored at the address "0x22222222" is "RSA 2048bit".
[0052] Next, a description will be given of the procedure of the server authentication process executed by the authentication server 3. The server authentication process is a process that is repeatedly executed while the control unit 31 is in operation. 6, the CPU 41 of the control unit 31 first determines in S10 whether or not a data collection request has been received via the browser 4. The data collection request includes one user authentication token, one or more DIDs of data to be collected, one or more pieces of timing information, one or more script files, one configuration file, and one vehicle ID.
[0053] The user authentication token includes the above-mentioned user ID and a password for accessing the authentication server 3 . The timing information is provided for each one or more script files, and indicates the timing for executing the corresponding script file.
[0054] The script file specifies one or more collection target data and one or more data collection conditions corresponding to each of the one or more collection target data in a script language. For example, the script file is set to determine whether or not a data collection condition is satisfied based on the status of the collection target vehicle (e.g., vehicle speed and vehicle position, etc.), and when the data collection condition is satisfied, to acquire the collection target data corresponding to the satisfied data collection condition from the ECU connected to the in-vehicle device 2 of the collection target vehicle via the CAN bus. The in-vehicle device 2 performs data communication with the ECU mounted on the vehicle according to UDS. UDS is an international standard for diagnostic communication, and is an abbreviation of Unified Diagnostic Services. In addition, when the CANID of the CAN frame corresponding to the collection target data can be identified, a CAN frame including a specific CANID may be acquired from the CAN frames transmitted to the CAN bus.
[0055] In the script file of this embodiment, the source code that specifies the data to be collected and the data collection conditions is described in a classified manner for each data to be collected that has the same DID. For example, the source code for which the data corresponding to DID "1" is the data to be collected, the source code for which the data corresponding to DID "2" is the data to be collected, and the source code for which the data corresponding to DID "3" is the data to be collected are described in a state where they are grouped together as separate groups.
[0056] The configuration file is a file in which the settings for executing the script file are described. The vehicle ID is information for identifying the target vehicle. Here, if a data collection request has not been received, the CPU 41 ends the server authentication process. On the other hand, if a data collection request has been received, the CPU 41 acquires a user authentication token from the received data collection request in S20. Furthermore, the CPU 41 acquires a user ID from the user authentication token in S30. Then, the CPU 41 checks whether the operator identified by the user ID is a "correct user" in S40. Specifically, the CPU 41 determines that the operator is a "correct user" when the user ID acquired in S30 exists in a registered user table in which the user ID of the "correct user" is registered. The registered user table is stored in the storage unit 33. Alternatively, the CPU 41 may determine whether the user is a user to which a valid security level has been assigned by referring to the user information table 56, and may determine that the user is a "correct user" if a valid security level has been assigned, and may determine that the user is not a "correct user" otherwise.
[0057] Next, in S50, the CPU 41 determines whether the operator who sent the data collection request via the browser 4 is a "valid user" based on the confirmation result in S40. If the operator is not a "valid user," the CPU 41 executes authentication failure processing in S60 and ends the server authentication processing. In the authentication failure processing, the CPU 41 discards the received data collection request, and further stores an audit log in the storage unit 33 indicating that the user authentication has failed.
[0058] Furthermore, if it is determined in S50 that the operator is a "valid user," then in S70 the CPU 41 refers to the user information table 56 to identify the user security level corresponding to the user ID acquired in S30.
[0059] Furthermore, in S80, the CPU 41 refers to the security level table 57 to identify the key ID corresponding to the user security level identified in S70. Furthermore, the CPU 41 generates a code signature in S90. Specifically, the CPU 41 first refers to the key table 58 to identify the storage location and encryption method of the private key corresponding to the user security level identified in S70. The CPU 41 then accesses the identified storage location of the HSM to obtain the private key corresponding to the user security level identified in S70. Next, the CPU 41 obtains a 256-bit hash value from the source code described in the script file included in the data collection request, for example, using a hash function of SHA-256. The CPU 41 then encrypts the obtained hash value with an encryption method corresponding to the key ID using the private key obtained from the HSM to generate a code signature. In the case of a compiler language, the hash value may be obtained from the source code or from the object code.
[0060] Next, the CPU 41 generates a distribution package in S100. As shown in Figure 7, the distribution package includes one manifest file, one or more script files included in the data collection request, and one configuration file included in the data collection request, and is generated by compressing these files together using a predetermined compression algorithm (e.g., gzip).
[0061] The manifest file includes an app ID, a usage DID, a code signature, and the above timing information. The app ID is information for identifying a script file included in the distribution package. The usage DID is a DID of the collection target data that is collected by executing the script file. The code signature is a code signature generated in S90. In this embodiment, one application ID exists for multiple script files. Also, multiple usage DIDs exist corresponding to one application ID. And the code signature is one signature for a collection of multiple script files. That is, one code signature corresponds to one application ID.
[0062] 6, when the process of S100 is completed, the CPU 41 transmits a process execution request to the in-vehicle device 2 of the vehicle identified by the vehicle ID in S110, and ends the server authentication process. The process execution request includes the distribution package generated in S100.
[0063] Next, a description will be given of the procedure of the vehicle authentication process executed by the in-vehicle device 2. The vehicle authentication process is a process that is repeatedly executed while the control unit 11 is in operation. When the vehicle authentication process is executed, the CPU 21 of the control unit 11 first determines whether or not a process execution request has been received from the authentication server 3 in S210, as shown in FIG.
[0064] If a process execution request has not been received, the CPU 21 ends the vehicle authentication process. On the other hand, if a process execution request has been received, the CPU 21 unpacks the distribution package included in the process execution request in S220.
[0065] Then, in S230, the CPU 21 refers to the DID information table 77 for each of all the used DIDs included in the manifest file to identify the data security level.
[0066] Then, in S240, the CPU 21 executes a signature authentication process, which will be described later. Next, in S250, the CPU 21 determines whether the authentication is successful or not based on the signature authentication result in S240. If there is a used DID that has been successfully authenticated, in S260, the CPU 21 executes a release process described later and ends the vehicle authentication process.
[0067] On the other hand, if authentication has failed for all of the used DIDs included in the manifest file, the CPU 21 executes an authentication failure process, which will be described later, in S270 and ends the vehicle authentication process.
[0068] Next, the procedure of the signature authentication process executed in S240 will be described. When the signature authentication process is executed, the CPU 21 first selects one unselected used DID from among all used DIDs included in the manifest file in S410, as shown in Fig. 9. Hereinafter, the used DID selected in S410 will be referred to as the selected DID.
[0069] Furthermore, the CPU 21 sets the data security level value LV to the value of the data security level of the selected DID in S430. Then, in S430, the CPU 21 determines whether or not the data security level value LV is greater than 0. If the data security level value LV is greater than 0, in S440, the CPU 21 identifies the key ID by referring to the security level table 78 based on the data security level of the selected DID.
[0070] Then, the CPU 21 generates a code signature in S450. Specifically, the CPU 21 first refers to the key table 79 to identify the storage location and encryption method of the private key corresponding to the key ID identified in S440. The CPU 41 then accesses the identified storage location of the HSM to obtain a private key corresponding to the data security level of the selected DID. Next, the CPU 21 obtains a 256-bit hash value from the source code described in the script file obtained by unzipping the distribution package in S220 (i.e., the source code of the script file corresponding to the application ID described in the manifest) using a hash function such as SHA-256. The CPU 21 then encrypts the obtained hash value with the encryption method corresponding to the key ID using the private key obtained from the HSM, thereby generating a code signature.
[0071] Next, in S460, CPU 21 compares the code signature obtained by unzipping the distribution package (i.e., the code signature written in the manifest) with the generated code signature. If the two code signatures match, CPU 21 determines that authentication has been successful, and if the two code signatures do not match, CPU 21 determines that authentication has failed.
[0072] When the process of S460 ends, the CPU 21 determines in S470 whether the authentication has been successful or not based on the signature authentication result in S460. If the authentication has failed, the CPU 21 subtracts 1 from the data security level value LV in S480 and proceeds to S430.
[0073] On the other hand, if the authentication is successful, the CPU 21 sets "authentication successful" for the selected DID in S490, and proceeds to S510. Also, in S430, if the data security level value LV is equal to or less than 0, the CPU 21 sets "authentication failed" for the selected DID in S500, and proceeds to S510.
[0074] When the process proceeds to S510, the CPU 21 judges whether or not all the used DIDs included in the manifest file have been selected in S410. If there are any used DIDs that have not been selected, the CPU 21 proceeds to S410. On the other hand, if all the used DIDs have been selected, the CPU 21 ends the signature authentication process.
[0075] Next, the procedure of the release process executed in S260 will be described. When the release process is executed, as shown in FIG. 10, first, in S610, the CPU 21 grants to the script execution environment the permission definition set in the security policy corresponding to the key ID of the private key used to generate the code signature that was successfully authenticated in the signature authentication process.
[0076] For example, if the key ID of the private key used to generate the code signature that was successfully authenticated in the signature authentication process is "1," the permission definition described in the security policy information SP1 is used. That is, the permission definition that allows reading and writing for the use DIDs "1," "2," and "3" is given to the script execution environment.
[0077] Furthermore, if the key ID of the private key used to generate the code signature that was successfully authenticated in the signature authentication process is "2", the permission definition described in the security policy information SP2 is used. That is, a permission definition that allows only reading for use DIDs "2" and "3" and prohibits reading of use DID "1" and writing to use DIDs "1", "2", and "3" is given to the script execution environment.
[0078] The script execution environment is an environment for executing a process defined by a source code written in a script file. In this embodiment, a sandbox is used as the script execution environment. The sandbox is a virtual environment that is constructed so that a program is executed in an area isolated from other programs on a computer and does not affect other programs even when a problem occurs.
[0079] Therefore, the CPU 21 first creates a sandbox from which all permissions have been deleted as a script execution environment, and then assigns the permission definition of the security policy corresponding to the successfully authenticated key ID to the created sandbox.
[0080] As described above, in the script file of this embodiment, the source code that specifies the collection target data and the data collection conditions is described by classifying the collection target data with the same DID. Therefore, the CPU 21 can assign permission definitions to each group of source code classified by DID in the script file.
[0081] Next, in S620, CPU 21 schedules the script and transitions it to an execution state. Specifically, CPU 21 sets execution timing for one or more script files included in the distribution package based on timing information included in the manifest file. CPU 21 then executes one or more script files in the sandbox created in S610.
[0082] Then, in S630, the CPU 21 stores in the storage unit 13 an audit log describing the used DIDs for which authentication has been successful and the used DIDs for which authentication has failed, and ends the release process. Next, the authentication failure process executed in S270 will be described.
[0083] When the authentication failure process is executed, as shown in FIG. 11, first in S710, the CPU 21 discards the code signature generated in S450. In addition, in S720, the CPU 21 deletes the distribution package that was decompressed in S220. In addition, in S730, the CPU 21 transmits to the authentication server 3 an error code indicating that the authentication has failed.
[0084] Furthermore, in S740, the CPU 21 transmits an authentication failure signal indicating that the authentication has failed to the CAN bus. As a result, the ECUs 111, 112, 113, and 114 connected to the in-vehicle device 2 via the CAN bus receive the authentication failure signal. Then, for example, the ECU 114 that has received the authentication failure signal executes a process for displaying on a meter that the authentication has failed.
[0085] Next, in S750, the CPU 21 stores an audit log indicating that the authentication has failed in the storage unit 13, and ends the authentication failure process. The authentication system 1 configured in this manner includes a plurality of vehicle-mounted devices 2 and an authentication server 3, and performs authentication in response to an access request requesting access to at least one of the vehicle-mounted devices 2.
[0086] When the authentication server 3 receives the script file from the operator, it determines a user security level for access to the collection target data based on the type of the operator. The script file is a program that specifies at least one collection target data and at least one collection condition for each of the at least one collection target data, and transmits the collection target data corresponding to the collection condition to the authentication server 3 when the collection condition is established.
[0087] The authentication server 3 generates a code signature (hereinafter, referred to as a first code signature) by encrypting a hash value of the source code of the script file with a private key that is set in advance according to the user security level.
[0088] When the in-vehicle device 2 receives the script file from the authentication server 3, the in-vehicle device 2 determines a data security level regarding access to the collection target data for each type of collection target data based on at least one type of collection target data.
[0089] The vehicle-mounted device 2 generates a code signature (hereinafter, second code signature) for each type of data to be collected by encrypting a hash value of the source code of the script file with a private key that is preset according to the data security level.
[0090] The vehicle-mounted device 2 uses the first code signature and the second code signature to perform authentication for each type of collection target data.
[0091] If the authentication is successful, the in-vehicle device 2 permits the collection of collection target data by executing the script file, and if the authentication is unsuccessful, prohibits the collection of collection target data by executing the script file. Specifically, the in-vehicle device 2 permits the collection of collection target data corresponding to the type of collection target data for which authentication is determined to have been successful, among the multiple collection target data.
[0092] Such an authentication system 1 can perform authentication once before executing a received script file, and can transmit collection target data corresponding to the collection conditions defined in the script file from the in-vehicle device 2 to the authentication server 3 each time the collection conditions are met. In other words, the authentication system 1 eliminates the need for the operator to transmit an access request to the authentication server 3 each time the collection conditions are met, and eliminates the need to perform authentication each time the collection conditions are met. This allows the authentication system 1 to reduce the processing load of authentication for collecting vehicle data.
[0093] Furthermore, since the authentication system 1 performs authentication using a code signature generated by encryption with a private key, it is possible for each vehicle to verify whether the operator has legitimate access rights to the data to be collected.
[0094] In addition, the source code of the script file is written in a script language and classified for each collection target data of the same type. Such an authentication system 1 can reduce the processing load for granting permission definitions. Furthermore, the authentication server 3 generates a first code signature by encrypting a hash value of the source code of the script file. Furthermore, the in-vehicle device 2 generates a second code signature by encrypting a hash value of the source code of the script file. This allows the authentication system 1 to reduce the data size of the generated first and second code signatures.
[0095] Furthermore, when it is determined that the authentication has failed, the in-vehicle device 2 notifies the target vehicle of the failure of the authentication. In this way, when the authentication has failed, the authentication system 1 can make the occupant of the target vehicle aware of the failure of the authentication.
[0096] In the embodiment described above, the authentication server 3 corresponds to the server, S70 corresponds to the process performed by the first security level determination unit, and S80 and S90 correspond to the processes performed by the first signature generation unit.
[0097] Moreover, S230 corresponds to the processing performed by a second security level determination unit, S450 corresponds to the processing performed by a second signature generation unit, S420, S430, S460, and S480 correspond to the processing performed by an authentication unit, and S490 and S500 correspond to the processing performed by an executive control unit.
[0098] In addition, the operator corresponds to the access requester, the script file corresponds to the data collection program, the user security level corresponds to the first security level, the private key obtained in S90 corresponds to the first encryption key, the data security level corresponds to the second security level, and the private key obtained in S450 corresponds to the second encryption key. Moreover, the hash value of the source code and the hash value of the object code correspond to values related to the program.
[0099] Moreover, S100 and S110 correspond to the processing performed by a package transmitting unit, DID corresponds to data type information, S610 and S620 correspond to the processing performed by a permission executing unit, and S740 corresponds to the processing performed by an authentication notifying unit.
[0100] Although one embodiment of the present disclosure has been described above, the present disclosure is not limited to the above embodiment and can be implemented in various modified forms. [Variation 1] In the above embodiment, a permission definition is given to the collection target data corresponding to a successfully authenticated DID. However, if there is a DID that has failed authentication, permission definition may not be given to all collection target data (i.e., execution of the script file may be prohibited). Since such an authentication system 1 can end authentication at the time when a failed authentication DID is found, the authentication processing load can be reduced.
[0101] [Variation 2] In the above embodiment, authentication is performed for all the used DIDs included in the manifest file. However, it is also possible to select one used DID with the highest data security level from all the used DIDs included in the manifest file, and perform authentication for the selected one used DID.
[0102] For example, if the data security level is "2" or "3" for all use DIDs included in the manifest file, one use DID with a data security level of "2" is selected. Then, if authentication is successful for the selected use DID (i.e., the user security level is "1" or "2"), permission definitions are granted for all use DIDs included in the manifest file. On the other hand, if authentication is unsuccessful for the selected use DID (i.e., the user security level is "3"), permission definitions are not granted for all use DIDs included in the manifest file.
[0103] Such an authentication system 1 can reduce the processing load of authentication. [Variation 3] In the above embodiment, when authentication fails, an audit log indicating that authentication has failed is stored. However, when the number of times authentication has failed within a preset determination period (e.g., three minutes) exceeds a preset determination count (e.g., three times), the same access request may not be accepted until a preset designated time (e.g., three minutes) has elapsed. This enables the authentication system 1 to prevent the occurrence of a situation in which vehicle data is illegally accessed by a DoS attack. DoS is an abbreviation for Denial of Service. [Variation 4] In the above embodiment, the manifest file of the distribution package added to the process execution request contains the application ID, the usage DID, the code signature, and the timing information. However, the in-car device 2 may receive the information contained in the manifest file as a parameter of the process execution request.
[0104] The control unit 11, 31 and the method described in the present disclosure may be realized by a dedicated computer provided by configuring a processor and a memory programmed to execute one or more functions embodied in a computer program. Alternatively, the control unit 11, 31 and the method described in the present disclosure may be realized by a dedicated computer provided by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the control unit 11, 31 and the method described in the present disclosure may be realized by one or more dedicated computers configured by a combination of a processor and a memory programmed to execute one or more functions and a processor configured with one or more hardware logic circuits. In addition, the computer program may be stored in a computer-readable non-transitory tangible recording medium as instructions executed by a computer. The method for realizing the functions of each unit included in the control unit 11, 31 does not necessarily need to include software, and all of the functions may be realized using one or more hardware.
[0105] In the above embodiments, multiple functions of one component may be realized by multiple components, or one function of one component may be realized by multiple components. Also, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Also, part of the configuration of the above embodiments may be omitted. Also, at least part of the configuration of the above embodiments may be added to or substituted for the configuration of another of the above embodiments.
[0106] In addition to the above-mentioned in-vehicle device 2 and authentication server 3, the present disclosure can also be realized in various forms, such as a system including the in-vehicle device 2 and the authentication server 3 as components, an authentication program for causing a computer to function as the in-vehicle device 2 and the authentication server 3, a non-transient physical recording medium such as a semiconductor memory on which this authentication program is recorded, and an authentication method. [Explanation of symbols]
[0107] 1... authentication system, 2... in-vehicle device, 3... authentication server
Claims
1. A plurality of on-board devices (2) mounted on a plurality of vehicles, respectively, and configured to transmit vehicle data relating to the vehicle in which the on-board devices are mounted; a server (3) that is installed outside the plurality of vehicles and configured to acquire the vehicle data from the plurality of on-board devices by performing data communication with the plurality of on-board devices; An authentication system (1) for performing authentication for an access request for accessing at least one of a plurality of the in-vehicle devices, comprising: The server, a first security level determination unit (S70) configured to determine a first security level regarding access to the collection target data based on a type of the access request source when a data collection program is received from the access request source, the data collection program defining at least one collection target data, which is at least one of the vehicle data to be collected by an access request source that has made the access request, and at least one collection condition for each of the at least one collection target data, and causing the collection target data corresponding to the collection condition to be transmitted to the server when the collection condition is established; a first signature generating unit (S80, S90) configured to generate a first code signature by encrypting a value related to the program of the data collection program with a first encryption key preset according to the first security level, The plurality of in-vehicle devices a second security level determination unit (S230) configured to determine a second security level regarding access to the collection target data for each of the types of collection target data based on at least one type of the collection target data when the data collection program is received from the server; a second signature generating unit (S450) configured to generate a second code signature for each of the types of data to be collected by encrypting a value related to the program of the data collection program with a second encryption key that is preset according to the second security level; an authentication unit (S420, S430, S460, S480) configured to perform the authentication for each of the types of the collection target data by using the first code signature and the second code signature; an execution control unit (S490, S500) configured to permit collection of the collection target data by executing the data collection program when the authentication by the authentication unit is successful, and to prohibit collection of the collection target data by executing the data collection program when the authentication is unsuccessful; An authentication system comprising:
2. 2. The authentication system according to claim 1, The at least one collection target data is a plurality of collection target data, The execution control unit is configured to permit collection of the collection target data corresponding to the type of the collection target data for which the authentication has been determined to have been successful, among the plurality of collection target data.
3. 2. The authentication system according to claim 1, The at least one collection target data is a plurality of collection target data, The execution control unit is configured to prohibit collection of all of the plurality of collection target data when there is a type of collection target data for which the authentication is determined to have failed.
4. 4. The authentication system according to claim 3, An authentication system configured such that the second signature generation unit generates the second code signature by encrypting with the second encryption key of the second security level, which is the highest level among the second security levels determined by the second security level determination unit.
5. The authentication system according to any one of claims 1 to 4, The at least one collection target data is a plurality of collection target data, An authentication system in which the data collection program is written using a script language and classified for each of the collection target data of the same type.
6. The authentication system according to any one of claims 1 to 5, The server, An authentication system comprising: a package transmission unit (S100, S110) configured to generate a distribution package including the data collection program, data type information indicating the type of data to be collected, and the first code signature, and to transmit the generated distribution package to the in-vehicle device of the vehicle that is the subject of the access request.
7. The authentication system according to any one of claims 1 to 6, The authentication system, wherein the value associated with the program is a hash value of the program.
8. The authentication system according to any one of claims 1 to 7, An authentication system comprising: an authorization execution unit (S610, S620) configured to execute the data collection program in the vehicle equipped with the on-board device when the authentication unit determines that the authentication has been successful.
9. The authentication system according to any one of claims 1 to 8, An authentication system comprising: an authentication notification unit (S740) configured to notify the vehicle in which the on-board device is mounted of a failure of the authentication when the authentication unit determines that the authentication has failed.
10. A plurality of on-board devices (2) mounted on a plurality of vehicles, respectively, and configured to transmit vehicle data relating to the vehicle in which the on-board devices are mounted; a server (3) that is installed outside the plurality of vehicles and configured to acquire the vehicle data from the plurality of on-board devices by performing data communication with the plurality of on-board devices; The server of an authentication system (1) for performing authentication for an access request for accessing at least one of the plurality of in-vehicle devices, a first security level determination unit (S70) configured to determine a first security level regarding access to the collection target data based on a type of the access request source when a data collection program is received from the access request source, the data collection program defining at least one collection target data, which is at least one of the vehicle data to be collected by an access request source that has made the access request, and at least one collection condition for each of the at least one collection target data, and causing the collection target data corresponding to the collection condition to be transmitted to the server when the collection condition is established; a first signature generating unit (S80, S90) configured to generate a first code signature by encrypting a value related to the program of the data collection program with a first encryption key preset according to the first security level; A server comprising:
11. A plurality of on-board devices (2) mounted on a plurality of vehicles, respectively, and configured to transmit vehicle data relating to the vehicle in which the on-board devices are mounted; a server (3) that is installed outside the plurality of vehicles and configured to acquire the vehicle data from the plurality of on-board devices by performing data communication with the plurality of on-board devices, and that is further configured to specify at least one collection target data, which is at least one of the vehicle data to be collected by an access request source that has made an access request to at least one of the plurality of on-board devices, and at least one collection condition for each of the at least one collection target data, and that, when the collection condition is established, receives from the access request source a data collection program that is a program for transmitting the collection target data corresponding to the collection condition, determine a first security level regarding access to the collection target data based on a type of the access request source, and generate a first code signature by encrypting a value related to the program of the data collection program with a first encryption key that is preset according to the first security level; The in-vehicle device of an authentication system (1) that performs authentication for the access request, a second security level determination unit (S230) configured to determine a second security level regarding access to the collection target data for each of the types of collection target data based on at least one type of the collection target data when the data collection program is received from the server; a second signature generating unit (S450) configured to generate a second code signature for each of the types of data to be collected by encrypting a value related to the program of the data collection program with a second encryption key that is preset according to the second security level; an authentication unit (S420, S430, S460, S480) configured to perform the authentication for each of the types of the collection target data by using the first code signature and the second code signature; an execution control unit (S490, S500) configured to permit collection of the collection target data by executing the data collection program when the authentication by the authentication unit is successful, and to prohibit collection of the collection target data by executing the data collection program when the authentication is unsuccessful; An in-vehicle device comprising:
12. A plurality of on-board devices (2) mounted on a plurality of vehicles, respectively, and configured to transmit vehicle data relating to the vehicle in which the on-board devices are mounted; a server (3) that is installed outside the plurality of vehicles and configured to acquire the vehicle data from the plurality of on-board devices by performing data communication with the plurality of on-board devices; An authentication method executed by a server of an authentication system (1) for performing authentication for an access request for accessing at least one of a plurality of in-vehicle devices, comprising: a data collection program that specifies at least one collection target data, which is at least one of the vehicle data to be collected by the access request source that has made the access request, and at least one collection condition for each of the at least one collection target data, and that causes the collection target data corresponding to the collection condition to be transmitted to the server when the collection condition is established, when the data collection program is received from the access request source, a first security level regarding access to the collection target data is determined based on a type of the access request source; an authentication method for generating a first code signature by encrypting a value associated with the program of the data collection program with a first encryption key preset according to the first security level;
13. A plurality of on-board devices (2) mounted on a plurality of vehicles, respectively, and configured to transmit vehicle data relating to the vehicle in which the on-board devices are mounted; a server (3) that is installed outside the plurality of vehicles and configured to acquire the vehicle data from the plurality of on-board devices by performing data communication with the plurality of on-board devices; An authentication system (1) for performing authentication for an access request for accessing at least one of the plurality of vehicle-mounted devices, a first security level determination unit (S70) configured to determine a first security level regarding access to the collection target data based on a type of the access request source when a data collection program is received from the access request source, the data collection program defining at least one collection target data, which is at least one of the vehicle data to be collected by the access request source that has made the access request, and at least one collection condition for each of the at least one collection target data, and causing the collection target data corresponding to the collection condition to be transmitted to the server when the collection condition is established; a first signature generating unit (S80, S90) configured to generate a first code signature by encrypting a value related to the program of the data collection program with a first encryption key preset according to the first security level; Certification program to function as.
14. A plurality of on-board devices (2) mounted on a plurality of vehicles, respectively, and configured to transmit vehicle data relating to the vehicle in which the on-board devices are mounted; a server (3) that is installed outside the plurality of vehicles and configured to acquire the vehicle data from the plurality of on-board devices by performing data communication with the plurality of on-board devices; An authentication program executed by an in-vehicle device of an authentication system (1) for performing authentication for an access request requesting access to at least one of a plurality of in-vehicle devices, comprising: The server, a first security level determination unit (S70) configured to determine a first security level regarding access to the collection target data based on a type of the access request source when a data collection program is received from the access request source, the data collection program defining at least one collection target data, which is at least one of the vehicle data to be collected by an access request source that has made the access request, and at least one collection condition for each of the at least one collection target data, and causing the collection target data corresponding to the collection condition to be transmitted to the server when the collection condition is established; a first signature generating unit (S80, S90) configured to generate a first code signature by encrypting a value related to the program of the data collection program with a first encryption key preset according to the first security level, The authentication program causes a computer of the vehicle-mounted device to a second security level determination unit (S230) configured to determine, when receiving the data collection program from the server, a second security level regarding access to the collection target data for each of the types of the collection target data based on at least one of the types of the collection target data; a second signature generating unit (S450) configured to generate a second code signature for each of the types of data to be collected by encrypting a value related to the program of the data collection program with a second encryption key preset according to the second security level; An authentication unit (S420, S430, S460, S480) configured to perform the authentication for each of the types of the collection target data by using the first code signature and the second code signature; and an execution control unit (S490, S500) configured to permit collection of the collection target data by executing the data collection program when the authentication by the authentication unit is successful, and to prohibit collection of the collection target data by executing the data collection program when the authentication is unsuccessful; Certification program to function as.
Citation Information
Patent Citations
Data acquisition method and device, storage medium and system
CN113256845A
Control system, server device, method for control, and computer program
JP2018116544A
Update management method, update management device, and control program
JP2020048203A
Vehicle maintenance system, maintenance server device, management server device, on-vehicle device, maintenance tool, computer program, and vehicle maintenance method
JP2020088836A
In-vehicle recording device and information recording method
JP2021100153A