In-vehicle device, program, and information processing method

The in-vehicle device efficiently verifies and secures the integrity of processing units by comparing data with stored verification data, addressing the lack of security measures in existing devices and reducing costs through differential microcontroller performance.

JP7707965B2Active Publication Date: 2025-07-15SUMITOMO WIRING SYSTEMS LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2022030128
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-02-28
Publication Date
2025-07-15
Estimated Expiration
2042-02-28

AI Technical Summary

Technical Problem

Existing in-vehicle electronic control devices lack efficient security measures for microcontrollers, particularly in scenarios involving communication with external devices, which can lead to unauthorized access and compromised integrity.

Method used

An in-vehicle device with a first processing unit connected to the in-vehicle network and a second processing unit that performs security verification on acquired data from the second unit, ensuring its integrity by comparing with stored verification data, and taking actions such as deactivation or recovery when necessary.

Benefits of technology

Ensures efficient security measures for mounted processing units, reducing product costs by using less expensive microcontrollers for the second unit and preventing unauthorized access, while maintaining network integrity and functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007707965000001
    Figure 0007707965000001
  • Figure 0007707965000002
    Figure 0007707965000002
  • Figure 0007707965000003
    Figure 0007707965000003
Patent Text Reader

Abstract

To provide an on-vehicle device and the like that can efficiently take security measures for a processing unit mounted.SOLUTION: An on-vehicle device is installed in a vehicle having an on-vehicle network, and includes a first processing unit connected to the on-vehicle network, and a second processing unit communicably connected to the first processing unit. The first processing unit obtains data related to a program executed by the second processing unit from the second processing unit, performs security verification on the obtained data, and determines whether the second processing unit is normal based on a result of the security verification.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an in-vehicle device, a program, and an information processing method.

Background Art

[0002] An electronic control device mounted on a vehicle, having a plurality of microcontrollers and capable of detecting an abnormality in a communication bus, is disclosed (for example, Patent Document 1). The electronic control device of Patent Document 1 is one of a plurality of nodes connected to a communication bus, and includes a first microcontroller and a second microcontroller that receive a transmission signal flowing through the communication bus and transmit a transmission signal to the communication bus. The transmission signal to be transmitted to the communication bus is transmitted to each microcontroller without passing through the communication bus, and each microcontroller is configured to receive the transmission signal.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the electronic control device of Patent Document 1, there is a problem that no consideration is given to efficiently performing security measures on the microcontrollers included in the electronic control device.

[0005] An object of the present disclosure is to provide an in-vehicle device or the like that can efficiently perform security measures on a mounted processing unit.

Means for Solving the Problems

[0006] An in-vehicle device according to one aspect of the present disclosure is an in-vehicle device mounted on a vehicle having an in-vehicle network, and includes a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit. The first processing unit acquires data related to a program executed by the second processing unit from the second processing unit, performs security verification on the acquired data, and determines whether the second processing unit is normal based on the result of the security verification.

Effect of the Invention

[0007] According to one aspect of the present disclosure, it is possible to provide an in-vehicle device or the like that efficiently performs security measures on a mounted processing unit.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Modes for Carrying Out the Invention

[0009] [Description of Embodiments of the Present Disclosure] First, embodiments of the present disclosure will be listed and described. Also, at least a part of the embodiments described below may be arbitrarily combined.

[0010] (1) An in-vehicle device according to one aspect of the present disclosure is an in-vehicle device mounted on a vehicle having an in-vehicle network, comprising a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit. The first processing unit acquires data regarding a program executed by the second processing unit from the second processing unit, performs security verification on the acquired data, and determines whether the second processing unit is normal based on the result of the security verification.

[0011] In this aspect, the in-vehicle device includes a first processing unit and a second processing unit, and each of these processing units is constituted by, for example, a separate microcomputer or the like. The first processing unit connected to the in-vehicle network performs security verification on the second processing unit and exhibits a monitoring function for the second processing unit. Therefore, when the second processing unit communicates with an off-vehicle device located outside the vehicle, such as an OTA server or a diagnostic device, even if unauthorized access or data is transmitted to the second processing unit from outside the vehicle, the first processing unit can guarantee the integrity (normality) of the second processing unit by performing security verification on the second processing unit. Thus, even when a plurality of microcomputers or the like constituting the first processing unit and the second processing unit are mounted on a single in-vehicle device, the first processing unit connected to the in-vehicle network can efficiently perform security verification on the second processing unit (another processing unit) that is not directly connected to the in-vehicle network. The data related to the program executed by the second processing unit may be not only the program itself (execution image) but also a reference file or a setting file called (referenced) from the program, that is, software data used for software processing by the second processing unit. By performing security verification (security measures) on the data (software data) related to the program executed by the second processing unit in this way, it is possible to guarantee the integrity (normality) of the second processing unit by determining whether the second processing unit is normal. When performing the security verification, the first processing unit may compare the software data acquired from the second processing unit with the software data (verification data) previously stored in the first storage unit provided in the first processing unit. When the software data acquired from the second processing unit is the same as the software data (verification data) previously stored in the first storage unit, the first processing unit determines that the result of the security verification (software data) is legitimate. When the software data acquired from the second processing unit is different from the software data (verification data) previously stored in the first storage unit, the first processing unit determines that the result of the security verification (software data) is inappropriate.When the result of security verification (software data) is valid, the first processing unit determines that the second processing unit is normal. When the result of security verification (software data) is inappropriate, the first processing unit determines that the second processing unit is abnormal. Since the security verification (security measure) of the second processing unit by the first processing unit is performed using software data such as a program used in the processing by the second processing unit itself, it is possible to eliminate the need to implement a security function such as an authentication module in the second processing unit. As a result, the second processing unit can be configured with a relatively inexpensive microcomputer or the like, and the product cost can be reduced.

[0012] (2) In the in-vehicle device according to one aspect of the present disclosure, the second processing unit acquires out-vehicle communication data from an external device outside the vehicle, and the first processing unit and the second processing unit are connected by a data communication line through which the out-vehicle communication data flows and a verification communication line through which data for the security verification flows.

[0013] In this aspect, as a communication circuit between the first processing unit and the second processing unit, a parallel circuit including a data communication line and a verification communication line is configured and duplicated. Thereby, security verification using the verification communication line can be performed without affecting relay processing or the like using the data communication line.

[0014] (3) In the in-vehicle device according to one aspect of the present disclosure, the first processing unit designates data to be output to the first processing unit to the second processing unit, and the second processing unit outputs the data designated by the first processing unit as data related to the program.

[0015] In this aspect, the second processing unit outputs the data specified by the first processing unit as data related to the program, and the output data is used by the first processing unit to perform security verification on the second processing unit. Therefore, compared with the case where the data (software data) for performing the security verification is fixed, by using the data specified each time by the first processing unit as the target data for the security verification, the reliability in the security verification can be improved. Such output (transmission) of data from the second processing unit to the first processing unit can use a general-purpose program for file transfer between microcontrollers, thereby reducing the development man-hours for performing security verification on the second processing unit by the first processing unit.

[0016] (4) The in-vehicle device according to one aspect of the present disclosure, wherein the second processing unit includes a second storage unit, and the data related to the program executed by the second processing unit is stored in the second storage unit.

[0017] In this aspect, the second processing unit includes a second storage unit, and the second storage unit stores program files, reference files, etc. (software data) that are executed or referenced when the second processing unit performs software processing. For example, when an unauthorized access from outside the vehicle or the like (security attack) is performed on the second processing unit, it is assumed that the program files, etc. (software data) stored in the second storage unit are modified. On the other hand, since the data to be the target of the security verification by the first processing unit is the data stored in the second storage unit, when the data stored in the second storage unit is modified, the first processing unit can surely perform security verification on the modified data, and can efficiently ensure the integrity (normality) of the second processing unit.

[0018] (5) The in-vehicle device according to one aspect of the present disclosure, wherein the processing performance of the second processing unit is lower than that of the first processing unit.

[0019] In this aspect, since the security verification in the second processing unit is substantially performed by the first processing unit, the processing performance required of the second processing unit can be made lower than that of the first processing unit. When each of the first processing unit and the second processing unit is configured by, for example, separate microcontrollers or the like, the component cost of the microcontroller depends on the processing performance. Therefore, by making the processing performance of the second processing unit lower than that of the first processing unit, the component cost of the second processing unit can be made lower than that of the first processing unit. As a result, the second processing unit can be configured with a relatively inexpensive microcontroller, and the product cost of the in-vehicle device can be reduced.

[0020] (6) In the in-vehicle device according to one aspect of the present disclosure, when the first processing unit determines that the second processing unit is abnormal based on the result of the security verification, the first processing unit performs a process for deactivating the second processing unit.

[0021] In this aspect, when the first processing unit determines that the second processing unit is abnormal based on the result of the security verification, the first processing unit substantially disconnects the second processing unit in an abnormal state from the in-vehicle network in order to deactivate the second processing unit, and it is possible to prevent the control of the vehicle (vehicle system) from being affected by the second processing unit. When deactivating the second processing unit, the first processing unit may cut off the power supply to the second processing unit, forcibly stop (shutdown) the second processing unit, cut off the data communication line with the second processing unit, or invalidate the communication port (in-vehicle communication unit) connected to the data communication line.

[0022] (7) In the in-vehicle device according to one aspect of the present disclosure, when the first processing unit determines that the second processing unit is abnormal based on the result of the security verification, the first processing unit performs a recovery process for recovering the second processing unit.

[0023] In this aspect, when the first processing unit determines that the second processing unit is abnormal based on the result of security verification, the first processing unit performs a recovery process such as cutting off the power supply to the second processing unit and then restarting the second processing unit by resupplying power, and outputting a recovery signal to the second processing unit. As a result, for example, the second processing unit that has entered an abnormal state due to unauthorized access from outside the vehicle (security attack) can be transitioned (recovered) to a normal state. The recovery signal for the second processing unit may be, for example, a signal including a reboot, initialization of the second processing unit, or a program pre-stored in the storage unit of the first processing unit and an execution instruction for the program. If the result of the security verification (verification result) for the second processing unit continues to be abnormal even after the first processing unit outputs the recovery signal to the second processing unit a plurality of times (a predetermined number of times), the first processing unit may deactivate the second processing unit.

[0024] (8) In the in-vehicle device according to one aspect of the present disclosure, a plurality of in-vehicle ECUs are connected to the in-vehicle network, and the first processing unit relays the data acquired from the second processing unit to the in-vehicle ECUs via the in-vehicle network.

[0025] In this aspect, since the first processing unit relays the data acquired by the second processing unit to the in-vehicle ECUs via the in-vehicle network, the in-vehicle device can function as a relay device. In addition, a plurality of communication cables (such as CAN buses) constituting the in-vehicle network are connected to the first processing unit, and the first processing unit may relay the data transmitted and received between the in-vehicle ECUs connected to each of these plurality of communication cables.

[0026] (9) An information processing method according to one aspect of the present disclosure is implemented on a computer mounted in a vehicle having an in-vehicle network, the computer including a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit. The first processing unit acquires data related to a program executed by the second processing unit from the second processing unit, performs a security verification on the acquired data, and determines whether the second processing unit is normal based on the result of the security verification.

[0027] In this aspect, an information processing method can be provided to cause a computer to function as an in-vehicle device that efficiently performs security measures on a mounted processing unit.

[0028] (10) A program according to an aspect of the present disclosure is installed in a vehicle having an in-vehicle network, and includes a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit. The first processing unit acquires data related to a program executed by the second processing unit from the second processing unit, performs security verification on the acquired data, and determines whether the second processing unit is normal based on the result of the security verification.

[0029] In this aspect, a program can be provided to cause a computer to function as an in-vehicle device that efficiently performs security measures on a mounted processing unit.

[0030] [Details of Embodiments of the Present Disclosure] The present disclosure will be specifically described based on the drawings showing its embodiments. An in-vehicle system S according to an embodiment of the present disclosure will be described below with reference to the drawings. Note that the present disclosure is not limited to these examples, and is defined by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims.

[0031] (Embodiment 1) Hereinafter, embodiments will be described with reference to the drawings. FIG. 1 is a schematic diagram illustrating the system configuration of the in-vehicle system S according to Embodiment 1. FIG. 2 is a block diagram illustrating the internal configuration of the in-vehicle device 2 included in the in-vehicle system S. The in-vehicle system S includes an in-vehicle device 2 mounted on a vehicle C and a plurality of in-vehicle ECUs 4, and these in-vehicle device 2 and the plurality of in-vehicle ECUs 4 are communicably connected via an in-vehicle network 3 constituted by a communication cable 31 such as a CAN bus. An actuator 5 (see FIG. 5) such as a motor, or an in-vehicle device such as a lamp or a sensor is connected to the in-vehicle ECU 4. The in-vehicle device 2 may function as a relay device that relays data transmitted and received between the plurality of in-vehicle ECUs 4 connected to the in-vehicle network 3.

[0032] An off-vehicle communication device 1 for communicating via an external network is connected to the in-vehicle device 2. The in-vehicle device 2 communicates with an external server 100 or a mobile terminal or the like via the off-vehicle communication device 1 and the external network. The external server 100 is a computer such as a server connected to an off-vehicle network such as the Internet or a public switched telephone network, and may be an OTA (Over The Air) server that provides an update program.

[0033] The vehicle exterior communication device 1 includes a wireless communication unit (not shown) and a communication I / F for communicating with the in-vehicle device 2. The wireless communication unit is a communication device for performing wireless communication using mobile communication protocols such as 4G, LTE (Long Term Evolution / trademark), 5G, WiFi (trademark), etc., and transmits and receives data to and from the external server 100 via the antenna 11 connected to the vehicle exterior communication unit 223. The communication I / F may be a communication interface for serial communication with the in-vehicle device 2, or a CAN transceiver for CAN communication. The communication between the vehicle exterior communication device 1 and the external server 100 is performed via an external network such as a public switched telephone network or the Internet. In this embodiment, the vehicle exterior communication device 1 is a separate device from the in-vehicle device 2, and these devices are communicably connected by the communication I / F, etc., but it is not limited thereto. The vehicle exterior communication device 1 may be incorporated in the in-vehicle device 2 as a component of the in-vehicle device 2. In this case, the second processing unit 22 (vehicle exterior microcomputer) may have the function of the vehicle exterior communication device 1.

[0034] The in-vehicle device 2 may be connected to a diagnostic device 101 used during inspection of the vehicle C, etc. Further, the in-vehicle device 2 may be connected to an LF antenna and an RF antenna and receive a signal transmitted from a smart key. In this way, an external device located outside the vehicle C is directly or indirectly connected to the in-vehicle device 2, and the in-vehicle device 2 also functions as a relay device that relays data (vehicle exterior communication data) output (transmitted) from the external device to the in-vehicle ECU 4 connected to the in-vehicle network 3. That is, the in-vehicle device 2 performs data relay processing between the in-vehicle ECUs 4 in the in-vehicle network 3 and data relay processing between the external device located outside the vehicle C and these in-vehicle ECUs 4.

[0035] In this way, the in-vehicle device 2 that functions as a relay device includes a first processing unit 21 connected to the in-vehicle network 3 and a second processing unit 22 that is not directly connected to the in-vehicle network 3 and receives data transmitted from an external device. When each of the first processing unit 21 and the second processing unit 22 is configured by, for example, a microcomputer, the first processing unit 21 corresponds to an in-vehicle microcomputer, and the second processing unit 22 corresponds to an out-of-vehicle microcomputer.

[0036] A security function is implemented in the first processing unit 21 (in-vehicle microcomputer), and the first processing unit 21 monitors the state of the second processing unit 22 by periodically performing security verification (security measures) on the second processing unit 22 using the security function. On the other hand, the second processing unit 22 (out-of-vehicle microcomputer) does not have a security function such as that of the first processing unit 21, and the second processing unit 22 does not have a function of performing security verification (security measures) on itself alone. Therefore, the first processing unit 21 having the security function acquires data (software data) regarding the program executed by the second processing unit 22 from the second processing unit 22 not having the security function, and performs security verification on the software data, thereby ensuring the integrity (legitimacy) of the second processing unit 22. Therefore, the second processing unit 22 not having the security function can be configured by a relatively inexpensive microcomputer or the like, and the product cost of the in-vehicle device 2 can be reduced. Moreover, in the data flow direction from outside the vehicle C by an external device, the first processing unit 21 (in-vehicle microcomputer) located inside the vehicle (downstream side) performs security measures on the second processing unit 22 (out-of-vehicle microcomputer) located outside the vehicle (upstream side), thereby ensuring the integrity of the second processing unit 22 (out-of-vehicle microcomputer) and providing resistance to security attacks from outside the vehicle.

[0037] The in-vehicle device 2 integrates multiple segments such as in-vehicle devices like the control system ECU, in-vehicle devices like the safety system ECU, and body in-vehicle devices like the BCU (Body Control Unit), and relays communication between these in-vehicle devices. The in-vehicle device 2 is, for example, a gateway or an Ethernet switch, and may function as a Layer 2 switch, a Layer 3 switch, or a CAN gateway. Or, the in-vehicle device 2 may be composed of a central control device such as a vehicle computer, and may be an integrated ECU that controls the entire vehicle C.

[0038] The in-vehicle device 2 includes a first processing unit 21 and a second processing unit 22. The second processing unit 22 located on the outer side of the vehicle receives data transmitted from an external device such as the external server 100 or the diagnostic device 101, and transmits data to these external devices. The first processing unit 21 located on the inner side of the vehicle, in addition to relaying data transmitted and received between the in-vehicle ECUs 4 connected to the in-vehicle network 3, relays the data from the external device received by the second processing unit 22 to the in-vehicle ECU 4, that is, performs relaying processing between the in-vehicle ECU 4 and the second processing unit 22.

[0039] In this embodiment, the first processing unit 21 that is directly connected to the in-vehicle network 3 and located on the inner side of the vehicle is one, but it is not limited to this. The first processing unit 21 (inner side processing unit) directly connected to the in-vehicle network 3 may be plural. In this embodiment, the second processing unit 22 that is not directly connected to the in-vehicle network 3 and located on the outer side of the vehicle is one, but it is not limited to this. The second processing unit 22 (outer side processing unit) that is not directly connected to the in-vehicle network 3 and located on the outer side of the vehicle may be plural. In this case, the first processing unit 21 may perform security verification for each of the plural second processing units 22.

[0040] The first processing unit 21 and the second processing unit 22 are communicably connected by a data communication line 201 and a verification communication line 203. That is, a parallel circuit formed by the data communication line 201 and the verification communication line 203 is configured as a communication circuit between the first processing unit 21 and the second processing unit 22, and the in-vehicle device 2 has such a duplicated communication circuit.

[0041] The first processing unit 21 is constituted by, for example, a microcomputer, and includes a first control unit 211, a first storage unit 212, and an in-vehicle communication unit 213. The first control unit 211 is constituted by, for example, a CPU (Central Processing Unit), an MPU (Micro Processing Unit), or the like, and performs various control processes, arithmetic processes, and the like by reading and executing a program P (program product) and data stored in advance in the first storage unit 212.

[0042] The first storage unit 212 is constituted by, for example, a volatile memory element such as a RAM (Random Access Memory), or a non-volatile memory element such as a ROM (Read Only Memory), an EEPROM (Electrically Erasable Programmable ROM), or a flash memory, and stores in advance a program P (program product) and data to be referred to during processing. The program P (program product) stored in the first storage unit 212 may be one that stores the program P (program product) read from a recording medium M readable by the in-vehicle device 2. Alternatively, the program P (program product) may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the first storage unit 212.

[0043] In the first memory unit 212, data identical to the software data transmitted from the second processing unit 22 is pre-stored (saved) as verification data. The verification data corresponding to the software data of the second processing unit 22 may be stored in the first memory unit 212, for example, at the manufacturing stage of the vehicle C. Further, when the program P (software data) executed by the second processing unit 22 is reprogrammed by an update program transmitted from, for example, an OTA server or the like, the verification data stored in the first memory unit 212 may also be updated in conjunction with the execution of the reprogramming.

[0044] The in-vehicle communication unit 213 is constituted by, for example, a CAN transceiver and is an input / output interface using the communication protocol of CAN. Alternatively, the in-vehicle communication unit 213 may be constituted by an Ethernet PHY and be an input / output interface using the communication protocol of Ethernet (Ethernet / Registered Trademark). The first processing unit 21 is communicably connected to an in-vehicle ECU 4 connected to the in-vehicle network 3 via the in-vehicle communication unit 213.

[0045] The second processing unit 22 is constituted by, for example, a microcomputer and includes a second control unit 221, a second memory unit 222, and an out-vehicle communication unit 223. The second control unit 221 is constituted by, for example, a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), etc., and reads and executes the program P (program product) and data pre-stored in the second memory unit 222 to perform various control processes, arithmetic processes, etc.

[0046] The second storage unit 222 is constituted by, for example, a volatile memory element such as a RAM (Random Access Memory), or a non-volatile memory element such as a ROM (Read Only Memory), an EEPROM (Electrically Erasable Programmable ROM), or a flash memory, and stores in advance a program P (program product) and data to be referred to during processing. The program P (program product) stored in the second storage unit 222 may be one that stores the program P (program product) read from a recording medium M readable by the in-vehicle device 2. Alternatively, the program P (program product) may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the second storage unit 222. The program P etc. (software data) stored in the second storage unit 222 is data output (transmitted) from the second processing unit 22 to the first processing unit 21 and is data to be subjected to security verification (security treatment) by the first processing unit 21.

[0047] The out-vehicle communication unit 223 is constituted by, for example, a CAN transceiver and is an input / output interface using the communication protocol of CAN. Alternatively, the in-vehicle communication unit 213 may be constituted by an Ethernet PHY and be an input / output interface using the communication protocol of Ethernet (Ethernet / Registered Trademark). The second processing unit 22 is communicably connected to an external server 100 (out-vehicle communication device 1) or a diagnostic device 101 via the out-vehicle communication unit 223.

[0048] In the present embodiment, each of the first processing unit 21 and the second processing unit 22 is assumed to be constituted by a separate microcomputer, but it is not limited thereto. The in-vehicle device 2 may include, for example, a multi-CPU composed of a plurality of CPUs, and individual CPUs in the multi-CPU may function as the first processing unit 21 and the second processing unit 22.

[0049] Each of the first processing unit 21 and the second processing unit 22 further includes a data communication unit 202 and a verification communication unit 204. The first processing unit 21 and the second processing unit 22 are communicably connected via a data communication line 201 connected to the respective data communication units 202. When these data communication units 202 are configured by, for example, a CAN transceiver, the data communication line 201 is configured by a CAN bus, and data communication between the first processing unit 21 and the second processing unit 22 is performed using the CAN protocol. When these data communication units 202 are configured by, for example, an Ethernet (registered trademark) PHY, the data communication line 201 is configured by an Ethernet cable, and data communication between the first processing unit 21 and the second processing unit 22 is performed using the TCP / IP protocol. The data flowing through the data communication line 201 is data transmitted and received between an external device such as an external server 100 or a diagnostic device 101 and an in-vehicle ECU 4 connected to the in-vehicle network 3, and is data relayed by the in-vehicle device 2 (relay target data).

[0050] The first processing unit 21 and the second processing unit 22 are further communicably connected via a verification communication line 203 connected to the respective verification communication units 204. The verification communication line 203 is configured by, for example, a serial cable. In this case, each of the verification communication units 204 is configured by a serial communication IF. Data communication between the first processing unit 21 and the second processing unit 22 via the verification communication line 203 is performed by serial communication. Alternatively, the verification communication line 203 may be, for example, a conductive pattern such as a land provided on a substrate on which the first processing unit 21 and the second processing unit 22 are mounted. In this case, the verification communication unit 204 is configured by terminals provided on the first processing unit 21 and the second processing unit 22. Alternatively, the verification communication line 203 and the verification communication unit 204 may correspond to CAN or Ethernet in the same manner as the data communication line 201 and the data communication unit 202.

[0051] The data flowing through the verification communication line 203 is data related to security verification (security measures) performed by the first processing unit 21 on the second processing unit 22. For example, it includes a request signal indicating an output request for software data from the first processing unit 21 to the second processing unit 22, and software data output from the second processing unit 22 to the first processing unit 21. Further, an inactivation signal output when the first processing unit 21 inactivates the second processing unit 22, or a return signal output when the first processing unit 21 returns the second processing unit 22 may flow through the verification communication line 203.

[0052] In this way, the communication line between the first processing unit 21 and the second processing unit 22 is configured as a separate line (separate system) from the data communication line 201 for data relay through which in-vehicle communication data transmitted and received with an external device flows, and the verification communication line 203 through which data for security verification flows. Thereby, without inhibiting the relay processing performed by the in-vehicle device 2, that is, while maintaining the processing ability of the conventional functions performed by the in-vehicle device 2 functioning as a relay device (securing the bandwidth for data relay), security measures can be efficiently performed on a plurality of processing units (microcontrollers) mounted on the in-vehicle device 2.

[0053] FIG. 3 is a flowchart illustrating the processing of the first processing unit 21 and the second processing unit 22 of the in-vehicle device 2. The in-vehicle device 2 constantly performs the following processing, for example, when the vehicle C is in the start state (IG switch is on) or the stop state (IG switch is off). A series of processing of the first processing unit 21 (in-vehicle microcontroller) and the second processing unit 22 (out-of-vehicle microcontroller) of the in-vehicle device 2 is performed in association with each other. First, the processing by the first processing unit 21 (in-vehicle microcontroller) will be described, and then the processing by the second processing unit 22 (out-of-vehicle microcontroller) will be described.

[0054] The first processing unit 21 (the first control unit 211) determines whether a predetermined period has elapsed (S101). The first processing unit 21 is configured to periodically perform security verification (security measures) on the second processing unit 22, and the period is stored in, for example, the first storage unit 212. The first processing unit 21 has a clock function and determines whether the period has elapsed from a predetermined starting point. If the predetermined period has not elapsed (S101: NO), the first processing unit 21 performs a loop process to execute the process of S101 again.

[0055] If the predetermined period has elapsed (S101: YES), the first processing unit 21 requests software data from the second processing unit 22 (S102). When the predetermined period has elapsed, the first processing unit 21 requests the second processing unit 22 to output software data that is the target of security verification (security measures). When performing this request, the first processing unit 21 may transmit a request signal to the second processing unit 22. The software data is stored in the second storage unit 222 of the second processing unit 22, and may be the program itself (execution image) executed when the second processing unit 22 performs software processing, or a reference file or setting file called (referenced) from the program.

[0056] The first processing unit 21 is communicably connected to the second processing unit 22 via the verification communication line 203, and may request the second processing unit 22 to output software data via the verification communication line 203. When performing this request, the first processing unit 21 may specify a specific file (software data) such as a program file or a setting file to be output. Alternatively, the software data that is the target of security verification (security measures) is predetermined between the first processing unit 21 and the second processing unit 22, and the first processing unit 21 may request the second processing unit 22 to output software data without specifying the file (software data) to be output.

[0057] The first processing unit 21 is further communicably connected to the second processing unit 22 via the data communication line 201. Data (out-of-vehicle communication data) transmitted from an external device such as the external server 100 and received by the second processing unit 22 is output from the second processing unit 22 to the first processing unit 21 via the data communication line 201. In this way, the first processing unit 21 and the second processing unit 22 are communicably connected by a dual communication path using different communication lines, namely the data communication line 201 and the verification communication line 203. Thereby, it is possible to perform processing for security verification, such as a request for verification software data, on the verification communication line 203 without affecting the relay processing of the out-of-vehicle communication data via the data communication line 201.

[0058] The first processing unit 21 acquires software data from the second processing unit 22 (S103). The first processing unit 21 acquires software data from the second processing unit 22 via the verification communication line 203. The first processing unit 21 stores the software data acquired from the second processing unit 22 in the first storage unit 212.

[0059] The first processing unit 21 determines whether the acquired software data is legitimate (S104). In the first storage unit 212 of the first processing unit 21, the same data (software data) as the software data acquired from the second processing unit 22 is stored in advance as verification data. The first processing unit 21 performs security verification (security treatment) on the software data acquired from the second processing unit 22 by comparing the software data acquired from the second processing unit 22 with the software data (verification data) stored in advance in the first storage unit 212.

[0060] When the software data obtained from the second processing unit 22 is the same as the software data (verification data) previously stored in the first storage unit 212, the first processing unit 21 determines that the software data obtained from the second processing unit 22 is legitimate. When the software data obtained from the second processing unit 22 is different from the software data (verification data) previously stored in the first storage unit 212, the first processing unit 21 determines that the software data obtained from the second processing unit 22 is inappropriate.

[0061] In this embodiment, although the same data (software data) as the software data obtained from the second processing unit 22 is previously stored as verification data in the first storage unit 212 of the first processing unit 21, it is not limited to this. The first storage unit 212 may store a hash value generated based on the software data obtained from the second processing unit 22. In this case, the first processing unit 21 performs security verification (security processing) by hash-converting the software data obtained from the second processing unit 22 and comparing the generated hash value with the hash value previously stored in the first storage unit 212 as verification data. Alternatively, when the first processing unit 21 has, for example, an HSM (Hardware Security Module), security verification (security processing) for the software data obtained from the second processing unit 22 may be performed using the HSM to determine whether the software data is legitimate.

[0062] When it is determined that the software data is valid (S104: YES), the first processing unit 21 determines that the second processing unit 22 is normal (S105). When the first processing unit 21 determines that the software data acquired from the second processing unit 22 is valid (normal), the first processing unit 21 determines that the second processing unit 22 is normal. The first processing unit 21 may store the result of the determination of normality in the first storage unit 212 as history information in association with time point information indicating the date and time when the security verification was performed or a time stamp or the like. After executing S105, the first processing unit 21 may perform a loop process to execute the process from S101 again.

[0063] When it is determined that the software data is not valid (S104: NO), the first processing unit 21 determines that the second processing unit 22 is abnormal (S1041). When the first processing unit 21 determines that the software data is not valid, that is, inappropriate (abnormal), the first processing unit 21 determines that the second processing unit 22 is abnormal. The first processing unit 21 may store the result of the determination of abnormality in the first storage unit 212 as history information in association with time point information indicating the date and time when the security verification was performed or a time stamp or the like.

[0064] The first processing unit 21 deactivates the second processing unit 22 (S1042). The first processing unit 21 performs a process for deactivating the second processing unit 22 determined to be abnormal as a result of the security verification. The process for deactivating includes, for example, cutting off the power supply to the second processing unit 22, forcibly stopping (shutting down) the second processing unit 22, cutting off the data communication line 201 with the second processing unit 22, or invalidating the communication port connected to the data communication line 201.

[0065] When cutting off the power supply to the second processing unit 22 as a process for inactivation, the first processing unit 21 may turn off a relay or semiconductor switch provided in the power line that supplies power to the second processing unit 22. When performing forced stop (shutdown) of the second processing unit 22 as a process for inactivation, the first processing unit 21 may output (transmit) a forced stop signal to the second processing unit 22 via the verification communication line 203. When cutting off the data communication line 201 with the second processing unit 22 as a process for inactivation, the first processing unit 21 may turn off a relay or semiconductor switch provided in the data communication line 201. When invalidating the communication port connected to the data communication line 201 as a process for inactivation, the first processing unit 21 may stop supplying power to the data communication unit 202 provided in its own unit. Even in this case, the first processing unit 21 may maintain the activation state of the verification communication unit 204 and continue the communicable state with the second processing unit 22 via the verification communication line 203. The first processing unit 21 may store, as history information in the first storage unit 212, the details of the measures taken to inactivate the second processing unit 22 in association with the result of determining it as an abnormality.

[0066] The second processing unit 22 (second control unit 221) outputs software data (T101) in response to a request from the first processing unit 21. The second processing unit 22 acquires data (request signal) regarding the request output from the first processing unit 21, and outputs the software data stored in the second storage unit 222 to the first processing unit 21 in response to the request. The second processing unit 22 may output (transmit) the software data to the first processing unit 21 via the verification communication line 203. When the request output from the first processing unit 21 designates a specific file (software data) such as a program file or a setting file to be the output target, the designated file (software data) is output to the first processing unit 21.

[0067] The second processing unit 22 transitions to an inactivated state by the inactivation processing performed by the first processing unit 21 (T102). Based on the result of the security verification, when the first processing unit 21 determines that the second processing unit 22 is abnormal, the first processing unit 21 performs a measure for inactivating the second processing unit 22. By this measure, the second processing unit 22 will transition to an inactivated state. Thereby, for example, the second processing unit 22 that has become in an abnormal state due to unauthorized access from outside the vehicle or the like (security attack) can be substantially disconnected (separated) from the in-vehicle network 3, and it can be prevented that the control of the vehicle C (vehicle C system) is affected by the second processing unit 22. Based on the result of the security verification, when the first processing unit 21 determines that the second processing unit 22 is normal, the first processing unit 21 does not perform a measure for inactivating the second processing unit 22, so the activated state of the second processing unit 22 is maintained (continued).

[0068] (Embodiment 2) FIG. 4 is a flowchart illustrating the processing of the first processing unit 21 and the second processing unit 22 of the in-vehicle device 2 according to Embodiment 2 (return signal). The in-vehicle device 2 constantly performs the following processing, for example, when the vehicle C is in a startup state (IG switch is on) or a stop state (IG switch is off), as in Embodiment 1. A series of processing of the first processing unit 21 (in-vehicle microcomputer) and the second processing unit 22 (out-of-vehicle microcomputer) of the in-vehicle device 2 is performed in association with each other. First, the processing by the first processing unit 21 (in-vehicle microcomputer) will be described, and thereafter, the processing by the second processing unit 22 (out-of-vehicle microcomputer) will be described.

[0069] The first processing unit 21 (the first control unit 211) determines whether a predetermined period has elapsed (S201). The first processing unit 21 requests software data from the second processing unit 22 (S202). The first processing unit 21 acquires software data from the second processing unit 22 (S203). The first processing unit 21 determines whether the acquired software data is legitimate (S204). When it is determined that the software data is legitimate (S204: YES), the first processing unit 21 determines that the second processing unit 22 is normal (S205). The first processing unit 21 performs the processes of S201 to S205 in the same manner as the processes of S101 to S105 in Embodiment 1.

[0070] When it is determined that the software data is not legitimate (S204: NO), the first processing unit 21 determines that the second processing unit 22 is abnormal (S2041). The first processing unit 21 performs the process of S2041 in the same manner as the process of S1041 in Embodiment 1.

[0071] The first processing unit 21 executes a recovery process for the second processing unit 22 (S2042). When the first processing unit 21 determines that the second processing unit 22 is abnormal, it performs a recovery process for restoring the second processing unit 22. The recovery process for restoring the second processing unit 22 includes, for example, restarting the second processing unit 22 by cutting off and then supplying power to the second processing unit 22, or outputting a recovery signal to the second processing unit 22.

[0072] As a return process, when restarting the second processing unit 22 by cutting off and then resupplying power to the second processing unit 22, the first processing unit 21 may turn off and then turn on again a relay or semiconductor switch provided in the power line for supplying power to the second processing unit 22. The return signal for the second processing unit 22 may be, for example, a signal including a reboot, initialization of the second processing unit 22, or a program pre-stored in the storage unit of the first processing unit 21 and an execution instruction for the program. The return signal may be output (transmitted) from the first processing unit 21 to the second processing unit 22 via the verification communication line 203. If the result of the security verification (verification result) for the second processing unit 22 continues to be abnormal even though the first processing unit 21 has output the return signal to the second processing unit 22 a plurality of times (a predetermined number of times), the first processing unit 21 may deactivate the second processing unit 22 in the same manner as in Embodiment 1.

[0073] The second processing unit 22 (second control unit 221) outputs software data (T201) in response to a request from the first processing unit 21. The second processing unit 22 performs the process of T201 in the same manner as the process T101 of Embodiment 1.

[0074] The second processing unit 22 executes a return process (T202) by the return process performed by the first processing unit 21. Based on the result of the security verification, when the first processing unit 21 determines that the second processing unit 22 is abnormal, the first processing unit 21 takes measures to return the second processing unit 22. By this measure, the second processing unit 22 executes a return process, for example, by restarting, loading and executing a normal program transmitted from the first processing unit 21, etc. Thereby, for example, the second processing unit 22 that has become in an abnormal state due to an unauthorized access from outside the vehicle or the like (security attack) can be transitioned (returned) to a normal state.

[0075] (Embodiment 3) FIG. 5 is a schematic diagram illustrating the system configuration of the in-vehicle system S according to Embodiment 3 (connected to the actuator 5). In the present embodiment, the in-vehicle ECU 4 directly connected to an actuator 5 such as a motor also includes a first processing unit 41 and a second processing unit 42, similar to the in-vehicle device 2 described in Embodiment 1. The configurations and processes of the first processing unit 41 and the second processing unit 42 of the in-vehicle ECU 4 are the same as the configurations and processes of the first processing unit 21 and the second processing unit 22 of the in-vehicle device 2.

[0076] The first processing unit 41 of the in-vehicle ECU 4 is not directly connected to the in-vehicle network 3 but is directly connected to an actuator 5 such as a motor. The second processing unit 42 of the in-vehicle ECU 4 is directly connected to the in-vehicle network 3. The first processing unit 41 and the second processing unit 42 of the in-vehicle ECU 4 are communicably connected by a data communication line 201 and a verification communication line 203, similar to the in-vehicle device 2 of Embodiment 1.

[0077] The first processing unit 41 and the second processing unit 42 included in the in-vehicle ECU 4 perform security verification, similar to the in-vehicle device 2 of Embodiment 1. The first processing unit 41 located on the actuator 5 side performs security verification (security treatment) on the second processing unit 42 located on the in-vehicle network 3 side. That is, the first processing unit 41 located on the actuator 5 side acquires software data from the second processing unit 42 located on the in-vehicle network 3 side and performs security verification (security treatment) on the software data to determine whether the second processing unit 42 is normal. Thereby, in the in-vehicle ECU 4 in which a plurality of processing units (microcontrollers) are mounted, the integrity of the second processing unit 42 on the in-vehicle network 3 side can be ensured, and resistance to security attacks from outside the vehicle via the in-vehicle network 3 can be provided.

[0078] In this embodiment, the second processing unit 42 is located on the in-vehicle network 3 side, and the first processing unit 41 is located on the actuator 5 side. However, the present invention is not limited to this. The first processing unit 41 may be located on the in-vehicle network 3 side, and the second processing unit 42 may be located on the actuator 5 side. Thus, in the in-vehicle ECU 4 in which a plurality of processing units (microcontrollers) are mounted, the integrity of the second processing unit 42 on the actuator 5 side can be ensured, and the in-vehicle ECU 4 can be provided with resistance to security attacks from the actuator 5 side.

[0079] The embodiments disclosed this time should be considered as illustrative in all respects and not restrictive. The scope of the present disclosure is shown not by the above meaning but by the scope of claims, and it is intended that all modifications within the meaning and scope equivalent to the scope of claims are included.

Explanation of Reference Numerals

[0080] C Vehicle S In-vehicle system 100 External server 101 Diagnostic device 1 Vehicle exterior communication device 11 Antenna 2 In-vehicle device (relay device) 21 First processing unit (in-vehicle side microcontroller) 211 First control unit 212 First storage unit 213 In-vehicle communication unit 22 Second processing unit (vehicle exterior side microcontroller) 221 Second control unit 222 Second storage unit 223 Vehicle exterior communication unit M Recording medium P Program (program product) 201 Communication line for data 202 Communication unit for data 203 Communication line for verification 204 Communication unit for verification 3 In-vehicle network 31 Communication cable 4 In-vehicle ECU 41 First processing unit 42 Second processing unit 5 Actuator

Claims

1. An in-vehicle device mounted on a vehicle having an in-vehicle network, comprising: a first processing unit connected to the in-vehicle network; a second processing unit communicably connected to the first processing unit; wherein the first processing unit: obtains data regarding a program executed by the second processing unit from the second processing unit; performs security verification on the obtained data; determines whether the second processing unit is normal based on the result of the security verification; when it is determined based on the result of the security verification that the second processing unit is abnormal, performs a recovery process for recovering the second processing unit; when the result of the security verification for the second processing unit continues to be abnormal despite outputting a recovery signal for performing the recovery process to the second processing unit a plurality of times, deactivates the second processing unit In-vehicle device.

2. The second processing unit obtains out-vehicle communication data from an external device outside the vehicle, The first processing unit and the second processing unit are connected by a data communication line through which the out-vehicle communication data flows and a verification communication line through which data for the security verification flows. The in-vehicle device according to claim 1.

3. The first processing unit designates data to be output to the first processing unit for the second processing unit, The second processing unit outputs the data designated by the first processing unit as data regarding the program. The in-vehicle device according to claim 1 or claim 2.

4. The second processing unit includes a second storage unit, Data regarding the program executed by the second processing unit is stored in the second storage unit. The in-vehicle device according to any one of claims 1 to 3.

5. The processing performance of the second processing unit is lower than that of the first processing unit. The in-vehicle device according to any one of claims 1 to 4.

6. When it is determined based on the result of the security verification that the second processing unit is abnormal, the first processing unit performs a process for deactivating the second processing unit. The in-vehicle device according to any one of claims 1 to 5.

7. A plurality of in-vehicle ECUs are connected to the in-vehicle network, The first processing unit relays the data obtained from the second processing unit to the in-vehicle ECU via the in-vehicle network. The in-vehicle device according to any one of claims 1 to 6.

8. A computer mounted on a vehicle having an in-vehicle network, comprising a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit, in the first processing unit, obtain data regarding a program executed by the second processing unit from the second processing unit, perform security verification on the obtained data, determine whether the second processing unit is normal based on the result of the security verification, when it is determined based on the result of the security verification that the second processing unit is abnormal, perform a recovery process for recovering the second processing unit, if the result of the security verification for the second processing unit continues to be abnormal despite outputting a recovery signal for performing the recovery process to the second processing unit a plurality of times, deactivate the second processing unit An information processing method for causing the execution of the process.

9. A computer mounted on a vehicle having an in-vehicle network, comprising a first processing unit connected to the in-vehicle network and a second processing unit communicably connected to the first processing unit, in the first processing unit, obtain data regarding a program executed by the second processing unit from the second processing unit, perform security verification on the obtained data, determine whether the second processing unit is normal based on the result of the security verification, when it is determined based on the result of the security verification that the second processing unit is abnormal, perform a recovery process for recovering the second processing unit, if the result of the security verification for the second processing unit continues to be abnormal despite outputting a recovery signal for performing the recovery process to the second processing unit a plurality of times, deactivate the second processing unit A program for causing the execution of the process.

Citation Information

Patent Citations

  • Electronic control device

    JP2016126716A

  • On-vehicle device, relay device, and computer programs

    JP2018116669A

  • Communication system

    JP2021022801A

  • Secure boot for vehicular systems

    US9792440B1