Vehicle-mounted device, program, and information processing method
The in-vehicle device ensures efficient security verification of processing units by using a challenge-response method, addressing the lack of security measures in existing devices and preventing unauthorized access.
Patent Information
- Application Number
- JP2022030127
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-02-28
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-02-28
AI Technical Summary
Existing in-vehicle devices lack efficient security measures for microcontrollers, particularly in ensuring the integrity and security of processing units that communicate with external devices.
An in-vehicle device with a first processing unit connected to the in-vehicle network and a second processing unit, where the first unit performs security verification on the second unit using methods like challenge-response authentication, ensuring integrity and detecting unauthorized access.
Efficiently secures the in-vehicle processing units by verifying their integrity and preventing unauthorized access, maintaining network security and preventing unauthorized control of vehicle systems.
Smart Images

Figure 0007707964000001 
Figure 0007707964000002 
Figure 0007707964000003
Abstract
Description
Technical Field
[0001] The present invention relates to an in-vehicle device, a program, and an information processing method.
Background Art
[0002] An electronic control device mounted on a vehicle and including a plurality of microcontrollers and capable of detecting an abnormality in a communication bus has been disclosed (for example, Patent Document 1). The electronic control device of Patent Document 1 is one of a plurality of nodes connected to a communication bus, and includes a first microcontroller and a second microcontroller that receive a transmission signal flowing through the communication bus and transmit a transmission signal to the communication bus. The transmission signal to be transmitted to the communication bus is transmitted to each microcontroller without passing through the communication bus, and each microcontroller is configured to receive the transmission signal.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, in the electronic control device of Patent Document 1, there is a problem that the microcontrollers included in the electronic control device are not considered in terms of efficiently performing security measures.
[0005] An object of the present disclosure is to provide an in-vehicle device or the like that can efficiently perform security measures on a mounted processing unit.
Means for Solving the Problems
[0006] An in-vehicle device according to an aspect of the present disclosure is an in-vehicle device mounted on a vehicle having an in-vehicle network, and includes a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit. The first processing unit performs a security verification on the second processing unit.
Effect of the Invention
[0007] According to an aspect of the present disclosure, it is possible to provide an in-vehicle device or the like that efficiently performs security measures on a mounted processing unit.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Modes for Carrying Out the Invention
[0009] [Description of Embodiments of the Present Disclosure] First, embodiments of the present disclosure will be listed and described. Further, at least a part of the embodiments described below may be arbitrarily combined.
[0010] (1) An in-vehicle device according to an aspect of the present disclosure is an in-vehicle device mounted on a vehicle having an in-vehicle network, and includes a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit. The first processing unit performs a security verification on the second processing unit.
[0011] In this aspect, the in-vehicle device includes a first processing unit and a second processing unit, and each of these processing units is constituted by, for example, a separate microcomputer or the like. The first processing unit connected to the in-vehicle network performs security verification on the second processing unit and exhibits a monitoring function for the second processing unit. Therefore, when the second processing unit communicates with an out-vehicle device located outside the vehicle, such as an OTA server or a diagnostic device, even if unauthorized access or data is transmitted from outside to the second processing unit, the first processing unit can ensure the integrity (normality) of the second processing unit by performing security verification on the second processing unit. Thus, even when a plurality of microcomputers or the like constituting the first processing unit and the second processing unit are mounted on a single in-vehicle device, the first processing unit connected to the in-vehicle network can efficiently perform security verification on the second processing unit (other processing unit) that is not directly connected to the in-vehicle network.
[0012] (2) In the in-vehicle device according to one aspect of the present disclosure, the first processing unit acquires response data from the second processing unit for the security verification, and determines whether the second processing unit is normal based on the acquired response data.
[0013] In this aspect, when the first processing unit performs security verification on the second processing unit, it acquires response data from the second processing unit and determines whether the second processing unit is normal based on the result of the security verification of the response data. For example, the first processing unit may store in advance in the storage unit a hash value generated based on the response data, and compare the pre-stored hash value (correct value) with the hash value generated (converted) based on the response data acquired from the second processing unit for security verification, so as to determine whether the acquired response data is normal or abnormal. When the response data is normal, the first processing unit determines that the second processing unit is normal; when the response data is abnormal, the first processing unit determines that the second processing unit is abnormal. Even when the response data cannot be acquired, the first processing unit may determine that the second processing unit is abnormal. By using the result of the security verification of the response data acquired from the second processing unit in this way, the security verification of the second processing unit can be efficiently performed.
[0014] (3) In the in-vehicle device according to one aspect of the present disclosure, the first processing unit performs security verification on the second processing unit using the challenge-response method.
[0015] In this aspect, the first processing unit uses the challenge-response method to randomly generate challenge information and send it to the second processing unit, and generate response information corresponding to the challenge information. The second processing unit generates (converts) a hash value from the challenge information output from the first processing unit and the password set in the second processing unit to generate response information, and outputs it to the first processing unit. The first processing unit compares the response information output from the second processing unit with the response information generated by itself from the challenge information, and if they are the same, it succeeds in authentication (challenge-response authentication) to perform security verification. By using the challenge-response method in this way, the security verification of the second processing unit can be efficiently performed.
[0016] (4) In one aspect of the present disclosure, in the in-vehicle device, in response to a verification request from the second processing unit, the first processing unit performs a security verification on the second processing unit.
[0017] In this aspect, the second processing unit makes a verification request (outputs an authentication request) to the first processing unit, for example, periodically or regularly. The first processing unit performs a security verification on the second processing unit in response to the verification request from the second processing unit. Thereby, the first processing unit can use the verification request from the second processing unit as a trigger to start the security verification, eliminating the need for processing related to scheduling or timing control when performing the security verification on the second processing unit, and reducing the load on the first processing unit. Therefore, even when there are a plurality of second processing units (other processing units) for which the first processing unit is responsible for security verification, by responding to the verification requests from these plurality of second processing units, the security verification on the second processing unit can be efficiently performed.
[0018] (5) In one aspect of the present disclosure, in the in-vehicle device, when the first processing unit does not acquire a verification request from the second processing unit for a predetermined period, the second processing unit determines that the second processing unit is abnormal.
[0019] In this aspect, when the second processing unit is configured to periodically output a verification request to the first processing unit, if the first processing unit does not acquire a verification request from the second processing unit for a predetermined period, it is assumed that the second processing unit is in an abnormal state due to, for example, unauthorized access from outside the vehicle (security attack). Even in such a case, since the first processing unit determines that the second processing unit is abnormal because it has not acquired a verification request from the second processing unit for a predetermined period, the security verification on the second processing unit can be efficiently performed.
[0020] (6) The in-vehicle device according to one aspect of the present disclosure is such that the second processing unit acquires out-vehicle communication data from an external device outside the vehicle, and the first processing unit and the second processing unit are connected by a data communication line through which the out-vehicle communication data flows and a verification communication line through which data for security verification flows.
[0021] In this aspect, as a communication circuit between the first processing unit and the second processing unit, a parallel circuit including a data communication line and a verification communication line is configured and duplicated. Thereby, security verification using the verification communication line can be performed without affecting relay processing or the like using the data communication line.
[0022] (7) The in-vehicle device according to one aspect of the present disclosure is such that when the first processing unit determines that the second processing unit is abnormal based on the result of the security verification, the first processing unit performs processing for deactivating the second processing unit.
[0023] In this aspect, when the first processing unit determines that the second processing unit is abnormal based on the result of the security verification, the first processing unit deactivates the second processing unit, thereby substantially disconnecting the second processing unit in an abnormal state from the in-vehicle network and preventing the control of the vehicle (vehicle system) from being affected by the second processing unit. When deactivating the second processing unit, the first processing unit may cut off the power supply to the second processing unit, forcibly stop (shutdown) the second processing unit, cut off the data communication line with the second processing unit, or invalidate the communication port (in-vehicle communication unit) connected to the data communication line.
[0024] (8) The in-vehicle device according to one aspect of the present disclosure is such that when the first processing unit determines that the second processing unit is abnormal based on the result of the security verification, the first processing unit performs a recovery process for recovering the second processing unit.
[0025] In this aspect, when the first processing unit determines that the second processing unit is abnormal based on the result of security verification, the first processing unit performs a recovery process such as cutting off the power supply to the second processing unit and restarting the second processing unit by re-supplying power, and outputting a recovery signal to the second processing unit. As a result, for example, the second processing unit that has entered an abnormal state due to unauthorized access from outside the vehicle (security attack) can be transitioned (recovered) to a normal state. The recovery signal for the second processing unit may be, for example, a signal including a reboot, initialization of the second processing unit, or a program pre-stored in the storage unit of the first processing unit and an execution instruction for the program. If the result of the security verification (verification result) for the second processing unit continues to be abnormal even though the first processing unit has output the recovery signal to the second processing unit a plurality of times (a predetermined number of times), the first processing unit may deactivate the second processing unit.
[0026] (9) In the in-vehicle device according to one aspect of the present disclosure, a plurality of in-vehicle ECUs are connected to the in-vehicle network, and the first processing unit relays the data acquired from the second processing unit to the in-vehicle ECU via the in-vehicle network.
[0027] In this aspect, since the first processing unit relays the data acquired by the second processing unit to the in-vehicle ECU via the in-vehicle network, the in-vehicle device can function as a relay device. In addition, a plurality of communication cables (such as CAN buses) constituting the in-vehicle network may be connected to the first processing unit, and the first processing unit may relay the data transmitted and received between the in-vehicle ECUs connected to each of these plurality of communication cables.
[0028] (10) An information processing method according to one aspect of the present disclosure is executed by a computer mounted on a vehicle having an in-vehicle network, the computer including a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit, and the first processing unit performs a security verification on the second processing unit.
[0029] In this aspect, an information processing method can be provided to cause a computer to function as an in-vehicle device that efficiently performs security measures on a mounted processing unit.
[0030] (11) A program according to an aspect of the present disclosure is mounted on a vehicle having an in-vehicle network, and causes a computer including a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit to perform security verification on the second processing unit by the first processing unit.
[0031] In this aspect, a program can be provided to cause a computer to function as an in-vehicle device that efficiently performs security measures on a mounted processing unit.
[0032] [Details of Embodiments of the Present Disclosure] The present disclosure will be specifically described based on the drawings showing its embodiments. The in-vehicle system S according to the embodiment of the present disclosure will be described below with reference to the drawings. Note that the present disclosure is not limited to these examples, and is intended to be defined by the claims and to include all modifications within the meaning and scope equivalent to the claims.
[0033] (Embodiment 1) Hereinafter, embodiments will be described with reference to the drawings. FIG. 1 is a schematic diagram illustrating the system configuration of the in-vehicle system S according to Embodiment 1. FIG. 2 is a block diagram illustrating the internal configuration of the in-vehicle device 2 included in the in-vehicle system S. The in-vehicle system S includes an in-vehicle device 2 and a plurality of in-vehicle ECUs 4 mounted on a vehicle C, and these in-vehicle device 2 and plurality of in-vehicle ECUs 4 are communicably connected via an in-vehicle network 3 constituted by a communication cable 31 such as a CAN bus. An actuator 5 (see FIG. 5) such as a motor or an in-vehicle device such as a lamp or a sensor is connected to the in-vehicle ECU 4. The in-vehicle device 2 may function as a relay device that relays data transmitted and received between a plurality of in-vehicle ECUs 4 connected to the in-vehicle network 3.
[0034] An in-vehicle communication device 1 for communicating via an external network is connected to the in-vehicle device 2. The in-vehicle device 2 communicates with an external server 100 or a mobile terminal via the in-vehicle communication device 1 and the external network. The external server 100 is a computer such as a server connected to an external network such as the Internet or a public switched telephone network, and may be an OTA (Over The Air) server that provides an update program.
[0035] The in-vehicle communication device 1 includes a wireless communication unit (not shown) and a communication I / F for communicating with the in-vehicle device 2. The wireless communication unit is a communication device for performing wireless communication using a mobile communication protocol such as 4G, LTE (Long Term Evolution / registered trademark), 5G, or WiFi (registered trademark), and transmits and receives data to and from the external server 100 via an antenna 11 connected to the in-vehicle communication unit 223. The communication I / F may be a communication interface for serial communication with the in-vehicle device 2, or a CAN transceiver for CAN communication. Communication between the in-vehicle communication device 1 and the external server 100 is performed via an external network such as a public switched telephone network or the Internet. In this embodiment, the in-vehicle communication device 1 is a separate device from the in-vehicle device 2, and these devices are communicably connected by a communication I / F or the like, but the present invention is not limited thereto. The in-vehicle communication device 1 may be incorporated in the in-vehicle device 2 as a component of the in-vehicle device 2. In this case, the second processing unit 22 (external microcomputer) may have the function of the in-vehicle communication device 1.
[0036] The in-vehicle device 2 may be connected to a diagnostic device 101 used during inspections of the vehicle C or the like. Further, the in-vehicle device 2 may be connected to an LF antenna and an RF antenna and receive signals transmitted from a smart key. In this way, an external device located outside the vehicle C is directly or indirectly connected to the in-vehicle device 2, and the in-vehicle device 2 also functions as a relay device that relays data (off-vehicle communication data) output (transmitted) from the external device to an in-vehicle ECU 4 connected to the in-vehicle network 3. That is, the in-vehicle device 2 performs data relay processing between in-vehicle ECUs 4 within the in-vehicle network 3 and data relay processing between an external device located outside the vehicle C and these in-vehicle ECUs 4.
[0037] The in-vehicle device 2 that functions as a relay device in this way includes a first processing unit 21 connected to the in-vehicle network 3 and a second processing unit 22 that is not directly connected to the in-vehicle network 3 and receives data transmitted from an external device. When each of the first processing unit 21 and the second processing unit 22 is configured by, for example, a microcomputer, the first processing unit 21 corresponds to an in-vehicle microcomputer, and the second processing unit 22 corresponds to an out-of-vehicle microcomputer.
[0038] These first processing unit 21 (in-vehicle microcomputer) and second processing unit 22 (out-of-vehicle microcomputer) are implemented with a security function using, for example, a challenge-response method. The first processing unit 21 monitors the state of the second processing unit 22 by periodically performing a security verification (security treatment) on the second processing unit 22 using the security function. In the data flow direction from outside the vehicle C by the external device, the first processing unit 21 (in-vehicle microcomputer) located on the in-vehicle side (downstream side) performs a security treatment on the second processing unit 22 (out-of-vehicle microcomputer) on the out-of-vehicle side (upstream side), thereby ensuring the integrity of the second processing unit 22 (out-of-vehicle microcomputer) and providing resistance to security attacks from outside the vehicle.
[0039] The in-vehicle device 2 integrates a plurality of segments, such as in-vehicle devices like the control system ECU, in-vehicle devices like the safety system ECU, and body in-vehicle devices like the BCU (Body Control Unit), and relays communications between these in-vehicle devices. The in-vehicle device 2 may be, for example, a gateway or an Ethernet switch, and may function as a layer 2 switch, a layer 3 switch, or a CAN gateway. Or, the in-vehicle device 2 may be constituted by a central control device such as a vehicle computer, and may be an integrated ECU that controls the entire vehicle C.
[0040] The in-vehicle device 2 includes a first processing unit 21 and a second processing unit 22. The second processing unit 22 located on the outer side of the vehicle receives data transmitted from an external device such as the external server 100 or the diagnostic device 101, and transmits data to these external devices. The first processing unit 21 located on the inner side of the vehicle, in addition to relaying the data transmitted and received between the in-vehicle ECUs 4 connected to the in-vehicle network 3, relays the data from the external device received by the second processing unit 22 to the in-vehicle ECU 4, that is, performs relay processing between the in-vehicle ECU 4 and the second processing unit 22.
[0041] In the present embodiment, the number of the first processing units 21 directly connected to the in-vehicle network 3 and located on the inner side of the vehicle is one, but it is not limited thereto, and there may be a plurality of the first processing units 21 (inner side processing units) directly connected to the in-vehicle network 3. In the present embodiment, the number of the second processing units 22 not directly connected to the in-vehicle network 3 and located on the outer side of the vehicle is one, but it is not limited thereto, and there may be a plurality of the second processing units 22 (outer side processing units) not directly connected to the in-vehicle network 3 and located on the outer side of the vehicle. In this case, the first processing unit 21 may perform security verification for each of the plurality of second processing units 22.
[0042] The first processing unit 21 and the second processing unit 22 are communicably connected by a data communication line 201 and a verification communication line 203. That is, a parallel circuit including the data communication line 201 and the verification communication line 203 is configured as a communication circuit between the first processing unit 21 and the second processing unit 22, and the in-vehicle device 2 has such a duplicated communication circuit.
[0043] The first processing unit 21 is constituted by, for example, a microcomputer, and includes a first control unit 211, a first storage unit 212, and an in-vehicle communication unit 213. The first control unit 211 is constituted by, for example, a CPU (Central Processing Unit), an MPU (Micro Processing Unit), or the like, and performs various control processes, arithmetic processes, and the like by reading and executing a program P (program product) and data stored in advance in the first storage unit 212.
[0044] The first storage unit 212 is constituted by, for example, a volatile memory element such as a RAM (Random Access Memory) or a non-volatile memory element such as a ROM (Read Only Memory), an EEPROM (Electrically Erasable Programmable ROM), or a flash memory, and stores in advance a program P (program product) and data referred to during processing. The program P (program product) stored in the first storage unit 212 may store the program P (program product) read from a recording medium M readable by the in-vehicle device 2. Alternatively, the program P (program product) may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the first storage unit 212.
[0045] The in-vehicle communication unit 213 is constituted by, for example, a CAN transceiver and is an input / output interface using the communication protocol of CAN. Alternatively, the in-vehicle communication unit 213 may be constituted by an Ethernet PHY and be an input / output interface using the communication protocol of Ethernet (Ethernet / Registered Trademark). The first processing unit 21 is communicably connected to an in-vehicle ECU 4 connected to the in-vehicle network 3 via the in-vehicle communication unit 213.
[0046] The second processing unit 22 is constituted by, for example, a microcomputer and includes a second control unit 221, a second storage unit 222, and an out-vehicle communication unit 223. The second control unit 221 is constituted by, for example, a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), etc., and reads and executes a program P (program product) and data pre-stored in the second storage unit 222 to perform various control processes, arithmetic processes, etc.
[0047] The second storage unit 222 is constituted by, for example, a volatile memory element such as a RAM (Random Access Memory) or a non-volatile memory element such as a ROM (Read Only Memory), an EEPROM (Electrically Erasable Programmable ROM), or a flash memory, and pre-stores a program P (program product) and data to be referred to during processing. The program P (program product) stored in the second storage unit 222 may store the program P (program product) read from a recording medium M readable by the in-vehicle device 2. Further, it may be that the program P (program product) is downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the second storage unit 222.
[0048] The vehicle external communication unit 223 is constituted by, for example, a CAN transceiver and is an input / output interface using the communication protocol of CAN. Alternatively, the vehicle internal communication unit 213 may be constituted by an Ethernet PHY and be an input / output interface using the communication protocol of Ethernet (registered trademark). The second processing unit 22 is communicably connected to the external server 100 (vehicle external communication device 1) or the diagnostic device 101 via the vehicle external communication unit 223.
[0049] In the present embodiment, each of the first processing unit 21 and the second processing unit 22 is assumed to be constituted by a separate microcomputer, but it is not limited thereto. The in-vehicle device 2 may include, for example, a multi-CPU composed of a plurality of CPUs, and individual CPUs in the multi-CPU may function as the first processing unit 21 and the second processing unit 22.
[0050] Each of the first processing unit 21 and the second processing unit 22 further includes a data communication unit 202 and a verification communication unit 204. The first processing unit 21 and the second processing unit 22 are communicably connected via a data communication line 201 connected to the respective data communication units 202. When these data communication units 202 are constituted by, for example, CAN transceivers, the data communication line 201 is constituted by a CAN bus, and data communication between the first processing unit 21 and the second processing unit 22 is performed using the CAN protocol. When these data communication units 202 are constituted by, for example, Ethernet (registered trademark) PHYs, the data communication line 201 is constituted by an Ethernet cable, and data communication between the first processing unit 21 and the second processing unit 22 is performed using the TCP / IP protocol. The data flowing through the data communication line 201 is data transmitted and received between an external device such as the external server 100 or the diagnostic device 101 and an in-vehicle ECU 4 connected to the in-vehicle network 3, and is data relayed by the in-vehicle device 2 (relay target data).
[0051] The first processing unit 21 and the second processing unit 22 are communicably connected via a verification communication line 203 connected to each verification communication unit 204. The verification communication line 203 is constituted by, for example, a serial cable. In this case, each of the verification communication units 204 is constituted by a serial communication IF. Data communication between the first processing unit 21 and the second processing unit 22 via the verification communication line 203 is performed by serial communication. Alternatively, the verification communication line 203 may be, for example, a conductive pattern such as a land provided on a substrate on which the first processing unit 21 and the second processing unit 22 are mounted. In this case, the verification communication unit 204 is constituted by terminals provided on the first processing unit 21 and the second processing unit 22. Alternatively, the verification communication line 203 and the verification communication unit 204 may correspond to CAN or Ethernet in the same manner as the data communication line 201 and the data communication unit 202.
[0052] The data flowing through the verification communication line 203 is data related to security verification (security processing) performed by the first processing unit 21 on the second processing unit 22. When the challenge response method is used as the security verification, it includes an authentication request, challenge information, and response information. Further, an inactivation signal output when the first processing unit 21 inactivates the second processing unit 22, or a return signal output when the first processing unit 21 returns the second processing unit 22 may flow through the verification communication line 203.
[0053] In this way, the communication line between the first processing unit 21 and the second processing unit 22 is configured as a separate line (separate system) from the data communication line 201 for data relay through which in-vehicle communication data transmitted and received to and from an external device flows, and the verification communication line 203 through which data for security verification flows. Thereby, without inhibiting the relay processing performed by the in-vehicle device 2, that is, while maintaining the processing ability of the conventional function performed by the in-vehicle device 2 functioning as a relay device (securing the bandwidth for data relay), security processing for a plurality of processing units (microcomputers) mounted on the in-vehicle device 2 can be efficiently performed.
[0054] FIG. 3 is a flowchart exemplifying the processing of the first processing unit 21 and the second processing unit 22 of the in-vehicle device 2. The in-vehicle device 2 constantly performs the following processing, for example, when the vehicle C is in the start state (IG switch is on) or the stop state (IG switch is off). A series of processes of the first processing unit 21 (in-vehicle microcomputer) and the second processing unit 22 (out-of-vehicle microcomputer) of the in-vehicle device 2 are performed in association with each other. First, the processing by the first processing unit 21 (in-vehicle microcomputer) will be described, and then the processing by the second processing unit 22 (out-of-vehicle microcomputer) will be described.
[0055] The first processing unit 21 (first control unit 211) determines whether it has acquired a verification request from the second processing unit 22 (S101). The first processing unit 21 is communicably connected to the second processing unit 22 via the verification communication line 203, and performs a process of acquiring (receiving) data or a signal regarding a verification request (authentication request) from the second processing unit 22 via the verification communication line 203 on a periodic or regular basis. The first processing unit 21 determines whether it has acquired a verification request from the second processing unit 22 based on the acquisition result of the verification request (authentication request).
[0056] The first processing unit 21 is also communicably connected to the second processing unit 22 via the data communication line 201. Data (out-of-vehicle communication data) transmitted from an external device such as the external server 100 and received by the second processing unit 22 is output from the second processing unit 22 to the first processing unit 21 via the data communication line 201. In this way, the first processing unit 21 and the second processing unit 22 are communicably connected by a duplex communication path using different communication lines, namely the data communication line 201 and the verification communication line 203. Thereby, processing for security verification, such as communication of a verification request (authentication request), can be performed on the verification communication line 203 without affecting the relay processing of the out-of-vehicle communication data via the data communication line 201.
[0057] When the verification request (authentication request) from the second processing unit 22 has not been acquired (S101: NO), the first processing unit 21 performs a loop process to execute the process of S101 again. That is, the first processing unit 21 may continue to wait for the verification request (authentication request) transmitted from the second processing unit 22. Therefore, the first processing unit 21 performs the relay process of the data (out-of-vehicle communication data) transmitted and received between the first processing unit 21 and the second processing unit 22 via the data communication line 201 in parallel with the process of waiting for the verification request (authentication request) transmitted from the second processing unit 22.
[0058] When the verification request (authentication request) from the second processing unit 22 has been acquired (S101: YES), the first processing unit 21 performs security verification on the second processing unit 22 (S102). When the first processing unit 21 acquires (receives) data or a signal related to the verification request (authentication request) from the second processing unit 22, the first processing unit 21 performs security verification on the second processing unit 22 using the verification request as a trigger. However, the first processing unit 21 is not limited to performing security verification triggered by the verification request (authentication request) from the second processing unit 22, and the first processing unit 21 itself may spontaneously perform (start) security verification on the second processing unit 22 at a predetermined cycle. The first processing unit 21 may perform the relay process of the data (out-of-vehicle communication data) transmitted and received between the first processing unit 21 and the second processing unit 22 via the data communication line 201 in parallel with the security verification on the second processing unit 22.
[0059] When performing the security verification, the first processing unit 21 may use, for example, a challenge-response method. When using the challenge-response method, the first processing unit 21 generates challenge information and transmits the generated challenge information to the second processing unit 22. Further, the first processing unit 21 also generates response information corresponding to the generated challenge information and stores the generated response information in the first storage unit 212.
[0060] In this embodiment, although the first processing unit 21 uses the challenge-response method for security verification, it is not limited to this. The first processing unit 21 may perform security verification using a predetermined password authentication, common key encryption, or the like. That is, both the first processing unit 21 and the second processing unit 22 have the same type of security function implemented, and the first processing unit 21 may perform security verification (security processing) of the second processing unit 22 using the security function.
[0061] The first processing unit 21 acquires (S103) response data from the second processing unit 22 for security verification. For the generation of challenge information performed as security verification and the transmission to the second processing unit 22, the first processing unit 21 acquires (receives) response data generated by the second processing unit 22 based on the challenge information from the second processing unit 22.
[0062] The first processing unit 21 determines (S104) whether the acquired response data is valid. For example, when using the challenge-response method, the first processing unit 21 compares the response data (response information) acquired (received) from the second processing unit 22 with the response data (response information) generated by itself (the first processing unit 21) based on the challenge information, and determines whether these response data (response information) are the same.
[0063] If these response data (response information) are the same, the first processing unit 21 determines that the response data (response information) acquired (received) from the second processing unit 22 is legitimate (normal). At this time, the first processing unit 21 determines that the challenge response authentication for the second processing unit 22 has been successful. If these response data (response information) are not the same, that is, if the response data (response information) acquired (received) from the second processing unit 22 is different from the response data (response information) generated by itself (the first processing unit 21) based on the challenge information, the first processing unit 21 determines that the response data (response information) acquired (received) from the second processing unit 22 is inappropriate (abnormal). At this time, the first processing unit 21 determines that the challenge response authentication for the second processing unit 22 has failed.
[0064] Even when the first processing unit 21 cannot acquire the response data (response information) from the second processing unit 22 for a predetermined period after outputting (transmitting) the challenge information, the first processing unit 21 may determine that the response data (response information) is inappropriate (abnormal). For example, when the second processing unit 22 is in an abnormal state due to an unauthorized access from outside the vehicle or the like (security attack), it is also assumed that the security function itself for the challenge response method has already failed. Even in such a case, when the response information cannot be acquired for a predetermined period, by determining that the response data is inappropriate, the first processing unit 21 can efficiently determine that the second processing unit 22 is in an abnormal state.
[0065] When it is determined that the response data is valid (S104: YES), the first processing unit 21 determines that the second processing unit 22 is normal (S105). When the first processing unit 21 determines that the response data is valid (normal), it succeeds in the challenge response authentication for the second processing unit 22, and the second processing unit 22 is determined to be normal. The first processing unit 21 may store, as history information in the first storage unit 212, a determination result indicating that the challenge response authentication has succeeded, in association with time point information indicating the date and time when the security verification was performed or a time stamp or the like. After executing S105, the first processing unit 21 may perform a loop process to execute the process from S101 again.
[0066] When it is determined that the response data is not valid (S104: NO), the first processing unit 21 determines that the second processing unit 22 is abnormal (S1041). When the first processing unit 21 determines that the response data is not valid, that is, inappropriate (abnormal), it fails the challenge response authentication for the second processing unit 22, and the second processing unit 22 is determined to be abnormal. The first processing unit 21 may store, as history information in the first storage unit 212, a determination result indicating that the challenge response authentication has failed, in association with time point information indicating the date and time when the security verification was performed or a time stamp or the like.
[0067] The first processing unit 21 deactivates the second processing unit 22 (S1042). The first processing unit 21 performs a process for deactivating the second processing unit 22 determined to be abnormal as a result of the security verification. The process for deactivating includes, for example, cutting off the power supply to the second processing unit 22, forcibly stopping (shutting down) the second processing unit 22, cutting off the data communication line 201 with the second processing unit 22, or invalidating the communication port connected to the data communication line 201.
[0068] When cutting off the power supply to the second processing unit 22 as a process for inactivation, the first processing unit 21 may turn off a relay or a semiconductor switch provided in the power line for supplying power to the second processing unit 22. When performing forced stop (shutdown) of the second processing unit 22 as a process for inactivation, the first processing unit 21 may output (transmit) a forced stop signal to the second processing unit 22 via the verification communication line 203. When cutting off the data communication line 201 with the second processing unit 22 as a process for inactivation, the first processing unit 21 may turn off a relay or a semiconductor switch provided in the data communication line 201. When invalidating the communication port connected to the data communication line 201 as a process for inactivation, the first processing unit 21 may stop the power supply to the data communication unit 202 provided in its own unit. Even in this case, the first processing unit 21 may maintain the activation state of the verification communication unit 204 and continue the communicable state with the second processing unit 22 via the verification communication line 203. The first processing unit 21 may store, as history information, the details of the measures taken to inactivate the second processing unit 22 in association with the determination result indicating that the challenge response authentication has failed in the first storage unit 212.
[0069] The second processing unit 22 (second control unit 221) outputs a verification request to the first processing unit 21 (T101). The second processing unit 22 outputs (transmits) a verification request (authentication request) to the first processing unit 21, for example, periodically or regularly. The second processing unit 22 may output (transmit) a verification request (authentication request) to the first processing unit 21 via the verification communication line 203.
[0070] The second processing unit 22 generates response data according to the security verification by the first processing unit 21 (T102). When using the challenge-response method as the security verification, the second processing unit 22 acquires (receives) the challenge information output (transmitted) from the first processing unit 21 and generates response information based on the challenge information. The second processing unit 22 may generate response information by generating (converting) a hash value based on the challenge information and the password set in the second processing unit 22 (the password stored in the second storage unit 222).
[0071] The second processing unit 22 outputs the generated response data to the first processing unit 21 (T103). The second processing unit 22 may output (transmit) the generated response data (response information) to the first processing unit 21 via the verification communication line 203.
[0072] The second processing unit 22 transitions to an inactivated state by the inactivation processing by the first processing unit 21 (T104). Based on the result of the security verification, when the first processing unit 21 determines that the second processing unit 22 is abnormal (the challenge-response authentication fails), the first processing unit 21 takes measures to inactivate the second processing unit 22. By this measure, the second processing unit 22 will transition to an inactivated state. Thereby, for example, the second processing unit 22 that has become in an abnormal state due to unauthorized access from outside the vehicle or the like (security attack) can be substantially disconnected (separated) from the in-vehicle network 3, and it is possible to prevent the control of the vehicle C (vehicle C system) from being affected by the second processing unit 22. Based on the result of the security verification, when the first processing unit 21 determines that the second processing unit 22 is normal (the challenge-response authentication is successful), the first processing unit 21 does not take measures to inactivate the second processing unit 22, so the activated state of the second processing unit 22 is maintained (continued).
[0073] (Embodiment 2) FIG. 4 is a flowchart illustrating the processing of the first processing unit 21 and the second processing unit 22 of the in-vehicle device 2 according to Embodiment 2 (return signal). Similar to Embodiment 1, the in-vehicle device 2 constantly performs the following processing, for example, when the vehicle C is in the startup state (IG switch is on) or the stop state (IG switch is off). A series of processes of the first processing unit 21 (in-vehicle microcomputer) and the second processing unit 22 (out-vehicle microcomputer) of the in-vehicle device 2 are performed in relation to each other. First, the processing by the first processing unit 21 (in-vehicle microcomputer) will be described, and then the processing by the second processing unit 22 (out-vehicle microcomputer) will be described.
[0074] The first processing unit 21 determines whether it has acquired a verification request from the second processing unit 22 (S201). The first processing unit 21 performs the process of S201 in the same manner as the process S101 of Embodiment 1.
[0075] When the verification request (authentication request) from the second processing unit 22 has not been acquired (S201: NO), the first processing unit 21 determines whether a predetermined period has elapsed (S2011). For example, when using the challenge-response method, the second processing unit 22 is configured to periodically output a verification request (authentication request) to the first processing unit 21, and the first processing unit 21 determines whether the state of not acquiring the verification request (authentication request) from the second processing unit 22 has continued for a predetermined period according to the period. The predetermined period may be, for example, a period three times the transmission period when the second processing unit 22 outputs (transmits) the verification request, and is preset and stored in the first storage unit 212. The first processing unit 21 may store in the first storage unit 212 as the reception history of the verification request whether it has acquired (received) the verification request from the second processing unit 22 each time the transmission period when the second processing unit 22 outputs (transmits) the verification request elapses.
[0076] When it is determined that the predetermined period has not elapsed (S2011: NO), the first processing unit 21 performs a loop process to execute the process of S101 again. That is, the first processing unit 21 may continue to wait for the verification request (authentication request) transmitted from the second processing unit 22.
[0077] When it is determined that the specified period has elapsed (S2011: YES), the first processing unit 21 determines that the second processing unit 22 is abnormal (S2041). When the state in which the second processing unit 22 does not output a verification request (authentication request) has elapsed for a period longer than the specified period, the first processing unit 21 may determine that the second processing unit 22 is in an abnormal state due to unauthorized access from outside the vehicle or the like (security attack), and the security function has already failed.
[0078] When the verification request (authentication request) from the second processing unit 22 is acquired (S201: YES), the first processing unit 21 performs security verification on the second processing unit 22 (S202). The first processing unit 21 acquires response data from the second processing unit 22 for the security verification (S203). The first processing unit 21 determines whether the acquired response data is valid (S204). When it is determined that the response data is valid (S204: YES), the first processing unit 21 determines that the second processing unit 22 is normal (S205). The first processing unit 21 performs the processes from S202 to S205 in the same manner as the processes S102 to S105 of Embodiment 1.
[0079] When it is determined that the response data is not valid (S204: NO), or when it is determined that the specified period has elapsed as described above (S2011: YES), the first processing unit 21 determines that the second processing unit 22 is abnormal (S2041). The first processing unit 21 performs the process of S2041 in the same manner as the process S1041 of Embodiment 1.
[0080] The first processing unit 21 executes a recovery process for the second processing unit 22 (S2042). When the first processing unit 21 determines that the second processing unit 22 is abnormal, it performs a recovery process for restoring the second processing unit 22. The recovery process for restoring the second processing unit 22 includes, for example, restarting the second processing unit 22 by cutting off and then re-supplying power to the second processing unit 22, or outputting a recovery signal to the second processing unit 22.
[0081] As a return process, when restarting the second processing unit 22 by cutting off and then re-supplying power to the second processing unit 22, the first processing unit 21 may turn off and then turn on again a relay or semiconductor switch provided in the power line that supplies power to the second processing unit 22. The return signal for the second processing unit 22 may be, for example, a signal including a reboot, initialization of the second processing unit 22, or a program pre-stored in the storage unit of the first processing unit 21 and an execution instruction for the program. The return signal may be output (transmitted) from the first processing unit 21 to the second processing unit 22 via the verification communication line 203. If the result of the security verification (verification result) for the second processing unit 22 continues to be abnormal even though the first processing unit 21 outputs the return signal to the second processing unit 22 a plurality of times (a predetermined number of times), the first processing unit 21 may deactivate the second processing unit 22 in the same manner as in Embodiment 1.
[0082] The second processing unit 22 outputs a verification request to the first processing unit 21 (T201). The second processing unit 22 generates response data according to the security verification by the first processing unit 21 (T202). The second processing unit 22 outputs the generated response data to the first processing unit 21 (T203). The second processing unit 22 performs the processes from T201 to T203 in the same manner as the processes T101 to T103 in Embodiment 1.
[0083] The second processing unit 22 executes a return process by the return process performed by the first processing unit 21 (T204). Based on the result of the security verification, when the first processing unit 21 determines that the second processing unit 22 is abnormal (the challenge response authentication fails), the first processing unit 21 takes measures to return the second processing unit 22. By this measure, the second processing unit 22 executes a return process, for example, by restarting, loading and executing a normal program transmitted from the first processing unit 21, etc. Thereby, for example, the second processing unit 22 that has become in an abnormal state due to an unauthorized access from outside the vehicle or the like (security attack) can be transitioned (returned) to a normal state.
[0084] (Embodiment 3) FIG. 5 is a schematic diagram illustrating the system configuration of the in-vehicle system S according to Embodiment 3 (connected to the actuator 5). In the present embodiment, the in-vehicle ECU 4 directly connected to the actuator 5 such as a motor also includes a first processing unit 41 and a second processing unit 42, similar to the in-vehicle device 2 described in Embodiment 1. The configurations and processes of the first processing unit 41 and the second processing unit 42 of the in-vehicle ECU 4 are the same as the configurations and processes of the first processing unit 21 and the second processing unit 22 of the in-vehicle device 2.
[0085] The first processing unit 41 of the in-vehicle ECU 4 is not directly connected to the in-vehicle network 3 but is directly connected to the actuator 5 such as a motor. The second processing unit 42 of the in-vehicle ECU 4 is directly connected to the in-vehicle network 3. The first processing unit 41 and the second processing unit 42 of the in-vehicle ECU 4 are communicably connected by a data communication line 201 and a verification communication line 203, similar to the in-vehicle device 2 of Embodiment 1.
[0086] The first processing unit 41 and the second processing unit 42 included in the in-vehicle ECU 4 perform security verification, similar to the in-vehicle device 2 of Embodiment 1. The first processing unit 41 located on the actuator 5 side performs security verification (security treatment) on the second processing unit 42 located on the in-vehicle network 3 side using the challenge-response method. Thereby, in the in-vehicle ECU 4 in which a plurality of processing units (microcontrollers) are mounted, the integrity of the second processing unit 42 on the in-vehicle network 3 side can be ensured, and resistance to security attacks from outside the vehicle via the in-vehicle network 3 can be provided.
[0087] In the present embodiment, the second processing unit 42 is located on the in-vehicle network 3 side and the first processing unit 41 is located on the actuator 5 side, but it is not limited thereto. The first processing unit 41 may be located on the in-vehicle network 3 side and the second processing unit 42 may be located on the actuator 5 side. Thereby, in the in-vehicle ECU 4 in which a plurality of processing units (microcontrollers) are mounted, the integrity of the second processing unit 42 on the actuator 5 side can be ensured, and resistance to security attacks from the actuator 5 side can be provided.
[0088] The embodiments disclosed this time should be considered as illustrative in all respects and not restrictive. The scope of the present disclosure is shown not by the above meaning, but by the claims, and it is intended that all modifications within the meaning and scope equivalent to the claims are included.
Description of Reference Numerals
[0089] C Vehicle S Vehicle-mounted System 100 External Server 101 Diagnostic Device 1 Vehicle External Communication Device 11 Antenna 2 Vehicle-mounted Device (Relay Device) 21 First Processing Unit (In-vehicle Microcomputer) 211 First Control Unit 212 First Storage Unit 213 In-vehicle Communication Unit 22 Second Processing Unit (Out-of-vehicle Microcomputer) 221 Second Control Unit 222 Second Storage Unit 223 Out-of-vehicle Communication Unit M Recording Medium P Program (Program Product) 201 Communication Line for Data 202 Data Communication Unit 203 Communication Line for Verification 204 Verification Communication Unit 3 Vehicle-mounted Network 31 Communication Cable 4 Vehicle-mounted ECU 41 First Processing Unit 42 Second Processing Unit 5 Actuator
Claims
1. An in-vehicle device mounted on a vehicle having an in-vehicle network, comprising: a first processing unit connected to the in-vehicle network; a second processing unit communicably connected to the first processing unit; wherein the first processing unit: performs security verification on the second processing unit; when it is determined that the second processing unit is abnormal based on the result of the security verification, performs a recovery process for recovering the second processing unit; if the result of the security verification for the second processing unit continues to be abnormal even after outputting a recovery signal for performing the recovery process to the second processing unit a plurality of times, deactivates the second processing unit In-vehicle device.
2. The first processing unit acquires response data from the second processing unit for the security verification, and determines whether the second processing unit is normal based on the acquired response data The in-vehicle device according to claim 1.
3. The first processing unit performs security verification on the second processing unit using a challenge-response method The in-vehicle device according to claim 1 or claim 2.
4. The first processing unit performs security verification on the second processing unit in response to a verification request from the second processing unit The in-vehicle device according to any one of claims 1 to 3.
5. If the first processing unit does not acquire a verification request from the second processing unit for a predetermined period, it is determined that the second processing unit is abnormal The in-vehicle device according to claim 4.
6. The second processing unit acquires out-of-vehicle communication data from an external device outside the vehicle, The first processing unit and the second processing unit are connected by a data communication line through which the out-of-vehicle communication data flows and a verification communication line through which data for the security verification flows The in-vehicle device according to any one of claims 1 to 5.
7. When it is determined that the second processing unit is abnormal based on the result of the security verification, the first processing unit performs a process for deactivating the second processing unit The in-vehicle device according to any one of claims 1 to 6.
8. A plurality of in-vehicle ECUs are connected to the in-vehicle network, The first processing unit relays data acquired from the second processing unit to the in-vehicle ECU via the in-vehicle network The in-vehicle device according to any one of claims 1 to 7.
9. A computer mounted on a vehicle having an in-vehicle network, comprising a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit, wherein the first processing unit performs a security verification on the second processing unit, and based on the result of the security verification, when it is determined that the second processing unit is abnormal, a recovery process for recovering the second processing unit is performed, and if the result of the security verification for the second processing unit continues to be abnormal despite outputting a recovery signal for performing the recovery process to the second processing unit a plurality of times, the second processing unit is deactivated An information processing method for executing the process.
10. A computer mounted on a vehicle having an in-vehicle network, comprising a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit, wherein the first processing unit performs a security verification on the second processing unit, and based on the result of the security verification, when it is determined that the second processing unit is abnormal, a recovery process for recovering the second processing unit is performed, and if the result of the security verification for the second processing unit continues to be abnormal despite outputting a recovery signal for performing the recovery process to the second processing unit a plurality of times, the second processing unit is deactivated A program for executing the process.
Citation Information
Patent Citations
Data communication authentication system for vehicle, and gateway apparatus for vehicle
JP2013171378A
Electronic control device
JP2016126716A
On-vehicle device, relay device, and computer programs
JP2018116669A
Communication system
JP2021022801A
Secure boot for vehicular systems
US9792440B1