Authentication system, authentication device, and authentication program
The authentication system addresses improper management of confidential information in shared vehicles by using an authentication and authorization management unit to manage access based on user authority, ensuring appropriate service delivery and preventing unauthorized access.
Patent Information
- Application Number
- JP2024530739
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-06-29
- Filing Date
- 2023-06-21
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2043-06-21
AI Technical Summary
In shared vehicles, improper management of confidential information can lead to inappropriate acquisition or lack of necessary information, affecting service provision and user convenience.
An authentication system with an authentication and authorization management unit, secret information management table, and authorization process management table to determine and manage access to confidential information based on user authority, preventing unauthorized access and ensuring appropriate service delivery.
The system effectively manages access to confidential information, ensuring that necessary information is provided to authorized services while preventing inappropriate acquisition, thereby enhancing user convenience and service appropriateness.
Smart Images

Figure 0007718593000001 
Figure 0007718593000002 
Figure 0007718593000003
Abstract
Description
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This international application claims priority based on Japanese Patent Application No. 2022-104543, filed with the Japan Patent Office on June 29, 2022, the entire contents of which are incorporated herein by reference. [Technical Field]
[0002] The present disclosure relates to an authentication system, an authentication device, and an authentication program. [Background technology]
[0003] Patent Document 1 describes an authentication system that includes multiple terminal devices mounted on vehicles and a center connected to the multiple terminal devices via a network, and that switches the authentication method for users who use the terminal devices based on the purpose of the terminal devices. This makes it possible to switch authentication methods, for example, by selecting an authentication method using an ID and password when the terminal device is mounted on a private car, and selecting an authentication method using a mobile terminal carried by the rental car user when the terminal device is mounted on a rental car. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-72976 Summary of the Invention
[0005] In recent years, car sharing has become widespread, and there are increasing opportunities for multiple users to share a single vehicle. When multiple users share a single vehicle, confidential information generated by the multiple users using the vehicle is stored in the same vehicle. Depending on the content of the confidential information, different authorities have the authority to approve the confidential information.
[0006] Furthermore, an increasing number of vehicles are equipped with applications that are configured to acquire vehicle information from the vehicle and provide predetermined services to vehicle users.
[0007] After detailed consideration by the inventors, it was found that if the confidential information stored in the vehicle is not properly managed, the application may not be able to obtain the necessary confidential information, and therefore may not be able to provide appropriate services, or confidential information that should not be provided may be provided to the application.
[0008] The present disclosure aims to improve convenience for vehicle users and to prevent inappropriate acquisition of confidential information.
[0009] One aspect of the present disclosure is an authentication system including at least one service application, a vehicle function block, an authentication and authorization management unit, a secret information management table, and an authorization process management table.
[0010] The at least one service application is configured to provide a service to a user using the vehicle using the vehicle information related to the vehicle.
[0011] The vehicle function block is configured to acquire vehicle information held by an electronic control unit mounted on the vehicle.
[0012] The authentication and authorization management unit is configured to determine whether to authorize a request to acquire confidential information when at least a service application issues a request to acquire confidential information from vehicle information via a vehicle function block.
[0013] The secret information management table defines users who have authorization authority for each of a plurality of pieces of secret information.
[0014] The authorization process management table defines an authorization process for authorizing a secret information acquisition request for each of a plurality of users and a plurality of pieces of secret information.
[0015] The authentication and authorization management unit then determines an authorization process based on the secret information management table and the authorization process management table, and uses the determined authorization process to determine whether or not to authorize the secret information acquisition request.
[0016] The authentication system of the present disclosure configured as above can, when a request for secret information acquisition is made from a service application, identify a user who has authorization authority for the secret information that is the target of the secret information acquisition request, and determine whether to authorize the secret information acquisition request using an authorization process determined for each vehicle user and each piece of secret information. If necessary, the authentication system of the present disclosure can include in the authorization process a process for requesting approval from a user who has authorization authority.
[0017] In this way, the authentication system of the present disclosure can determine whether to provide the secret information requested in the secret information acquisition request to the service application based on an authorization process determined based on a user who has authorization authority, a vehicle user, and the secret information. This prevents the application from being unable to acquire the necessary secret information, resulting in the application being unable to provide appropriate services to the vehicle user, or from providing secret information that should not be provided to the application. Therefore, the authentication system of the present disclosure can improve convenience for the vehicle user and prevent the inappropriate acquisition of secret information.
[0018] Another aspect of the present disclosure is an authentication device including an authentication and authorization management unit, a secret information management table, an authorization process management table, and a vehicle function block.
[0019] The vehicle function block is configured to acquire the secret information when the request to acquire the secret information is authorized by the authentication and authorization management unit.
[0020] The authentication and authorization management unit then determines an authorization process based on the secret information management table and the authorization process management table, and uses the determined authorization process to determine whether or not to authorize the secret information acquisition request.
[0021] The authentication device of the present disclosure configured in this manner is a device included in the authentication system of the present disclosure, and can obtain the same effects as the authentication system of the present disclosure.
[0022] Yet another aspect of the present disclosure is an authentication program for causing a computer to function as an authentication and authorization management unit and a vehicle functional block.
[0023] A computer controlled by the authentication program of the present disclosure can constitute a part of the authentication device of the present disclosure, and can obtain the same effects as the authentication device of the present disclosure.
[0024] Yet another aspect of the present disclosure is an authentication system having a first electronic control unit that manages vehicle information related to a vehicle and a second electronic control unit that has the function of relaying data transmitted from multiple first electronic control units.
[0025] The first electronic control device includes a first storage unit and a first vehicle function block. The first storage unit is configured to store vehicle information. The first vehicle function block is configured to acquire the vehicle information.
[0026] The second electronic control unit includes at least one service application, a second vehicle function block, an authentication and authorization management unit, a secret information management table, and an authorization process management table. The second vehicle function block is configured to acquire vehicle information from the first electronic control unit. The authentication and authorization management unit determines an authorization process based on the secret information management table and the authorization process management table, and determines whether to authorize a secret information acquisition request using the determined authorization process. When the secret information acquisition request is authorized by the authentication and authorization management unit, the at least one service application acquires the secret information via the first vehicle function block of the first electronic control unit or the second vehicle function block of the second electronic control unit, which stores secret information corresponding to the secret information acquisition request.
[0027] The authentication system of the present disclosure configured in this manner can improve convenience for vehicle users and prevent inappropriate acquisition of confidential information. [Brief explanation of the drawings]
[0028] [Figure 1] FIG. 1 is a block diagram showing a configuration of a vehicle control system. [Figure 2] FIG. 2 is a functional block diagram showing the functional configuration of the vehicle control system. [Figure 3] FIG. 2 is a functional block diagram showing the functional configuration of the ECU. [Figure 4] FIG. 10 is a diagram showing the configuration of a privacy information management table. [Figure 5] FIG. 10 is a diagram illustrating the configuration of an authorization process management table. [Figure 6] FIG. 10 is a diagram illustrating the association between current location information and a destination. [Figure 7] FIG. 10 is a sequence diagram showing a procedure when a service application acquires data. [Figure 8] FIG. 10 is a sequence diagram showing a procedure when an authentication and authorization management unit determines an authorization process. [Figure 9] FIG. 10 is a sequence diagram showing a procedure up to when an access control unit transmits a user authentication request. DETAILED DESCRIPTION OF THE INVENTION
[0029] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.
[0030] The vehicle control system 1 of this embodiment is mounted on a vehicle. The vehicle may have an automatic driving function in addition to a manual driving function. The vehicle may be a hybrid vehicle having an engine and an electric motor as a driving source. The vehicle is not limited to a vehicle having an automatic driving function or a hybrid vehicle, but may be a vehicle having only a manual driving function, or a vehicle having only an engine or only an electric motor as a driving source. Hereinafter, a vehicle equipped with the vehicle control system 1 will be simply referred to as a vehicle.
[0031] 1, the vehicle control system 1 includes one ECU 2, a plurality of ECUs 3, a plurality of ECUs 4, an external communication device 5, and an internal communication network 6. ECU is an abbreviation for Electronic Control Unit.
[0032] The ECU 2 realizes coordinated control of the entire vehicle by controlling the plurality of ECUs 3 and 4. The ECU 2 has a function of relaying data that the ECUs 3 and 4 transmit to the in-vehicle communication network 6.
[0033] An ECU 3 is provided for each domain, which is divided according to the vehicle's functions, and mainly controls the multiple ECUs 4 present within that domain. Each ECU 3 is connected to its subordinate ECUs 4 via a lower-level network (e.g., CAN) that is individually provided for each ECU 3. CAN stands for Controller Area Network. CAN is a registered trademark. Examples of domains include the powertrain, body, chassis, and cockpit.
[0034] The ECUs 4 connected to the ECUs 3 belonging to the powertrain domain include, for example, an ECU 4 that controls the engine, an ECU 4 that controls the motor, and an ECU 4 that controls the battery.
[0035] The ECUs 4 connected to the ECU 3 belonging to the body domain include, for example, an ECU 4 that controls an air conditioner, an ECU 4 that controls doors, and the like.
[0036] The ECUs 4 connected to the ECU 3 belonging to the chassis domain include, for example, an ECU 4 that controls braking, an ECU 4 that controls steering, and the like.
[0037] The ECUs 4 connected to the ECUs 3 belonging to the cockpit domain include, for example, an ECU 4 that controls the display of meters and navigation, and an ECU 4 that controls input devices operated by vehicle occupants.
[0038] Furthermore, one or more ECUs 4 do not belong to a domain and are directly connected to the in-vehicle communication network 6 without going through the ECU 3 .
[0039] The external vehicle communication device 5 performs data communication with a communication device outside the vehicle via a wide area wireless communication network.
[0040] The in-vehicle communication network 6 includes CAN FD and Ethernet. Ethernet is a registered trademark. CAN FD stands for CAN with Flexible Data Rate. CAN FD connects the ECU 4 to each ECU 3 and the external-vehicle communication device 5 via a bus. Ethernet individually connects the ECU 4 to each ECU 3 and the external-vehicle communication device 5.
[0041] The ECU2 is an electronic control device mainly composed of a microcomputer including a CPU2a, a ROM2b, a RAM2c, etc. Various functions of the microcomputer are realized by the CPU2a executing a program stored in a non-transitory storage medium. In this example, the ROM2b corresponds to the non-transitory storage medium storing the program. Furthermore, the execution of this program executes a method corresponding to the program. Note that some or all of the functions executed by the CPU2a may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the ECU2 may be one or more.
[0042] Like the ECU 2, the ECU 3, the ECU 4, and the exterior communication device 5 are all electronic control devices mainly configured with a microcomputer equipped with a CPU, ROM, RAM, etc. Furthermore, the number of microcomputers configuring the ECU 3, the ECU 4, and the exterior communication device 5 may be one or more. The ECU 3 controls one or more ECUs 4. The ECU 2 controls one or more ECUs 3, 4, or the exterior communication device 5 for the entire vehicle.
[0043] As shown in FIG. 2, the vehicle control system 1 includes service applications 11 and 12, a user authentication unit 13, an authentication and authorization management unit 14, vehicle function blocks 15, 16, and 17, an access control unit 18, vehicle function databases 21, 22, and 23, and an authorization policy database 25.
[0044] The service applications 11 and 12 are applications created to provide services to vehicle users.
[0045] Examples of services provided to vehicle users include controlling the air conditioner to wake the driver or controlling the windshield wipers to improve the driver's visibility in response to weather changes and the driver's fatigue level along the vehicle's planned route. These services require, for example, acquisition from inside the vehicle of planned route information, interior and exterior temperature information, current vehicle location information, driver age information, driver gender information, and driver body temperature information. Furthermore, these services require acquisition of rainy road information along the planned route from, for example, a social infrastructure platform outside the vehicle. Of the above information acquired from inside the vehicle, the current vehicle location information, driver age information, gender information, and body temperature information are considered private information.
[0046] The service applications 11 and 12 provide different services to the vehicle user.
[0047] The user authentication unit 13 is an application that authenticates the user of the vehicle (that is, the driver).
[0048] The authentication and authorization management unit 14 is an application that authorizes access from the service applications 11 and 12. The authentication and authorization management unit 14 determines whether to authorize access by, for example, performing data communication between an information terminal 110 carried by a vehicle user US1 and an information terminal 120 carried by a vehicle user US2.
[0049] The vehicle function blocks 15, 16, and 17 are applications that collect vehicle information and control the vehicle in order to provide services to the vehicle users. The vehicle function blocks 15, 16, and 17 provide different services to the vehicle users.
[0050] The vehicle information includes, for example, vehicle speed, engine RPM, steering angle, acceleration, position, etc. This vehicle information is information stored in the ECU 4 that controls the engine, the ECU 4 that controls the steering, the ECU 4 that controls the airbag, and the exterior communication device 5.
[0051] The vehicle information may also include images captured by a camera inside the vehicle and images captured by a camera outside the vehicle, and these vehicle information are stored in the ECU 4 that controls the cameras.
[0052] The vehicle information may also be an address registered in a navigation device. This address is information stored in the navigation device connected to the ECU 2.
[0053] The access control unit 18 is an application that provides messaging processing that manages message exchange between the service applications 11 and 12, the user authentication unit 13, and the authentication and authorization management unit 14 and the vehicle function blocks 15 and 16. In this embodiment, the access control unit 18 is, for example, an in-vehicle software platform that complies with AUTOSAR. AUTOSAR is an abbreviation for Automotive Open System Architecture. AUTOSAR is a registered trademark.
[0054] The vehicle function databases 21, 22, and 23 store the vehicle information collected by the vehicle function blocks 15, 16, and 17, respectively.
[0055] The authorization policy database 25 stores a privacy information management table 31 and an authorization process management table 32, which will be described later.
[0056] As shown in FIG. 3, service applications 11 and 12, a user authentication unit 13, an authentication and authorization management unit 14, a vehicle function block 17, an access control unit 18, a vehicle function database 23, and an authorization policy database 25 are mounted on an ECU 2.
[0057] The vehicle function block 15 and the vehicle function database 21 are mounted on one of the ECUs 3. The vehicle function block 15 collects vehicle information from the ECU 3 on which the vehicle function block 15 is mounted and the ECU 4 connected to this ECU 3.
[0058] The vehicle function block 16 and the vehicle function database 22 are mounted in one of the multiple ECUs 3, which is different from the ECU 3 that mounts the vehicle function block 15 and the vehicle function database 21. The vehicle function block 16 collects vehicle information from the ECU 3 that mounts the vehicle function block 16 and the ECU 4 that is connected to this ECU 3.
[0059] The vehicle function block 17 collects vehicle information from the ECU 2 in which the vehicle function block 17 is installed and the ECU 4 directly connected to the in-vehicle communication network 6. The vehicle function block 17 may also collect vehicle information from the ECU 3.
[0060] The external vehicle communication device 5 performs data communication with the information terminals 110 and 120 described above.
[0061] 4, the privacy information management table 31 sets, for each of a plurality of users, whether or not the user has authorization authority for each of a plurality of pieces of privacy information. Authorization authority is the authority to permit an application to use the privacy information.
[0062] 4 shows that the vehicle owner has authorization authority for the vehicle identification information, breakdown / repair history information, current location information, driver monitor images, and registration information (name, age, and gender) that are set as privacy information. Here, the privacy information management table 31 shows that the vehicle owner has authorization authority for the current location information when the vehicle owner uses the vehicle, for the driver monitor images, the owner's own image, and for the registration information, the owner's own information. Note that the privacy information management table 31 may be set so that the vehicle owner has authorization authority for the current location information, including the current location information when other people use the vehicle.
[0063] The privacy information management table 31 indicates that the spouse of the vehicle owner has authorization authority for the current location information, driver monitor images, and registration information. The privacy information management table 31 indicates that the spouse of the vehicle owner does not have authorization authority for the vehicle identification information and breakdown / repair history information.
[0064] The privacy information management table 31 shows that the child of the vehicle owner has authorization authority for the current location information. The privacy information management table 31 also shows that the child of the vehicle owner does not have authorization authority for the driver monitor image or the registration information of the vehicle owner.
[0065] The privacy information management table 31 indicates that the guest (i.e., the person to whom the vehicle is lent) has authorization authority for the current location information, the driver monitor image, and the registration information. The privacy information management table 31 indicates that the guest does not have authorization authority for the vehicle identification information and the breakdown / repair history information.
[0066] As shown in Fig. 5, the authorization process management table 32 is data for defining an authorization process for a user who does not have authorization authority, and an authorization process is set for each of multiple privacy information and multiple applications for each of multiple users. In Fig. 5, a "-" column in which no authorization process is defined indicates that the user has authorization authority and therefore the application can access the privacy information without going through the authorization process. In other words, the authorization process management table 32 also includes information on whether or not the user has authorization authority.
[0067] For example, when an application called "Data Update Service" accesses vehicle identification information, it is defined that if the user is the owner, the authorization process is unnecessary because the user has authorization authority, but if the user is a family member (spouse), family member (child), or guest (renter), the authorization process shown in Figure 5 is to be followed. When an application called "Insurance Service" accesses breakdown / repair history information, it is defined that if the user is the owner, the authorization process is unnecessary because the user has authorization authority, but if the user is a family member (spouse), family member (child), or guest (renter), the authorization process shown in Figure 5 is to be followed. When an application called "Driving Score Rating" accesses registered information (the user's name, age, and gender), it is defined that if the user is the owner, family member (spouse), or guest (renter), the authorization process is unnecessary because the user has authorization authority, but if the user is a family member (child), the authorization process called automatic approval is to be followed. When an application other than "Driving Score Rating" and "Drowsy Driving Detection" accesses registered information, if the user is the owner, a family member (spouse), or a guest (loanee), the authorization process is not required because they have authorization authority, but if the user is a family member (child), an authorization process is required in which approval is requested from the family member (spouse).
[0068] The authorization process consists of the process content and the party to be approved or notified.
[0069] In this embodiment, there are five types of process contents: "approval request," "automatic approval," "automatic approval + notification," "automatic denial," and "automatic denial + notification."
[0070] "Approval request" is a process of requesting approval from an approval destination included in the authorization process.
[0071] "Automatic approval" is a process in which approval is given automatically by a user with authorization authority.
[0072] "Automatic approval + notification" is a process in which approval is automatically performed and the notification destination included in the approval process is notified of the approval.
[0073] "Automatic denial" is a process in which authorization has been denied by a user who has authorization authority and is automatically denied.
[0074] "Automatic denial + notification" is a process in which the request is automatically denied and the notification destination included in the approval process is notified of the denial.
[0075] 5, vehicle identification information, breakdown / repair history information, and registration information are set as privacy information. The registration information includes name, age, and sex.
[0076] The applications that use the vehicle identification information include a data update service application and applications other than the data update service. The applications that use the breakdown / repair history information include an insurance service application, an appraisal service application, and applications other than the insurance service and appraisal service. The applications that use the registration information include a driving score application, a drowsiness detection application, and applications other than the driving score application and drowsiness detection application.
[0077] The authorization process management table 32 indicates that for the vehicle owner, it is not necessary to define an authorization process for all applications, and that for the vehicle owner's spouse and guests, it is not necessary to define an authorization process for applications that use registration information.
[0078] If the vehicle owner's spouse uses a data update service application and this application attempts to use the vehicle identification information, it will be automatically approved.
[0079] When a child of the vehicle owner uses an application for a data update service and this application attempts to use vehicle identification information, it is automatically approved, and the approval is notified to the information terminal of the vehicle owner.
[0080] When a guest uses a data update service application and the application attempts to use the vehicle identification information, an approval request is sent to the vehicle owner's information terminal. If the vehicle owner's approval is obtained, the data update service application can use the vehicle identification information. On the other hand, if the vehicle owner denies the approval, the data update service application cannot use the vehicle identification information.
[0081] If the spouse or guest of the vehicle owner uses an application other than the data update service and this application attempts to use the vehicle identification information, an approval request is sent to the information terminal of the vehicle owner, and if the approval of the vehicle owner is obtained, the application can use the vehicle identification information.
[0082] If the child of the vehicle owner uses an application other than the data update service and this application attempts to use the vehicle identification information, an approval request is sent to the information terminal of the spouse of the vehicle owner. Then, if approval is obtained from the spouse of the vehicle owner, the approval is automatically granted and a notification of approval is sent to the information terminal of the vehicle owner.
[0083] When the spouse of the vehicle owner uses an insurance service application and the application attempts to use breakdown / repair history information, the application is automatically approved and a notification of approval is sent to the vehicle owner's information terminal.
[0084] If a child or guest of the vehicle owner uses an insurance service application and the application attempts to use breakdown / repair history information, it will be automatically denied.
[0085] If the vehicle owner's spouse, the vehicle owner's child, or a guest uses an appraisal service application and the application attempts to use breakdown / repair history information, the application will be automatically denied.
[0086] If the spouse of the vehicle owner uses an application other than the insurance service and appraisal service and this application attempts to use the breakdown / repair history information, an approval request is sent to the information terminal of the vehicle owner, and if the approval of the vehicle owner is obtained, the application can use the breakdown / repair history information.
[0087] If a child of the vehicle owner uses an application other than the insurance and appraisal service and this application attempts to use breakdown / repair history information, it will be automatically denied.
[0088] If a guest uses an application other than the insurance or appraisal service and this application attempts to use breakdown / repair history information, it will be automatically denied and a notification of the denial will be sent to the vehicle owner's information terminal. This makes it possible to collect information on what applications use private information that you do not want used carelessly, for example.
[0089] If the vehicle owner's child uses a driving score or drowsiness detection application and this application attempts to use registration information, it will be automatically approved.
[0090] When the child of the vehicle owner uses an application other than the driving score assessment and drowsiness assessment and this application attempts to use the registered information, an approval request is sent to the information terminal of the spouse of the vehicle owner. Then, if the approval of the spouse of the vehicle owner is obtained, this application can use the registered information.
[0091] Next, the privacy information is broadly divided into privacy information of the vehicle owner, privacy information of the person using the vehicle, and privacy information directly linked to each individual.
[0092] Examples of privacy information of a vehicle owner include vehicle identification information. Examples of privacy information of a vehicle user include current location information, destination information, and driver monitor images. Examples of privacy information directly linked to each individual include registration information (e.g., name, age, sex, and height) and mobile device ID (e.g., phone number).
[0093] The privacy information of the vehicle owner belongs to the vehicle owner. Privacy information directly linked to each individual belongs to that individual. Ownership refers to who owns the privacy information.
[0094] The privacy information of a person using a vehicle belongs to different places depending on the timing at which the information is stored in the vehicle.
[0095] For example, privacy information indicating a current location belongs to the driver at the time the information is stored in the vehicle, as shown in Fig. 6. In Fig. 6, current location information from time t1 to time t100 (i.e., information from point 1 to point 100) belongs to the owner, who is the vehicle driver from time t1 to time t100. Current location information from time t201 to time t300 (i.e., information from point 201 to point 300) belongs to the guest, who is the vehicle driver from time t201 to time t300.
[0096] In this way, each time vehicle function blocks 15, 16, and 17 store privacy information of a person using the vehicle, they associate the privacy information with the driver at the time of storing the information in vehicle function databases 21, 22, and 23, and store the information in vehicle function databases 21, 22, and 23. The driver of the vehicle is identified by authentication by user authentication unit 13. For this reason, ECU 2 transmits to ECUs 3 and 4 the address information indicating the user authenticated by user authentication unit 13. This allows ECUs 3 and 4 to acquire the address information from ECU 2 and store the privacy information (for example, current location information, destination information, and driver monitor image) in association with the address indicated by the acquired address information.
[0097] Next, a procedure will be described in which the service application 11 acquires, for example, vehicle identification information from the vehicle function block 15 while the guest is driving the vehicle.
[0098] While the guest is driving the vehicle, the navigation device 200 installed in the vehicle transmits an execution request to the service application 11, as shown in process P1 in Fig. 7. Upon receiving the execution request, the service application 11 transmits a data use request for vehicle identification information to the access control unit 18, as shown in process P2. The data use request includes sender information indicating the application that is the sender, and requested data information indicating the data that is the target of the data use request.
[0099] When the access control unit 18 receives the data use request for the vehicle identification information, as shown in process P3, it transmits a user authentication request requesting authentication for the user to use the vehicle identification information to the authentication and authorization management unit 14. The user authentication request includes requested application information indicating the application that sent the data use request and requested data information indicating the data that is the subject of the data use request.
[0100] When the authentication and authorization management unit 14 receives the user authentication request, it determines an authorization process for the service application 11 to use the vehicle identification information when the guest is driving the vehicle, as shown in process P4.
[0101] When the authentication and authorization management unit 14 determines the authorization process, it transmits an authorization request to the navigation device 200 to use the vehicle identification information, as shown in process P5.
[0102] Upon receiving the authorization request, the navigation device 200 transmits an authorization response authorizing the use of the vehicle identification information to the authentication and authorization management unit 14, as shown in process P6.
[0103] When the authentication and authorization management unit 14 receives the authorization response, for example, if the information terminal is a smartphone, it sends an authorization request requesting approval for the use of the vehicle identification information to the smartphone 300 carried by the vehicle owner, as shown in process P7.
[0104] When the smartphone 300 receives the approval request, it displays an image for confirming whether or not to approve the guest's use of the vehicle identification information on the display screen of the smartphone 300. When the vehicle owner performs an operation to approve the guest's use of the vehicle identification information, the smartphone 300 transmits an approval response to the authentication and authorization management unit 14, as shown in process P8.
[0105] Upon receiving the approval response, the authentication and authorization management unit 14 transmits a user authentication response to the access control unit 18 as shown in process P9.
[0106] Upon receiving the user authentication response, the access control unit 18 transmits permission to use the vehicle identification information to the service application 11 as shown in process P10.
[0107] When the service application 11 receives permission to use the vehicle identification information, it accesses the vehicle function block 15 to obtain the vehicle identification information, as shown in operation P11.
[0108] In response to the access from the service application 11, the vehicle function block 15 transmits the vehicle identification information to the service application 11 as shown in process P12.
[0109] Next, the procedure when the authentication and authorization management unit 14 determines the authorization process will be described.
[0110] As shown in process P21 in FIG. 8, the user authentication unit 13 authenticates the user of the vehicle (i.e., the driver). The user authentication is performed using, for example, at least one of login authentication, device authentication, and biometric authentication. Login authentication is authentication that identifies the user by the user inputting a login ID and password into the navigation device 200, for example. Device authentication is authentication that identifies the user by performing data communication with a device (e.g., a smartphone or smart key) carried by the user. Biometric authentication is authentication that identifies the user by analyzing the user's fingerprints, veins, voiceprint, face, etc.
[0111] When the user authentication unit 13 identifies the user through user authentication, it transmits the user authentication result indicating the identified user to the authentication and authorization management unit 14 as shown in process P22.
[0112] Thereafter, when the authentication and authorization management unit 14 receives a user authentication request from the access control unit 18, as shown in process P23, it acquires the data to be used in the user authentication request from the vehicle function block 15, the vehicle function block 16, or the vehicle function block 17. For example, when a user authentication request to be used includes current location information, the authentication and authorization management unit 14 acquires the current location information from the vehicle function block 15.
[0113] Next, as shown in process P24, the authentication and authorization management unit 14 refers to the privacy information management table 31 to confirm the attribute of the data acquired in process P23. For example, if the data to be used in the user authentication request is vehicle identification information, the attribute is only to the vehicle owner. Also, if the data to be used in the user authentication request is the current location, the attribute is to the vehicle owner, the vehicle owner's spouse, the vehicle owner's child, and guests.
[0114] Furthermore, the authentication and authorization management unit 14 determines the data's destination as shown in process P25. The destination is determined in accordance with the following first or second pattern.
[0115] The first pattern is a pattern in which the destination can be uniquely determined by referring to the privacy information management table 31. For example, if the data to be used is vehicle identification information, the destination is determined to be the owner of the vehicle by referring to the privacy information management table 31.
[0116] The second pattern is a pattern in which the destination cannot be uniquely determined by referring to the privacy information management table 31, and the destination is determined by referring to the destination information added to the data. For example, if the data to be used is the current location, the destination is determined based on the destination information added to the current location information.
[0117] Next, the authentication and authorization management unit 14 determines the authorization process based on the data's destination, the user authentication result, the privacy information management table 31, and the authorization process management table 32, as shown in process P26.
[0118] Specifically, the authentication and authorization management unit 14 first determines whether the current vehicle user has authorization authority for the data being used, based on the data's destination, the user authentication result, and the privacy information management table 31.
[0119] If it is determined that the user has authorization, the authentication and authorization management unit 14 determines that the authorization process is unnecessary. On the other hand, if it is determined that the user does not have authorization, the authentication and authorization management unit 14 determines the authorization process based on the authorization process management table 32.
[0120] Then, the authentication and authorization management unit 14 transmits to the navigation device 200 an authorization request to use the data that is the target of use, as shown in process P27.
[0121] Next, the procedure up to when the access control unit 18 transmits a user authentication request will be described.
[0122] As shown in process P31 of Figure 9, when the service application 11 sends a data usage request to the access control unit 18, the access control unit 18 identifies the application that is the sender of the data usage request based on the sender information included in the data usage request, as shown in process P32.
[0123] Furthermore, as shown in process P33, the access control unit 18 identifies the data to be used based on the requested data information included in the data use request.
[0124] Then, as shown in process P34, the access control unit 18 transmits a user authentication request to the authentication and authorization management unit 14. The user authentication request includes requested application information indicating the application identified in process P32 and requested data information indicating the data identified in process P33.
[0125] The vehicle control system 1 configured as above includes service applications 11 and 12, vehicle function blocks 15, 16, and 17, an authentication and authorization management unit 14, a privacy information management table 31, and an authorization process management table 32.
[0126] The service applications 11 and 12 are configured to provide services to users who use the vehicles by using vehicle information related to the vehicles.
[0127] The vehicle function blocks 15, 16, and 17 are configured to acquire vehicle information held by the ECUs 2, 3, and 4 mounted on the vehicle.
[0128] The authentication and authorization management unit 14 is configured to determine whether to authorize a data usage request when the service application 11, 12 issues a data usage request requesting the provision of privacy information among vehicle information via the vehicle function blocks 15, 16, 17.
[0129] The privacy information management table 31 defines users who have authorization authority for each of a plurality of pieces of privacy information.
[0130] The authorization process management table 32 defines an authorization process for authorizing a data use request for each of a plurality of users and for each of a plurality of pieces of privacy information.
[0131] The authentication and authorization management unit 14 then determines an authorization process based on the privacy information management table 31 and the authorization process management table 32, and uses the determined authorization process to determine whether or not to authorize the data use request.
[0132] When a data use request is made from the service application 11, 12, the vehicle control system 1 can identify a user who has authorization authority for the privacy information that is the target of the data use request, and can determine whether to authorize the data use request using an authorization process determined for each vehicle user and each piece of privacy information. If necessary, the vehicle control system 1 can include in the authorization process a process for requesting approval from a user who has authorization authority.
[0133] In this way, the vehicle control system 1 can determine whether or not to provide the privacy information that is the subject of the data use request to the service applications 11 and 12, based on an authorization process determined based on the user who has authorization authority, the vehicle user, and the privacy information. This makes it possible for the vehicle control system 1 to prevent the service applications 11 and 12 from being unable to obtain the necessary privacy information, making it impossible for the service applications 11 and 12 to provide appropriate services to the vehicle user, or providing privacy information that should not be provided to the service applications 11 and 12. As a result, the vehicle control system 1 can improve convenience for the vehicle user and prevent inappropriate acquisition of privacy information.
[0134] The vehicle control system 1 also includes a user authentication unit 13 configured to authenticate a vehicle user. When the vehicle function blocks 15, 16, and 17 acquire destination attribute information (in this embodiment, for example, current location information, destination information, and driver monitor image) that is preset as information that needs to be linked to a destination among a plurality of pieces of privacy information, the vehicle function blocks 15, 16, and 17 are configured to associate the acquired destination attribute information with destination information indicating the user authenticated by the user authentication unit 13 and store the acquired destination attribute information. Note that the ECUs 3 and 4 may be configured to recognize in advance whether the information is destination attribute information or not, or may be configured to receive information regarding whether the information is destination attribute information from the ECU 2.
[0135] This allows the vehicle control system 1 to set an appropriate authorization process based on the destination of the privacy information, thereby further improving convenience for vehicle users and further preventing inappropriate acquisition of privacy information.
[0136] The authorization process management table 32 further defines an authorization process for each service application.
[0137] The vehicle control system 1 also includes an access control unit 18. The access control unit 18 is configured to manage transmission and reception of data between the service applications 11 and 12 and the vehicle function blocks 15, 16, and 17. The access control unit 18 is also configured to identify the service application 11 or 12 that is the sender of the data use request, upon receiving a data use request from the service application 11 or 12. The authentication and authorization management unit 14 is configured to determine an authorization process based on the service application 11 or 12 identified by the access control unit 18, the privacy information management table 31, and the authorization process management table 32.
[0138] Such a vehicle control system 1 can further set different authorization processes for the service application 11 and the service application 12. This allows the vehicle control system 1 to further prevent the service applications 11 and 12 from being unable to obtain necessary privacy information, making it impossible for the service applications 11 and 12 to provide appropriate services to vehicle users, or preventing privacy information that should not be provided from being provided to the service applications 11 and 12. Therefore, the vehicle control system 1 can further improve the convenience for vehicle users and further prevent inappropriate acquisition of privacy information.
[0139] The authorization process defined in the authorization process management table 32 includes an authorization request process that requests approval of a data use request from a preset approver and, if approval is obtained from the approver, authorizes the data use request. This allows the vehicle control system 1 to determine whether to authorize the data use request based on the decision of the approver.
[0140] The authorization processes defined in the authorization process management table 32 include an automatic authorization process that authorizes a data use request without requesting approval from a preset approver, thereby enabling the vehicle control system 1 to reduce the frequency with which the approver must perform approval or denial tasks.
[0141] The authorization processes defined in the authorization process management table 32 include an automatic approval notification process that approves a data use request without requesting approval from a preset approver and notifies the approver that the data use request has been approved. This enables the vehicle control system 1 to reduce the frequency with which the approver must perform approval or denial tasks, and also enables the approver to be aware that a data use request has been made.
[0142] The authorization processes defined in the authorization process management table 32 include an automatic denial process that denies a data use request without requesting approval from a preset approver, thereby enabling the vehicle control system 1 to reduce the frequency with which the approver must perform denial work.
[0143] The authorization processes defined in the authorization process management table 32 include an automatic denial notification process that denies a data use request without requesting approval from a preset approver and notifies the approver that the data use request has been denied. This enables the vehicle control system 1 to reduce the frequency with which the approver must perform denial work and to let the approver know that a data use request has been made.
[0144] The authentication and authorization management unit 14 is configured to determine whether or not the user has authorization authority based on the privacy information management table 31, and if the user does not have authorization authority, to determine the authorization process based on the authorization process management table 32.
[0145] The ECU 2 includes an authentication and authorization management unit 14, a privacy information management table 31, an authorization process management table 32, and a vehicle function block 17. The vehicle function block 17 is configured to acquire privacy information when a data use request is authorized by the authentication and authorization management unit 14. The authentication and authorization management unit 14 determines an authorization process based on the privacy information management table 31 and the authorization process management table 32, and uses the determined authorization process to determine whether or not to authorize the data use request.
[0146] Like the vehicle control system 1, the ECU 2 can further improve the convenience for the vehicle user and further prevent inappropriate acquisition of privacy information.
[0147] In the embodiment described above, the vehicle control system 1 corresponds to an authentication system, the ECUs 3 and 4 correspond to electronic control devices, the privacy information management table 31 corresponds to a confidential information management table, the privacy information corresponds to confidential information, the data usage request corresponds to a confidential information acquisition request, and the ECU 2 corresponds to an authentication device.
[0148] Furthermore, ECUs 3 and 4 correspond to the first electronic control unit, ECU 2 corresponds to the second electronic control unit, vehicle function databases 21 and 22 correspond to the first memory unit, vehicle function blocks 15 and 16 correspond to the first vehicle function block, and vehicle function block 17 corresponds to the second vehicle function block.
[0149] Although one embodiment of the present disclosure has been described above, the present disclosure is not limited to the above embodiment and can be implemented in various modifications.
[0150] [Variation 1] For example, in the above embodiment, the service applications 11 and 12 are mounted on the ECU 2, but they may also be mounted on the ECUs 3 and 4 and the exterior communication device 5. Furthermore, the service applications 11 and 12 may also be mounted on a center that is installed outside the vehicle and performs data communication with the exterior communication device 5.
[0151] [Variation 2] In the above embodiment, the user authentication unit 13, the authentication and authorization management unit 14, and the access control unit 18 are mounted on the ECU 2, but they may be mounted on the ECUs 3 and 4 and the exterior communication device 5. Furthermore, the user authentication unit 13, the authentication and authorization management unit 14, and the access control unit 18 may be mounted on different devices.
[0152] [Variation 3] In the above embodiment, the authorization process is determined based on the privacy information management table 31 and the authorization process management table 32. However, the authorization process may be determined based only on the authorization process management table 32 without using the privacy information management table 31.
[0153] That is, in the authorization process management table 32, a "-" column in which no authorization process is defined indicates that authorization authority is granted for the privacy information, so it is possible to determine whether authorization authority is granted or not based solely on the authorization process management table 32.
[0154] For example, when the application "Data Update Service" accesses vehicle identification information, it can be determined based on the authorization process management table 32 that the owner has authorization authority, but the family (spouse), family (children), and guests (rentees) do not have authorization authority.
[0155] Furthermore, when the application "Driving Score Rating" accesses the registered information (user's name, age, and gender), it can determine based on the authorization process management table 32 that the owner, family members (spouse) and guests (rented persons) have authorization authority, but that family members (children) do not have authorization authority.
[0156] [Variation 4] In the above embodiment, the vehicle function databases 21 and 22 are mounted on different ECUs 3. However, the vehicle function databases that store collected vehicle information may be mounted on the ECU 4 or the ECU 2 in addition to the ECU 3.
[0157] [Variation 5] In the above embodiment, the privacy information of the vehicle user is the confidential information. However, information that does not involve privacy but that should not be accessed without permission (for example, key information held by the ECUs 2, 3, and 4) may be included in the confidential information.
[0158] The ECUs 2 and 3 and the methods described herein may be implemented by a special-purpose computer configured with a processor and memory programmed to execute one or more functions embodied in a computer program. Alternatively, the ECUs 2 and 3 and the methods described herein may be implemented by a special-purpose computer configured with a processor configured with one or more dedicated hardware logic circuits. Alternatively, the ECUs 2 and 3 and the methods described herein may be implemented by one or more special-purpose computers configured with a processor and memory programmed to execute one or more functions and a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory storage medium. The methods for implementing the functions of each unit included in the ECUs 2 and 3 do not necessarily need to include software; all of the functions may be implemented using one or more hardware components.
[0159] In the above embodiments, multiple functions of one component may be realized by multiple components, or one function of one component may be realized by multiple components. Furthermore, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, part of the configuration of the above embodiments may be omitted. Furthermore, at least part of the configuration of the above embodiments may be added to or substituted for the configuration of another of the above embodiments.
[0160] In addition to the above-mentioned ECUs 2 and 3, the present disclosure can also be realized in various forms, such as a system including the ECUs 2 and 3 as components, a program for causing a computer to function as the ECUs 2 and 3, a non-transient physical recording medium such as a semiconductor memory on which this program is recorded, and an authentication method.
[0161] [Technical idea disclosed in this specification] [Item 1] at least one service application (11, 12) configured to provide a service to a user using a vehicle by using vehicle information related to the vehicle; a vehicle function block (15, 16, 17) configured to acquire the vehicle information held by an electronic control device mounted on the vehicle; an authentication and authorization management unit (14) configured to, when the at least one service application issues a secret information acquisition request requesting acquisition of secret information among the vehicle information via the vehicle function block, determine whether to authorize the secret information acquisition request; a secret information management table (31) that defines the users who have authorization authority for each of the plurality of pieces of secret information; an authorization process management table (32) that defines an authorization process for authorizing the secret information acquisition request for each of the plurality of users and each of the plurality of secret information; Equipped with The authentication and authorization management unit determines the authorization process based on the confidential information management table and the authorization process management table, and uses the determined authorization process to determine whether to authorize the confidential information acquisition request.
[0162] [Item 2] Item 1, an authentication system according to the present invention, a user authentication unit (13) configured to authenticate the user; The vehicle function block is configured to, when it acquires, from among the multiple pieces of confidential information, destination assignment information that has been preset as information that needs to be linked to the destination of the confidential information, link the acquired destination assignment information to destination information that indicates the user authenticated by the user authentication unit, and store the acquired destination assignment information.
[0163] [Item 3] Item 2: The authentication system according to item 2, The authentication system is configured such that the user authentication unit authenticates the user using at least one of login authentication, device authentication, and biometric authentication.
[0164] [Item 4] The authentication system according to any one of items 1 to 3, The authorization process management table further defines the authorization process for each of the at least one service application.
[0165] [Item 5] Item 4. An authentication system according to item 4, an access control unit (17) configured to manage data transmission and reception between the at least one service application and the vehicle function block; the access control unit is configured to, when receiving the secret information acquisition request from the at least one service application, identify the at least one service application that is a transmission source of the secret information acquisition request; an authentication system configured such that the authentication and authorization management unit determines the authorization process based on the at least one service application identified by the access control unit, the confidential information management table, and the authorization process management table.
[0166] [Item 6] An authentication system according to any one of items 1 to 5, The authorization process includes an approval request process that requests approval of the secret information acquisition request from a predetermined approver, and approves the secret information acquisition request if the approval is obtained from the approver.
[0167] [Item 7] An authentication system according to any one of items 1 to 6, The authentication system includes an automatic approval process for approving the request for secret information acquisition without requesting approval of the request for secret information acquisition from a preset approver.
[0168] [Item 8] An authentication system according to any one of items 1 to 7, The authorization process authorizes the request for secret information acquisition without requesting approval of the request for secret information acquisition from a predetermined approver, and notifies the approver that the request for secret information acquisition has been authorized.
[0169] [Item 9] An authentication system according to any one of items 1 to 8, The authentication system includes an automatic denial process for denying the request for secret information acquisition without requesting approval of the request for secret information acquisition from a preset approver.
[0170] [Item 10] The authentication system according to any one of items 1 to 9, The authorization process includes an automatic denial notification process that denies the request for secret information acquisition without requesting approval of the request for secret information acquisition from a predetermined approver, and notifies the approver that the request for secret information acquisition has been denied.
[0171] [Item 11] The authentication system according to any one of items 1 to 10, the authentication and authorization management unit determines whether the user has the authorization authority based on the confidential information management table, and if the user does not have the authorization authority, determines the authorization process based on the authorization process management table.
[0172] [Item 12] an authentication and authorization management unit (14) configured to determine whether to authorize a secret information acquisition request when at least one service application (11, 12) configured to provide a service to a user using a vehicle by using vehicle information related to the vehicle issues a secret information acquisition request requesting acquisition of secret information from the vehicle information; a secret information management table (31) that defines the users who have authorization authority for each of the plurality of pieces of secret information; an authorization process management table (32) that defines an authorization process for authorizing the secret information acquisition request for each of the plurality of users and each of the plurality of secret information; a vehicle function block (17) configured to acquire the secret information when the secret information acquisition request is authorized by the authentication and authorization management unit; Equipped with The authentication and authorization management unit determines the authorization process based on the confidential information management table and the authorization process management table, and uses the determined authorization process to determine whether to authorize the confidential information acquisition request.
[0173] [Item 13] Computer, an authentication and authorization management unit (14) configured to, when at least one service application (11, 12) configured to provide a service to a user using a vehicle by using vehicle information about the vehicle issues a secret information acquisition request requesting acquisition of secret information from the vehicle information, determine the authorization process based on a secret information management table (31) that defines the users who have authorization authority for each of the multiple pieces of secret information and an authorization process management table (32) that defines an authorization process for authorizing the secret information acquisition request for each of the multiple users and for each of the multiple pieces of secret information, and to determine whether to authorize the secret information acquisition request using the determined authorization process; a vehicle function block (17) configured to acquire the secret information when the secret information acquisition request is authorized by the authentication and authorization management unit; Certification program to function as.
[0174] [Item 14] An authentication system (1) having a first electronic control unit (3, 4) that manages vehicle information related to a vehicle, and a second electronic control unit (2) that has a function of relaying data transmitted from a plurality of the first electronic control units, The first electronic control unit is a first storage unit (21, 22) configured to store the vehicle information; a first vehicle function block (15, 16) configured to acquire the vehicle information; The second electronic control unit is at least one service application (11, 12) configured to provide a service to a user who uses the vehicle by using the vehicle information; a second vehicle function block (17) configured to acquire the vehicle information from the first electronic control unit; an authentication and authorization management unit (14) configured to, when the at least one service application issues a confidential information acquisition request requesting acquisition of confidential information among the vehicle information held by the first electronic control unit, determine whether to authorize the confidential information acquisition request; a secret information management table (31) that defines the users who have authorization authority for each of the plurality of pieces of secret information; an authorization process management table (32) that defines an authorization process for authorizing the secret information acquisition request for each of the plurality of users and each of the plurality of secret information; the authentication and authorization management unit determines the authorization process based on the secret information management table and the authorization process management table, and determines whether to authorize the secret information acquisition request using the determined authorization process; When the request to acquire confidential information is approved by the authentication and authorization management unit, the at least one service application acquires the confidential information via the first vehicle function block of the first electronic control unit or the second vehicle function block of the second electronic control unit, which stores the confidential information corresponding to the request to acquire confidential information.
[0175] [Item 15] Item 15. The authentication system according to item 14, The first vehicle function block is an authentication system that, when the secret information is destination-assigned information that has been preset as information that needs to be linked to the destination of the secret information, links the secret information to destination information indicating the destination and stores it in the first memory unit.
Claims
1. at least one service application (11, 12) configured to provide a service to a user using a vehicle by utilizing vehicle information related to the vehicle; a vehicle function block (15, 16, 17) configured to acquire the vehicle information held by an electronic control device mounted on the vehicle; an authentication and authorization management unit (14) configured to, when the at least one service application issues a secret information acquisition request requesting acquisition of secret information among the vehicle information via the vehicle function block, determine whether or not to authorize the secret information acquisition request; a secret information management table (31) that defines the users who have authorization authority for each of the plurality of pieces of secret information; an authorization process management table (32) that defines an authorization process for authorizing the secret information acquisition request for each of the plurality of users and each of the plurality of secret information; Equipped with The authentication and authorization management unit determines the authorization process based on the confidential information management table and the authorization process management table, and uses the determined authorization process to determine whether to authorize the confidential information acquisition request.
2. 2. The authentication system according to claim 1, a user authentication unit (13) configured to authenticate the user; The vehicle function block is configured to, when it acquires, from among the multiple pieces of confidential information, destination assignment information that has been preset as information that needs to be linked to the destination of the confidential information, link the acquired destination assignment information to destination information that indicates the user authenticated by the user authentication unit, and store the acquired destination assignment information.
3. 3. The authentication system according to claim 2, The authentication system is configured such that the user authentication unit authenticates the user using at least one of login authentication, device authentication, and biometric authentication.
4. The authentication system according to any one of claims 1 to 3, The authorization process management table further defines the authorization process for each of the at least one service application.
5. 5. The authentication system according to claim 4, an access control unit (18) configured to manage transmission and reception of data between the at least one service application and the vehicle function block; the access control unit is configured to, when receiving the secret information acquisition request from the at least one service application, identify the at least one service application that is a transmission source of the secret information acquisition request; an authentication system configured such that the authentication and authorization management unit determines the authorization process based on the at least one service application identified by the access control unit, the confidential information management table, and the authorization process management table;
6. The authentication system according to any one of claims 1 to 3, The authorization process includes an approval request process that requests approval of the secret information acquisition request from a predetermined approver, and approves the secret information acquisition request if the approval is obtained from the approver.
7. The authentication system according to any one of claims 1 to 3, The authentication system includes an automatic approval process for approving the request for secret information acquisition without requesting approval of the request for secret information acquisition from a preset approver.
8. The authentication system according to any one of claims 1 to 3, The authorization process authorizes the request for secret information acquisition without requesting approval of the request for secret information acquisition from a predetermined approver, and notifies the approver that the request for secret information acquisition has been authorized.
9. The authentication system according to any one of claims 1 to 3, The authentication system includes an automatic denial process for denying the request for secret information acquisition without requesting approval of the request for secret information acquisition from a preset approver.
10. The authentication system according to any one of claims 1 to 3, The authorization process includes an automatic denial notification process that denies the request for secret information acquisition without requesting approval of the request for secret information acquisition from a predetermined approver, and notifies the approver that the request for secret information acquisition has been denied.
11. The authentication system according to any one of claims 1 to 3, the authentication and authorization management unit determines whether the user has the authorization authority based on the confidential information management table, and if the user does not have the authorization authority, determines the authorization process based on the authorization process management table.
12. an authentication and authorization management unit (14) configured to determine whether to authorize a secret information acquisition request when at least one service application (11, 12) configured to provide a service to a user using a vehicle by using vehicle information related to the vehicle issues a secret information acquisition request requesting acquisition of secret information from the vehicle information; and a secret information management table (31) that defines the users who have authorization authority for each of the plurality of pieces of secret information; an authorization process management table (32) that defines an authorization process for authorizing the secret information acquisition request for each of the plurality of users and each of the plurality of pieces of secret information; a vehicle function block (17) configured to acquire the secret information when the secret information acquisition request is authorized by the authentication and authorization management unit; Equipped with The authentication and authorization management unit determines the authorization process based on the confidential information management table and the authorization process management table, and uses the determined authorization process to determine whether to authorize the confidential information acquisition request.
13. Computer, an authentication and authorization management unit (14) configured to, when at least one service application (11, 12) configured to provide a service to a user using a vehicle by using vehicle information about the vehicle issues a secret information acquisition request requesting acquisition of secret information from the vehicle information, determine the authorization process based on a secret information management table (31) that defines the users who have authorization authority for each of the multiple pieces of secret information and an authorization process management table (32) that defines an authorization process for authorizing the secret information acquisition request for each of the multiple users and for each of the multiple pieces of secret information, and to determine whether to authorize the secret information acquisition request using the determined authorization process; and a vehicle function block (17) configured to acquire the secret information when the secret information acquisition request is authorized by the authentication and authorization management unit; Certification program to function as.
14. An authentication system (1) having a first electronic control unit (3, 4) that manages vehicle information related to a vehicle, and a second electronic control unit (2) that has a function of relaying data transmitted from a plurality of the first electronic control units, The first electronic control unit a first storage unit (21, 22) configured to store the vehicle information; a first vehicle function block (15, 16) configured to acquire the vehicle information; The second electronic control unit is at least one service application (11, 12) configured to provide a service to a user who uses the vehicle by using the vehicle information; a second vehicle function block (17) configured to acquire the vehicle information from the first electronic control unit; an authentication and authorization management unit (14) configured to, when the at least one service application issues a confidential information acquisition request requesting acquisition of confidential information among the vehicle information held by the first electronic control unit, determine whether or not to authorize the confidential information acquisition request; a secret information management table (31) that defines the users who have authorization authority for each of the plurality of pieces of secret information; an authorization process management table (32) that defines an authorization process for authorizing the secret information acquisition request for each of the plurality of users and each of the plurality of secret information; the authentication and authorization management unit determines the authorization process based on the secret information management table and the authorization process management table, and determines whether to authorize the secret information acquisition request using the determined authorization process; When the request to acquire confidential information is approved by the authentication and authorization management unit, the at least one service application acquires the confidential information via the first vehicle function block of the first electronic control unit or the second vehicle function block of the second electronic control unit, which stores the confidential information corresponding to the request to acquire confidential information.
15. 15. The authentication system of claim 14, The first vehicle function block is an authentication system that, when the secret information is destination-assigned information that has been preset as information that needs to be linked to the destination of the secret information, links the secret information to destination information indicating the destination and stores it in the first memory unit.
Citation Information
Patent Citations
Information processing device, method, system, and program, and recording medium
JP2007094935A
Center apparatus, terminal apparatus and authentication system
JP2010072976A
Information processing device, method, program, and vehicle
JP2022076789A
Network services broker system and method
US20030105864A1
Process manager for digital communication
US20200099690A1