Mobile body control device, mobile body control method, and program

The secure boot process in movement control devices addresses false tampering detections by allowing continued use of essential functions until standby, enhancing safety and reducing disruptions.

JP7716527B1Active Publication Date: 2025-07-31HONDA MOTOR CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024050799
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-03-27
Publication Date
2025-07-31
Estimated Expiration
2044-03-27

AI Technical Summary

Technical Problem

In movement control devices, such as vehicles, secure boot processing for software integrity can lead to false detections of tampering, causing unnecessary interruptions in operation, which disrupts user usage and compromises traffic safety.

Method used

A secure boot process is executed by a tampering recognition unit, allowing continued use of predetermined functions until the device enters a standby state, with enhanced detection criteria during active use to minimize false positives, and responsive actions based on function type and location.

Benefits of technology

This approach reduces the likelihood of false detections, maintaining functionality during active use and ensuring safety by minimizing unnecessary shutdowns due to software tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007716527000001_ABST
    Figure 0007716527000001_ABST
Patent Text Reader

Abstract

To prevent interruption of use of a mobile device due to false detection of software tampering. [Solution] The mobile body control device 1 is equipped with a tampering recognition unit 22 that executes a secure boot process to verify whether software stored in a memory unit provided in the mobile body 100 has been tampered with, and recognizes software tampering, and a tampering response unit 23 that executes a tampering response suspension process to maintain a state in which the specified function can be used until the mobile body 100 enters a standby state, if the tampering recognition unit 22 recognizes tampering of software related to a specified function of the mobile body 100 when the mobile body 100 is in an activated state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a movement control device, a movement control method, and a program.

Background Art

[0002] Conventionally, when starting an electronic device, there is known a secure boot technology that verifies the presence or absence of tampering of software such as firmware and starts the device when it is certified that there is no tampering (see, for example, Patent Document 1). Patent Document 1 discloses a technique for shortening the startup time by collectively certifying that a plurality of firmware, which is the object of verifying the presence or absence of tampering, is not tampered with.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Also in a movement control device, which is an example of an electronic device, in order to improve traffic safety, secure boot processing is performed, and in addition to when the moving body starts up, secure boot processing is also performed in the background during operation. In this way, by performing secure boot processing even during the operation of the moving body, the reliability of the software can be improved. However, there is a concern that the possibility of false detection of tampering increases due to an increase in the timing of performing secure boot processing. When tampering of software is detected by secure boot processing, the operation of the moving body is stopped. However, even when false detection occurs, the operation of the moving body is similarly stopped. In this case, there is a disadvantage that the use of the moving body by the user is interrupted. Therefore, it is an object of the present application to suppress the interruption of the use of the moving body due to false detection of software tampering. The present application aims to improve safety in order to solve the above problems, and further contributes to the development of a sustainable transportation system by further improving traffic safety.

Means for Solving the Problems

[0005] As a first aspect for achieving the above object, a secure boot process for verifying the presence or absence of software tampering stored in a storage unit provided in a moving body is executed to recognize a tampering recognition unit for recognizing software tampering, and when the moving body is in an activated state, the secure boot process is executed by the tampering recognition unit, and when the tampering recognition unit recognizes software tampering related to a predetermined function of the moving body, a tampering response hold process for maintaining a state in which the use of the predetermined function is possible until the moving body enters a standby state is executed, and after the moving body enters the standby state, a tampering response unit for disabling the use of the predetermined function is provided. A mobile body control device is mentioned.

[0006] In the above mobile body control device, the tampering recognition unit may execute the secure boot process a plurality of times, and when tampering is continuously detected a predetermined number of times or more by the secure boot process, or when the ratio of the number of times tampering is detected among the number of executions of the plurality of secure boot processes is equal to or greater than a predetermined determination ratio, the recognition of software tampering may be determined.

[0007] In the above mobile body control device, the tampering recognition unit may set the determination number of times when the moving body is in an activated state to be larger than the determination number of times when the moving body is in a standby state, and set the determination ratio when the moving body is in an activated state to be larger than the determination ratio when the moving body is in a standby state.

[0008] In the above mobile body control device, the tampering recognition unit may change the determination number of times and the determination ratio according to the predetermined function.

[0009] In the above-described mobile body control device, when the mobile body is in an activated state, if the secure boot process is executed by the tampering recognition unit and the tampering recognition unit recognizes tampering of the software related to the predetermined function of the mobile body, the tampering response unit may be configured to determine whether to execute the tampering response suspension process according to the type of the predetermined function.

[0010] In the above-described mobile body control device, the mobile body is a vehicle, and includes a mobile body position recognition unit that recognizes the position of the mobile body. When the mobile body is in an activated state and the mobile body position recognition unit recognizes that the mobile body is located outside a road, if the secure boot process is executed by the tampering recognition unit and the tampering recognition unit recognizes tampering of the software related to the predetermined function of the mobile body, the use of the predetermined function may be disabled without executing the tampering response suspension process.

[0011] In the above-described mobile body control device, when the tampering recognition unit recognizes tampering of the software, the device may be configured to include a tampering notification unit that outputs warning information about the tampering of the software from a notification device used in the mobile body.

[0012] In the above-described mobile body control device, when the tampering recognition unit recognizes tampering of the software, the device may be configured to include a tampering notification unit that transmits warning information about the tampering of the software to a user terminal used by a user of the mobile body.

[0013] As a second aspect for achieving the above object, a movement control method executed by a computer, comprising: a tampering recognition step of executing a secure boot process for verifying the presence or absence of tampering of software stored in a storage unit provided in a moving body, and recognizing the tampering of the software; and a tampering response suspension process of maintaining a state in which the predetermined function can be used until the moving body enters a standby state when the secure boot process is executed by the tampering recognition step and the tampering of the software related to the predetermined function of the moving body is recognized by the tampering recognition step when the moving body is in an activated state, and a tampering response step of disabling the use of the predetermined function after the moving body enters the standby state.

[0014] As a third aspect for achieving the above object, a program for causing a computer to function as: a tampering recognition unit that executes a secure boot process for verifying the presence or absence of tampering of software stored in a storage unit provided in a moving body, and recognizes the tampering of the software; and a tampering response suspension process of maintaining a state in which the predetermined function can be used until the moving body enters a standby state when the secure boot process is executed by the tampering recognition unit and the tampering of the software related to the predetermined function of the moving body is recognized by the tampering recognition unit when the moving body is in an activated state, and a tampering response unit that disables the use of the predetermined function of the moving body after the moving body enters the standby state.

Advantages of the Invention

[0015] According to the above movement control device, movement control method, and program, it is possible to suppress the interruption of the use of the moving body due to false detection of software tampering.

Brief Description of the Drawings

[0016]

Figure 1

Figure 2

Figure 3

Embodiments for Carrying Out the Invention

[0017] [1. Configuration of the Movement Control Device] With reference to FIG. 1, the configuration of the movement control device 1 of the present embodiment will be described. The movement control device 1 is mounted on the vehicle 100 and controls the operation of the vehicle 100. The vehicle 100 corresponds to the moving body of the present disclosure. The moving body of the present disclosure may be an aircraft, a ship, etc. in addition to a vehicle. The vehicle 100 is provided with an SS (start / stop) switch 2 for instructing the start and stop (power on and power off) of the vehicle 100, a communication unit 3, a navigation device 4, and a display 5. In response to the start operation (start operation) of the SS switch 2, the vehicle 100 enters an operable start state, and in response to the stop operation (stop operation) of the SS switch, the vehicle 100 enters an inoperable standby state.

[0018] The communication unit 3 communicates with the mobile body management server 210 and the user terminal 90 used by the user U of the mobile body via the communication network 200, and also performs short-range wireless communication with the user terminal 90 by Bluetooth (registered trademark), Wifi (registered trademark), etc. The navigation device 4 has a GNSS (Global Navigation Satellite System) sensor for detecting the position of the vehicle 100 and performs route guidance to the destination.

[0019] The movement control device 1 includes a central ECU (Electronic Control Unit) 10, gateway ECUs 50a, 50b, and local ECUs 51a to 51f. The central ECU 10 is connected to the gateway ECU 50a by a communication line 40a and is also connected to the gateway ECU 50b by a communication line 40b.

[0020] The gateway ECU 50a is connected to a plurality of local ECUs 51a to 51c via the communication line 41a, and the gateway ECU 50b is connected to a plurality of local ECUs 51d to 51f via the communication line 41b. The local ECUs 51a to 51c control the operations of in-vehicle devices 71 to 73 provided in the vehicle 100. The in-vehicle devices 71 to 73 are, for example, drive sources such as engines and electric motors, driving operation units such as steering wheels, brake pedals, and accelerator pedals, lighting bodies such as headlights, auxiliary machines such as wipers, electric equipment such as power sliding doors and power windows, and air conditioners. Further, the local ECU 51d controls the operation of the communication unit 3, the local ECU 51e controls the operation of the navigation device 4, and the local ECU 51f controls the operation of the display 5.

[0021] Hereinafter, the gateway ECU 50a and the gateway ECU 50b are collectively referred to as the gateway ECU 50, and the local ECUs 51a to 51f are collectively referred to as the local ECU 51. Also, the devices connected to the local ECU 51 are collectively referred to as in-vehicle devices. The central ECU 10, the gateway ECU 50, and the local ECU 51 are control units provided with a processor, a memory, an interface circuit, and the like.

[0022] The plurality of local ECUs 51 connected to the gateway ECU 50 are grouped according to the functions and arrangement locations of the in-vehicle devices connected to the local ECUs 51. In FIG. 1, two gateway ECUs 50a and 50b are illustrated, but three or more gateway ECUs 50 may be provided. Also, the number of in-vehicle devices connected to the local ECU 51 may be two or more.

[0023] The Central ECU 10 executes the management of the mobile unit 100 via OTA (Over The Air), downloads the new version of the software of the Local ECU 51 (the software for update) from the mobile unit management server 210, and executes the process of updating the software of the Local ECU 51. Further, the Central ECU 10 executes a process of monitoring whether there is any tampering with the software stored in the memory of the Local ECU 51. Hereinafter, the tampering recognition process of the software of the Local ECU 51 executed by the Central ECU 10 and the corresponding process when tampering with the software is detected will be described.

[0024] The Central ECU 10 includes a processor 20, a memory 30, etc., and a control program 31 for the Central ECU 10 is stored in the memory 30. The processor 20 corresponds to the computer of the present disclosure. The processor 20 functions as a communication control unit 21, a tampering recognition unit 22, a tampering response unit 23, a mobile unit position recognition unit 24, and a tampering notification unit 25 by reading and executing the program 31.

[0025] The process executed by the tampering recognition unit 22 corresponds to the tampering recognition step in the mobile unit control method of the present disclosure, and the process executed by the tampering response unit 23 corresponds to the tampering response step in the mobile unit control method of the present disclosure.

[0026] The communication control unit 21 controls the communication between the mobile unit management server 210 and the user terminal 90 by the communication unit 3. The tampering recognition unit 22 executes a secure boot process for verifying whether there is any tampering with the software stored in the memory of the Local ECU 51, and recognizes the tampering of the software. When the tampering response unit 23 recognizes the tampering of the software of the Local ECU 51 by the tampering recognition unit 22, it executes a process of disabling the use of a predetermined function realized by the operation of the software. Details of this process will be described later.

[0027] The moving body position recognition unit 24 recognizes the position of the vehicle 100 detected by the GNSS sensor of the navigation device 4 through communication with the navigation device 4. When the forgery recognition unit 22 recognizes that the local software has been forged, the forgery notification unit 25 transmits forgery notification information for notifying the display 5 that the local software has been forged, and causes the display 5 to display a forgery notification screen indicating that the local software has been forged. Further, when the forgery recognition unit 22 recognizes that the local software has been forged, the forgery notification unit 25 transmits forgery notification information for notifying the user terminal 90 that the local software has been forged, and causes the display unit of the user terminal 90 to display a forgery notification screen indicating that the local software has been forged. [2. Software forgery monitoring process] According to the flowcharts shown in FIGS. 2 to 3, the procedure of the software forgery monitoring process of the local ECU 51 executed by the movement control device 1 will be described. When the vehicle 100 is in the start state and when the vehicle 100 is in the standby state, the movement control device 1 executes the process according to the flowcharts of FIGS. 2 to 3 on the software stored in the memories of the plurality of local ECUs 51 at a predetermined timing to monitor for forgery. The execution timing of the secure boot process is set, for example, when the vehicle 100 enters the standby state by the stop operation of the SS switch 2, or every time a predetermined time elapses.

[0028] In step S1 of FIG. 2, the forgery recognition unit 22 resets a counter variable CT for counting the number of times forgery has been detected (0 → CT). In the subsequent step S2, for the software of the local ECU 51 that is the target of the secure boot (hereinafter referred to as the target software), the secure boot process is executed to verify the presence or absence of forgery. In the subsequent step S3, when the forgery recognition unit 22 detects forgery of the target software, the process proceeds to step S10, and when forgery of the target software is not detected, the process proceeds to step S4 to end the current forgery monitoring process.

[0029] In step S10, the tampering recognition unit 22 counts up the counter variable CT (CT+1→CT). In the following step S12, the tampering recognition unit 22 determines whether the vehicle 100 is in an activated state, and if it is in an activated state, proceeds to step S20, and if it is not in an activated state (if it is in a standby state), proceeds to step S20.

[0030] In step S12, the tampering recognition unit 22 determines whether the counter variable CT is equal to or greater than the first determination count X1. If the counter variable CT is equal to or greater than the first determination count X1, the tampering recognition unit 22 confirms the recognition of tampering of the target software and proceeds to step S13, whereas if the counter variable CT is less than the first determination count, the tampering recognition unit 22 proceeds to step S2.

[0031] In step S13, the tampering notification unit 25 displays a tampering notification screen on the display 5 or the display unit of the user terminal 90, as described above. In the following step S14, the tampering response unit 23 prohibits the startup of the vehicle 100 as a first boot process against the tampering. The user U visually checks the tampering notification screen, recognizes that the target software has been tampered with, and requests a road service company or the like to handle the breakdown of the vehicle 100.

[0032] By processing steps S2, S3, S10 to S14, when tampering with the target software is detected consecutively for the first determination number X1 or more, the recognition of tampering with the target software is confirmed, thereby preventing the vehicle 100 from entering a startup prohibition state due to a false detection of tampering.

[0033] In step S20, the tampering recognition unit 22 determines whether the counter variable CT is equal to or greater than the second determination count X2. If the counter variable CT is equal to or greater than the second determination count X2, the tampering recognition unit 22 confirms that the target software has been tampered with and proceeds to step S21 in Fig. 3, whereas if the counter variable CT is less than the second determination count X2, the tampering recognition unit 22 proceeds to step S2.

[0034] Here, the second determination count X2 corresponding to the case where the vehicle 100 is in the activated state is set to a number greater than the first determination count X1 corresponding to the case where the vehicle 100 is in the standby state. Thereby, since the vehicle 100 is in the activated state, when the user U is using the vehicle 100 and the risk of theft or the like of the vehicle 100 is low, it is possible to suppress the boot process of the vehicle 100 from being executed and the use of the vehicle 100 from being interrupted due to a false detection of alteration of the target software.

[0035] In step S21 of FIG. 3, as described above, the alteration notification unit 25 causes the alteration notification screen to be displayed on the display 5 or the display unit of the user terminal 90. In the subsequent step S22, the alteration handling unit 23 determines whether or not the control target by the target software in which the alteration is recognized is a predetermined function. Here, the predetermined function is a function that does not hinder the running of the vehicle 100 (for example, an entertainment function such as the display of content by the display 5, a communication function by the communication unit 3, air conditioning, a connection function with a portable device by an interface such as USB (registered trademark), etc.).

[0036] Then, when the control target by the target software is a predetermined function, the alteration handling unit 23 advances the process to step S30, and when the control target by the target software is not a predetermined function, the alteration handling unit 23 advances the process to step S23. In step S23, when the vehicle 100 is in the activated state, the alteration handling unit 23 executes a second boot process and advances the process to step S4 of FIG. 2.

[0037] As the second boot process, when the vehicle 100 is running, the alteration handling unit 23 performs a degradation control such as deceleration or guidance to stop on the road shoulder, and after the vehicle 100 stops, when the vehicle 100 becomes in the standby state in response to the operation of the SS switch 2, the alteration handling unit 23 performs a process of prohibiting the activation of the vehicle 100.

[0038] In step S30, the tampering response unit 23 determines whether the current position of the vehicle 100 recognized by the moving body position recognition unit 24 is outside the road. Then, when the current position of the vehicle 100 is outside the road, the tampering response unit 23 proceeds with the process to step S22, and when the current position of the vehicle 100 is on the road, the tampering response unit 23 proceeds with the process to step S31.

[0039] In step S31, when the vehicle 100 enters the standby state in response to the operation of the SS switch 2, the tampering response unit 23 proceeds with the process to step S32. Similar to step S14 of FIG. 2 described above, the tampering response unit 23 executes the first boot process corresponding to the standby state and proceeds with the process to step S4 of FIG. 2. The process of step S30 corresponds to the tampering response hold process of the present disclosure.

[0040] [3. Other Embodiments] In the above embodiment, the tampering recognition unit 22 determines the recognition of the tampering of the target software when the tampering of the target software is continuously detected a predetermined number of times or more by the secure boot process. As another embodiment, the tampering recognition unit 22 may execute the secure boot process a plurality of times, and when the ratio of the number of times the tampering of the target software is detected among the plurality of execution times is equal to or greater than a predetermined determination ratio, the recognition of the tampering of the target software may be determined. In this case, the second determination ratio corresponding to the case where the vehicle 100 is in the startup state may be set to a larger ratio (the first determination ratio < the second determination ratio) than the first determination ratio corresponding to the case where the vehicle 100 is in the standby state.

[0041] Also, the first determination count, the second determination count, the first determination ratio, and the second determination ratio may be changed according to a predetermined function related to the target software. For example, the first determination count and the second determination count for the target software of the driving control system of the vehicle 100 may be set to be less than the first determination count and the second determination count for the target software related to controls other than the driving control system (target software related to air conditioning, entertainment, etc.). Also, the first determination ratio and the second determination ratio for the target software of the driving control system of the vehicle 100 may be set to be less than the first determination ratio and the second determination ratio for the target software related to controls other than the driving control system (target software related to air conditioning, entertainment, etc.).

[0042] In the above embodiment, the forgery recognition unit 22 sets the second determination count X2 corresponding to the case where the vehicle 100 is in the startup state to be more than the first determination count X1 corresponding to the case where the vehicle 100 is in the standby state (X1 < X2). As another embodiment, the first determination count X1 and the second determination count may be set to the same number. Also, when forgery of the target software is detected by the secure boot process, the recognition of the forgery of the target software may be determined without determining the detection count of the forgery.

[0043] In the above embodiment, the mobile body position recognition unit 24 is provided, and the forgery countermeasure unit 23 determines in step S30 of FIG. 3 whether the current position of the vehicle 100 is outside the road, and holds the execution of the first boot process in step S32 until the vehicle 100 enters the standby state in step S31. As another embodiment, the mobile body position recognition unit 24 may be omitted and the determination in step S30 may not be performed.

[0044] In the above embodiment, the forgery countermeasure unit 23 determines, in step S22 of FIG. 3, whether to suspend the execution of the first boot process in step S32 until the vehicle 100 enters the standby state according to the type of the control target by the target software. As another embodiment, the determination process in step S22 may be omitted, and the execution of the first boot process in step S32 may be suspended until the vehicle 100 enters the standby state regardless of the type of the control target by the target software.

[0045] In the above embodiment, the forgery notification unit 25 is provided to notify software forgery, but a configuration in which the forgery notification unit 25 is omitted may be employed.

[0046] Note that FIG. 1 is a schematic diagram showing the configuration of the movement control device 1 by classifying it according to the main processing contents in order to facilitate the understanding of the present invention, and the movement control device 1 may be configured by other classifications. Further, the processing of each component may be executed by one hardware unit or by a plurality of hardware units. Also, the processing by each component shown in FIGS. 2 to 3 may be executed by one program or by a plurality of programs.

[0047] [4. Configuration Supported by the Above Embodiment] The above embodiment is a specific example of the following configuration.

[0048] (Configuration 1) A movement control device including: a forgery recognition unit that executes a secure boot process for verifying the presence or absence of forgery of software stored in a storage unit provided in a moving body to recognize the forgery of the software; and a forgery countermeasure suspension process that maintains a state in which the use of a predetermined function is possible until the moving body enters a standby state when the secure boot process is executed by the forgery recognition unit and the forgery of the software related to the predetermined function of the moving body is recognized by the forgery recognition unit when the moving body is in an activated state, and a forgery countermeasure unit that disables the use of the predetermined function after the moving body enters the standby state. According to the movement control device of Configuration 1, when software tampering is recognized while the moving body is in the startup state, by maintaining the state where the use of a predetermined function related to the software is possible until the moving body enters the standby state, it is possible to suppress the moving body from becoming unusable due to a false detection of software tampering.

[0049] (Configuration 2) The tampering recognition unit executes the secure boot process a plurality of times. When tampering is continuously detected a predetermined number of times or more by the secure boot process, or when the ratio of the number of times tampering is detected among the number of executions of the plurality of secure boot processes is equal to or greater than a predetermined determination ratio, the movement control device according to Configuration 1 that determines the recognition of software tampering. According to the movement control device of Configuration 2, by executing the secure boot process a plurality of times and determining the recognition of software tampering, it is possible to reduce the possibility of software tampering being misrecognized.

[0050] (Configuration 3) The tampering recognition unit sets the determination number when the moving body is in the startup state to be larger than the determination number when the moving body is in the standby state, and sets the determination ratio when the moving body is in the startup state to be larger than the determination ratio when the moving body is in the standby state. The movement control device according to Configuration 2. According to the movement control device of Configuration 3, when the moving body is in the startup state and it is assumed that the risk of theft of the moving body is low because the user is using the moving body, by setting a larger determination number than when the moving body is in the standby state, or by setting a larger determination ratio than when the moving body is in the standby state, it is possible to reduce the possibility of software tampering being misrecognized.

[0051] (Configuration 4) The tampering recognition unit changes the determination number and the determination ratio according to the predetermined function. The movement control device according to Configuration 2 or Configuration 3. According to the movement control device of Configuration 4, by changing the appropriate number of determinations and determination ratio according to a predetermined function related to software, it is possible to reduce the possibility that software tampering is misrecognized.

[0052] (Configuration 5) The tampering response unit is configured such that when the moving body is in an activated state and the secure boot process is executed by the tampering recognition unit and the tampering recognition unit recognizes tampering of the software related to the predetermined function of the moving body, according to the type of the predetermined function, it determines whether to execute the tampering response suspension process, and is a movement control device according to any one of Configurations 1 to 4. According to the movement control device of Configuration 5, for example, it is possible to determine whether to execute the tampering response suspension process according to whether the type of the predetermined function related to software contributes to the control of the movement of the moving body or the like.

[0053] (Configuration 6) The moving body is a vehicle, and includes a moving body position recognition unit that recognizes the position of the moving body. The tampering response unit is configured such that when the moving body is in an activated state and it is recognized by the moving body position recognition unit that the moving body is located outside a road, and when the secure boot process is executed by the tampering recognition unit and the tampering recognition unit recognizes tampering of the software related to the predetermined function of the moving body, without executing the tampering response suspension process, it disables the use of the predetermined function, and is a movement control device according to any one of Configurations 1 to 5. According to the movement control device of Configuration 6, when the vehicle is parked in a parking space or the like outside a road and it is assumed that the inconvenience to the user is small even if the use of the predetermined function related to the software in which tampering is recognized is disabled, it is possible to immediately perform the tampering response process by disabling the use of the predetermined function.

[0054] Configuration 7: The mobile body control device according to any one of Configurations 1 to 6, further comprising a forgery notification unit that outputs warning information about the forgery of the software from a notification device used in the mobile body when the forgery recognition unit recognizes the forgery of the software. According to the mobile body control device of Configuration 7, it is possible to notify the user that the software has been forged and prompt the user to take measures against the forgery.

[0055] Configuration 8: The mobile body control device according to any one of Configurations 1 to 7, further comprising a forgery notification unit that transmits warning information about the forgery of the software to a user terminal used by the user of the mobile body when the forgery recognition unit recognizes the forgery of the software. According to the mobile body control device of Configuration 8, it is possible to notify the user that the software has been forged and prompt the user to take measures against the forgery.

[0056] Configuration 9: A mobile body control method executed by a computer, comprising: a forgery recognition step of verifying the presence or absence of forgery of software stored in a storage unit provided in the mobile body by executing a secure boot process to recognize the forgery of the software; and a forgery response suspension process of maintaining a state in which the use of the predetermined function is possible until the mobile body enters a standby state when the secure boot process is executed by the forgery recognition step and the forgery of the software related to the predetermined function of the mobile body is recognized by the forgery recognition step, and a forgery response step of disabling the use of the predetermined function after the mobile body enters the standby state. By executing the mobile body control method of Configuration 9 by a computer, the same operational effects as those of the mobile body control device of Configuration 1 can be obtained.

[0057] Program that causes a computer to function as a modification recognition unit that executes secure boot processing to verify the presence or absence of software tampering stored in a storage unit provided in a moving body and recognizes software tampering, and a modification response hold processing unit that, when the moving body is in an activated state, executes the secure boot processing by the modification recognition unit and, if the modification recognition unit recognizes software tampering related to a predetermined function of the moving body, maintains a state in which the use of the predetermined function is possible until the moving body enters a standby state, and a modification response unit that disables the use of the predetermined function of the moving body after the moving body enters the standby state. By executing the program of Configuration 10 on a computer, the configuration of the mobile body control device of Configuration 1 can be realized.

Explanation of Signs

[0058] 1... Mobile body control device, 2... SS switch, 3... Communication unit, 4... Navigation device, 5... Display, 10... Central ECU, 20... Processor, 21... Communication control unit, 22... Tampering recognition unit, 23... Tampering response unit, 24... Mobile body position recognition unit, 25... Tampering notification unit, 30... Memory, 31... Program, 50(50a, 50b)... Gateway ECU, 51(51a~51f)... Local ECU, 71~73... In-vehicle devices, 90... User terminal, 100... Vehicle (mobile body), 200... Communication network, 210... Mobile body management server, U... User.

Claims

1. A modification recognition unit that executes a secure boot process for verifying the presence or absence of software modification stored in a storage unit provided in a moving body, and recognizes the software modification; When the moving body is in an activated state, if the secure boot process is executed by the modification recognition unit and the modification recognition unit recognizes a modification of the software related to a predetermined function of the moving body, a modification response hold process is executed to maintain a state in which the use of the predetermined function is possible until the moving body enters a standby state, and after the moving body enters the standby state, a modification response unit that disables the use of the predetermined function; A mobile control device comprising:

2. The modification recognition unit executes the secure boot process a plurality of times, and when a modification is continuously detected a predetermined number of times or more by the secure boot process, or when the ratio of the number of times a modification is detected among the number of executions of the plurality of secure boot processes is equal to or greater than a predetermined determination ratio, the recognition of the software modification is confirmed The mobile control device according to claim 1.

3. The modification recognition unit Sets the determination number of times when the moving body is in an activated state to be larger than the determination number of times when the moving body is in a standby state, Sets the determination ratio when the moving body is in an activated state to be larger than the determination ratio when the moving body is in a standby state The mobile control device according to claim 2.

4. The modification recognition unit changes the determination number of times and the determination ratio according to the predetermined function The mobile control device according to claim 2 or claim 3.

5. When the moving body is in an activated state, if the secure boot process is executed by the modification recognition unit and the modification recognition unit recognizes a modification of the software related to the predetermined function of the moving body, the modification response unit determines whether to execute the modification response hold process according to the type of the predetermined function The mobile control device according to any one of claims 1 to 3.

6. The moving body is a vehicle, Comprising a moving body position recognition unit that recognizes the position of the moving body When the tampering response unit determines that the moving body is in an activated state and the moving body position recognition unit recognizes that the moving body is located outside a road, if the secure boot process is executed by the tampering recognition unit and the tampering recognition unit recognizes that the software related to the predetermined function of the moving body has been tampered with, the use of the predetermined function is disabled without executing the tampering response hold process. The mobile body control device according to any one of claims 1 to 3.

7. When the tampering recognition unit recognizes that the software has been tampered with, the device includes a tampering notification unit that outputs warning information about the tampering of the software from a notification device used in the moving body. The mobile body control device according to claims 1 to 3.

8. When the tampering recognition unit recognizes that the software has been tampered with, the device includes a tampering notification unit that transmits warning information about the tampering of the software to a user terminal used by a user of the moving body. The mobile body control device according to claims 1 to 3.

9. A mobile body control method executed by a computer, comprising: a tampering recognition step of executing a secure boot process for verifying the presence or absence of tampering of software stored in a storage unit provided in a moving body, and recognizing the tampering of the software; a tampering response step of, when the moving body is in an activated state, executing the secure boot process in the tampering recognition step and recognizing that the software related to a predetermined function of the moving body has been tampered with in the tampering recognition step, executing a tampering response hold process of maintaining a state in which the use of the predetermined function is possible until the moving body enters a standby state, and disabling the use of the predetermined function after the moving body enters the standby state; A mobile body control method including the above.

10. A computer, a tampering recognition unit that executes a secure boot process for verifying the presence or absence of tampering of software stored in a storage unit provided in a moving body, and recognizes the tampering of the software; When the mobile body is in the activated state, the forgery recognition unit executes the secure boot process. If the forgery recognition unit recognizes forgery of the software related to a predetermined function of the mobile body, a forgery response hold process is executed to maintain a state where the use of the predetermined function is possible until the mobile body enters the standby state. After the mobile body enters the standby state, there is a forgery response unit that disables the use of the predetermined function of the mobile body, and A program that causes it to function.

Citation Information

Patent Citations

  • Tampering detection system and electronic control unit

    JP2014151720A

  • Information processing system

    JP2017167916A

  • Information processing device, and information processing method

    JP2021002168A

  • Control system

    WO2021240700A1