Electronic device, software update method, and program
The described system efficiently updates vehicle electronic devices by using a relay device for authentication and patch data transfer, overcoming network dependency for software updates.
Patent Information
- Application Number
- JP2021143226
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-02
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2041-09-02
AI Technical Summary
Existing software update methods for electronic devices in vehicles are inefficient when mobile communication networks are unavailable.
An electronic device and method that utilizes a relay device mounted on a vehicle to communicate with external devices, performing authentication, acquiring patch data, and updating software using a session key, even without a mobile communication network.
Enables efficient software updates for vehicle electronic devices by establishing a secure channel through a relay device, ensuring updates can occur regardless of network availability.
Smart Images

Figure 0007729122000001 
Figure 0007729122000002 
Figure 0007729122000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to the technical field of a method for providing various services, such as payment, to a vehicle user via short-range wireless communication. [Background technology]
[0002] Conventionally, various services such as payment can be provided to vehicle users via short-range wireless communication between an ECU (Electronic Control Unit) or SE (Secure Element) installed in a vehicle and a server installed outside the vehicle. For example, Patent Document 1 discloses a system in which, when a VID (Vehicle Interface Device) installed in a vehicle receives a request for payment account information from a dealer access device, the system determines whether the user's mobile communication device is inside the vehicle, and if it determines that the mobile communication device is inside the vehicle, transmits payment account information read from a payment card inserted in the VID to the dealer access device. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2020-53066 Summary of the Invention [Problem to be solved by the invention]
[0004] The various services described above are realized by software such as applications installed in an ECU (Electronic Control Unit) or SE, and when such software needs to be updated, it is necessary to update the software installed in the ECU or SE by transmitting a patch (patch data) from a server to the ECU or SE using, for example, a mobile communication network. However, if a mobile communication network is not available, it is not possible to update the software efficiently.
[0005] Therefore, the present invention has been made in consideration of the above points and aims to provide an electronic device, a software update method, and a program that can more efficiently update software installed in an electronic device in a vehicle. [Means for solving the problem]
[0006] In order to solve the above problem, the invention of claim 1 provides an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, the electronic device comprising: a storage means for storing a unique identification number of the electronic device and a version number of software installed on the electronic device; an authentication means for executing an authentication process with the external device via the relay device; an acquisition means for acquiring patch data specified by the unique identification number and version number stored in the storage means from the external device via the relay device after the authentication process is completed; and an update means for updating the software based on the patch data acquired by the acquisition means. The acquisition means acquires a list registering combinations of specific unique identification numbers and specific version numbers from the external device via the relay device, and acquires the patch data from the external device via the relay device if the combination of the unique identification number and the version number stored in the storage means is registered in the list. It is characterized by: The invention described in claim 2 is an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, comprising: a storage means for storing a unique identification number of the electronic device and a version number of software installed in the electronic device; an authentication means for performing an authentication process with the external device via the relay device; an acquisition means for acquiring patch data identified by the unique identification number and version number stored in the storage means from the external device via the relay device after the authentication process is completed; and an update means for updating the software based on the patch data acquired by the acquisition means, wherein the electronic device is composed of a secure element and an ECU (Electronic Control Unit) mounted on the mobile body, the secure element includes the authentication means and the acquisition means, the acquisition means acquires the patch data encrypted using a session key generated in the authentication process and common to the external device, and decrypts the patch data using the session key, and the ECU includes the storage means and the update means, and the update means updates the software based on the decrypted patch data.
[0007] Claim 3 The invention described in claim 1 or 2 In the electronic device described in the above, the acquisition means acquires the patch data from the external device via the relay device by transmitting the unique identification number and the version number stored in the storage means to the external device via the relay device.
[0010] Claim 4The invention described in is a terminal device capable of communicating with an electronic device installed on a mobile body or an electronic device carried by a passenger of the mobile body via a relay device mounted on the mobile body, wherein the electronic device stores a unique identification number of the electronic device and a version number of software installed on the electronic device, and the terminal device is characterized by comprising: an authentication means for performing an authentication process with the electronic device via the relay device; an acquisition means for acquiring the unique identification number and the version number from the electronic device via the relay device after the authentication process is completed; and a transmission means for transmitting patch data for updating the software installed on the electronic device, the patch data corresponding to the unique identification number and the version number acquired by the acquisition means via the relay device.
[0011] Claim 5 The invention described in the item (2) is a software update method executed by an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, the method comprising the steps of: storing a unique identification number of the electronic device and a version number of software installed on the electronic device in a storage means; performing an authentication process with the external device via the relay device; and, after the authentication process is completed, acquiring patch data specified by the unique identification number and version number stored in the storage means from the external device via the relay device. acquisition and updating the software based on the acquired patch data. In the acquisition step, a list registering combinations of specific unique identification numbers and specific version numbers is acquired from the external device via the relay device, and if the combination of the unique identification number and the version number stored in the storage means is registered in the list, the patch data is acquired from the external device via the relay device. It is characterized by: The invention described in claim 6 is a software update method executed by an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, the electronic device being composed of a secure element mounted on the mobile body and an ECU (Electronic Control Unit), the method including: a step in which the ECU stores a unique identification number of the electronic device and a version number of software installed in the electronic device in a storage means; a step in which the secure element performs an authentication process with the external device via the relay device; an acquisition step in which the secure element acquires patch data identified by the unique identification number and the version number stored in the storage means from the external device via the relay device after the authentication process is completed; and an update step in which the ECU updates the software based on the acquired patch data, wherein in the acquisition step, the patch data encrypted with a session key generated in the authentication process and common to the external device is acquired, and the patch data is decrypted using the session key; and in the update step, the software is updated based on the decrypted patch data.
[0012] The invention described in claim 7 is a method for making a computer included in an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body function as: a storage means for storing a unique identification number of the electronic device and a version number of software installed in the electronic device; an authentication means for executing an authentication process with the external device via the relay device; an acquisition means for acquiring patch data specified by the unique identification number and version number stored in the storage means from the external device via the relay device after the authentication process is completed; and an update means for updating the software based on the patch data acquired by the acquisition means. a program, the acquisition means acquiring a list registering combinations of specific unique identification numbers and specific version numbers from the external device via the relay device, and acquiring the patch data from the external device via the relay device if the combination of the unique identification number and the version number stored in the storage means is registered in the list; It is characterized by: The invention described in claim 8 is a program that causes a computer included in an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, the electronic device being composed of a secure element and an ECU (Electronic Control Unit) mounted on the mobile body, to function as: a storage means that stores a unique identification number of the electronic device and a version number of software installed on the electronic device; an authentication means that performs an authentication process with the external device via the relay device; an acquisition means that, after the authentication process is completed, acquires patch data identified by the unique identification number and version number stored in the storage means from the external device via the relay device; and an update means that updates the software based on the patch data acquired by the acquisition means, wherein the acquisition means acquires the patch data encrypted using a session key generated in the authentication process and common to the external device, and decrypts the patch data using the session key, and the update means updates the software based on the decrypted patch data. [Effects of the Invention]
[0013] According to the present invention, software installed on electronic devices in a vehicle can be updated more efficiently. [Brief explanation of the drawings]
[0014] [Figure 1] 1 is a diagram illustrating an example of a schematic configuration of a payment processing system S according to an embodiment of the present invention. [Figure 2] FIG. 2 is a diagram illustrating an example of a schematic configuration of a payment terminal 2. [Figure 3] FIG. 2 is a diagram illustrating an example of a schematic configuration of an ECU 4. [Figure 4] FIG. 1 is a diagram illustrating an example of a schematic configuration of an eSE5. [Figure 5] 1 is a conceptual diagram showing the positional relationship between a reader / writer 22 embedded in the ground of a pay-by-the-hour parking lot and a vehicle C. FIG. [Figure 6] 10 is a sequence diagram showing an example of a transaction carried out in the payment processing system S before the start of a secure session. FIG. [Figure 7] 10 is a sequence diagram showing an example of a transaction carried out after a secure session is started in the payment processing system S. FIG. [Figure 8]10 is a sequence diagram showing an example of a transaction carried out after a secure session is started in the payment processing system S. FIG. DETAILED DESCRIPTION OF THE INVENTION
[0015] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings. The embodiment described below is an embodiment in which the present invention is applied to a payment processing system in which payment processing is performed between a payment terminal installed outside a vehicle and an ECU (Electronic Control Unit) installed in the vehicle. The payment terminal is an example of an external device, and the ECU is an example of an electronic device. The vehicle is an example of a mobile object, such as a two-wheeled automobile, a four-wheeled automobile, or a bicycle.
[0016] [1. Overview of payment processing system S] First, the schematic configuration of a payment processing system S according to this embodiment will be described with reference to Fig. 1 etc. Fig. 1 is a diagram showing an example of the schematic configuration of the payment processing system S according to this embodiment. As shown in Fig. 1, the payment processing system S is configured to include a management server 1, a payment terminal 2, a repeater 3 (an example of a repeater device), an ECU (Electronic Control Unit) 4, and an eSE (embedded Secure Element) 5. The management server 1 and the payment terminal 2 (an example of a terminal device) are each connected to a network NW configured, for example, by the Internet, and the management server 1 and the payment terminal 2 are capable of communicating via the network NW.
[0017] The management server 1 is a server for managing software that can be provided to specific devices (e.g., specific ECUs or eSEs). Examples of software include operating systems, firmware, and applications required for using various services such as payment services. Each piece of software is assigned a unique identifier and a version number that indicates the version of the software. Here, the version number is updated whenever the software is updated, for example, to fix a software defect or change its functionality. To update the software installed in the ECU 4 or eSE 5, a patch (patch data) generated by the management server 1 is applied.
[0018] A patch is generated for each software identifier and for each version number. For example, one patch "001" (identifier) is generated for software "Sxxx" (identifier) with "Ver1" (version number). The patch may be a program or configuration data. Each patch is assigned an identifier and associated with a list of devices to which the patch is applied. The list of devices to which the patch is applied registers the unique identification number of the specific device to which the patch is applied (e.g., a specific ECU or eSE) and the identifier and version number of the specific software to which the patch is applied, in association with each other. The patch and the list of devices to which the patch is applied are provided to the payment terminal 2 via the network NW. The unique identification number of the specific device may be a number that identifies the model of vehicle C.
[0019] The payment terminal 2 is installed in locations such as stores with drive-through facilities, parking lots, and gas stations, and is a terminal that performs payment processing between the payment terminal 2 and the ECU 4 for payment when a user purchases a product or receives a service. Such locations are outside the vehicle C and are vehicle visit locations that the vehicle C can visit while traveling. Payment methods used in the payment processing include, but are not limited to, electronic money payment and credit card payment. When the payment method is credit card payment, the payment terminal 2 may access a server that manages credit card information via the network NW to perform a credit inquiry.
[0020] FIG. 2 is a diagram showing an example of the schematic configuration of the payment terminal 2. As shown in FIG. 2, the payment terminal 2 includes a storage unit 21, a reader / writer 22, and a processing unit 23 configured from a CPU (Central Processing Unit) and the like. The storage unit 21 stores software such as an operating system (OS) and applications. The applications include an authentication processing program and a payment processing program. The storage unit 21 also stores authentication data used in authentication processing to establish a secure channel with the eSE 5. The authentication data is, for example, a key set including a secure channel encryption key, a secure channel MAC (Message Authentication Code) key, and a data encryption key. The storage unit 21 also stores patches provided by the management server 1 and a list of devices to which the patches should be applied, in association with each other.
[0021] The reader / writer 22 is equipped with an antenna and is capable of performing short-range wireless communication with the repeater 3 within a range where short-range wireless communication is possible. The protocol for short-range wireless communication between the reader / writer 22 and the repeater 3 may be, for example, a UWB protocol. In this case, the reader / writer 22 periodically checks (confirms its location) whether or not the repeater 3 with which it is communicating is present within a preset distance range, and performs short-range wireless communication with the repeater 3 that is confirmed to be present within the distance range. The reader / writer 22 may be embedded in the ground, for example, outside the housing of the payment terminal 2, through which the vehicle C passes.
[0022] The processing unit 23 is an example of the authentication means, acquisition means, and transmission means of the present invention. The processing unit 23 executes authentication processing for establishing a secure session with the eSE 5 via the repeater 3 in accordance with an authentication processing program. In this authentication processing, mutual authentication using, for example, GVAS (General Vehicle Authentication System) may be performed. When the authentication processing with the eSE 5 is completed and a secure session with the eSE 5 is established, the processing unit 23 encrypts a patch identified by the unique identification number and version number of the ECU 4 connected to the authenticated eSE 5 using a session key generated by the authentication processing (i.e., a session key shared with the eSE 5), and provides the encrypted patch to the eSE 5. After the secure session between the eSE 5 and the payment terminal 2 is established, the processing unit 23 executes payment processing in accordance with the payment processing program.
[0023] The repeater 3, ECU 4, and eSE 5 are installed, for example, in a center console in the vehicle C. In the vehicle C, the repeater 3 and the ECU 4 are electrically connected, and the ECU 4 and the eSE 5 are also electrically connected. The repeater 3 and the eSE 5 may be electrically connected. The repeater 3 is equipped with an antenna and is capable of short-range wireless communication with the reader / writer 22. Furthermore, the repeater 3 performs short-range wireless communication with an electronic device of a passenger (user) of the vehicle C within a range where short-range wireless communication is possible. The electronic device of the passenger of the vehicle C is, for example, a contactless IC card or a smartphone carried by the passenger. The protocol for short-range wireless communication between the electronic device of the passenger of the vehicle C and the repeater 3 may be, for example, an NFC protocol (for example, a protocol specified in ISO 14443). The contactless IC card may be configured to include a secure element, such as a UICC (Universal Integrated Circuit Card) with high tamper resistance.
[0024] FIG. 3 is a diagram showing an example of a schematic configuration of the ECU 4. As shown in FIG. 3, the ECU 4 is configured to include an interface (I / F) unit 41, an interface (I / F) unit 42, a storage unit 43, and a control unit 44. The interface unit 41 serves as an interface with the repeater 3. The interface unit 42 serves as an interface with the eSE 5. Examples of interfaces include SPI (Serial Peripheral Interface), I 2 C (Inter-Integrated Circuit), and ISO 7816 interfaces. The ECU 4 and eSE 5 constitute an electronic device of the present invention.
[0025] The memory unit 43 stores software such as an operating system and applications. The applications include a payment processing program to which patches can be applied. The memory unit 43 also stores payment data. The payment data includes information necessary for payment depending on the payment method. For example, if the payment method is credit card payment, the payment data includes data necessary for credit card payment, such as the credit card number, the cardholder's name, and expiration date. If the payment method is electronic money payment, the payment data includes data such as the electronic money number and electronic value necessary for electronic money payment. Furthermore, the memory unit 43 (an example of a storage means) stores the unique identification number of the ECU 4 and the version number of software such as the payment processing program installed in the ECU 4.
[0026] The control unit 44 is configured with a CPU, RAM, ROM, etc. The control unit 44 is an example of an acquisition means and an update means of the present invention. When a secure session is established between the eSE 5 and the payment terminal 2 and a patch is provided from the payment terminal 2 via the repeater 3 and the eSE 5, the control unit 44 acquires the patch and updates software such as a payment processing program for the patch. After a secure session is established between the eSE 5 and the payment terminal 2, the control unit 44 executes payment processing in accordance with the payment processing program. The control unit 44 may also be used to control the engine start of the vehicle C and the locking and unlocking of the doors. When a multimedia terminal such as a display is provided on the console of the vehicle C, the multimedia terminal is electrically connected to the control unit 44 via an interface unit (not shown) and controlled by the control unit 44.
[0027] The eSE 5 is installed, for example, inside the center console of the vehicle C, and is a secure element such as an eUICC (embedded universal integrated circuit card) with high tamper resistance. FIG. 4 is a diagram showing an example of a schematic configuration of the eSE 5. As shown in FIG. 4, the eSE 5 is configured with an interface (I / F) unit 51, a RAM (random access memory) 52, an NVM (nonvolatile memory) 53, a CPU 54, etc. The interface unit 51 serves as an interface with the ECU 4 and is electrically connected to the ECU 4. The NVM 53 stores software such as an operating system and applications. The applications include an authentication processing program to which patches can be applied.
[0028] NVM 53 stores authentication data (e.g., a key set including a secure channel encryption key, a secure channel MAC key, and a data encryption key) used in authentication processing to establish a secure channel with payment terminal 2. CPU 54 is an example of the authentication means and acquisition means of the present invention. CPU 54 executes authentication processing to establish a secure session with payment terminal 2 via repeater 3 in accordance with an authentication processing program. When authentication processing with payment terminal 2 is completed and a secure session with payment terminal 2 is established, and a patch encrypted with a common session key with payment terminal 2 is provided, CPU 54 acquires the patch (i.e., acquires the patch from payment terminal 2 via repeater 3), decrypts the patch with the session key, and provides the patch to ECU 4.
[0029] When a secure session is established between the eSE 5 and the payment terminal 2 and a patch for the authentication processing program is provided from the payment terminal 2 via the repeater 3, the CPU 54 may acquire the patch and, as an update means, update the authentication processing program based on the patch. In this case, the NVM 53 (an example of a storage means) stores the unique identification number of the eSE 5 and the version number of the authentication processing program installed in the eSE 5.
[0030] [2. Operation of payment processing system S] Next, the operation of the payment processing system S will be described with reference to Fig. 5 to Fig. 8. Fig. 5 is a conceptual diagram showing the positional relationship between a reader / writer 22 embedded in the ground of a pay-by-the-hour parking lot and a vehicle C. Fig. 6 is a sequence diagram showing an example of a transaction carried out in the payment processing system S before the start of a secure session. Figs. 7 and 8 are sequence diagrams showing an example of a transaction carried out in the payment processing system S after the start of a secure session.
[0031] 5A, the reader / writer 22 of the payment terminal 2 actively transmits radio waves D and periodically checks whether a communication partner (i.e., the payment terminal 2) is present within a predetermined distance range H, as shown in FIG. 5A. In the example of FIG. 5A, the vehicle C equipped with the repeater 3 is not within the distance range H, so the presence of the repeater 3 within the distance range H is not confirmed (detected) (standby state). On the other hand, in the example of FIG. 5B, the vehicle C equipped with the repeater 3 enters the distance range H, and the presence of the repeater 3 within the distance range H is confirmed (communication starts). Note that the example of FIG. 5B illustrates a case in which the vehicle C is parked. However, even when the vehicle C passes a predetermined position, such as in an electronic toll collection system (ETC), the ECU 4 may confirm that it is present within the distance range H, and as a result, communication may start. Alternatively, the repeater 3 equipped in the vehicle C may actively transmit radio waves and periodically check whether a communication partner (i.e., the payment terminal 2) is present within a predetermined distance range.
[0032] 6, when processing unit 23 of payment terminal 2 confirms that repeater 3 is present within distance range H (step S1), it starts short-range wireless communication with repeater 3 (step S2) and transmits a SELECT command to select an application (authentication processing program) for performing authentication processing to repeater 3 via reader / writer 22 (step S3). The SELECT command includes an identifier (AID) of the application to be selected.
[0033] Next, when the relay 3 receives the SELECT command from the payment terminal 2, it transmits the SELECT command to the ECU 4 (step S4). Note that if the relay 3 and the eSE 5 are electrically connected, the relay 3 may transmit a command directly to the eSE 5 without going through the ECU 4, or may receive a response directly from the ECU 4. Next, when the control unit 44 of the ECU 4 receives the SELECT command from the relay 3 via the interface unit 41, it transmits the SELECT command to the eSE 5 via the interface unit 42 (step S5).
[0034] Next, when the CPU 54 of the eSE 5 receives the SELECT command from the ECU 4 (or the repeater 3) via the interface unit 51, it selects an application (authentication processing program) in accordance with the SELECT command (i.e., by interpreting the command) (step S6). Next, the CPU 54 of the eSE 5 transmits a response to the SELECT command to the ECU 4 (or the repeater 3) via the interface unit 51 (step S7). This response includes, for example, SW "9000" and FCI (File Control Information) in TLV format.
[0035] Next, when the control unit 44 of the ECU 4 receives the response from the eSE 5 via the interface unit 42, the control unit 44 transmits the response to the repeater 3 via the interface unit 41 (step S8). Next, when the repeater 3 receives the response from the ECU 4 (or the eSE 5), the repeater 3 transmits the response to the payment terminal 2 (step S9).
[0036] Next, when the processing unit 23 of the payment terminal 2 receives a response from the repeater 3 via the reader / writer 22, it starts mutual authentication processing with the eSE 5 (step S10). Note that although the example in FIG. 6 shows mutual authentication processing, it may be one-sided authentication processing. When the mutual authentication processing starts, the processing unit 23 of the payment terminal 2 sends an INITALIZE UPDATE command to the repeater 3 via the reader / writer 22 (step S11). Here, the INITALIZE UPDATE command is a command for notifying the eSE 5 of the start of mutual authentication processing for establishing a secure channel between the payment terminal 2 and the eSE 5. The INITALIZE UPDATE command includes a random number and a Key Version Number. The Key Version Number is data used to identify authentication data that is the basis of cryptographic calculations.
[0037] Next, when the relay 3 receives the INITALIZE UPDATE command from the payment terminal 2, it transmits the INITALIZE UPDATE command to the ECU 4 (or eSE 5) (step S12). Next, when the control unit 44 of the ECU 4 receives the INITALIZE UPDATE command from the relay 3 via the interface unit 41, it transmits the INITALIZE UPDATE command to the eSE 5 via the interface unit 42 (step S13).
[0038] Next, when the CPU 54 of the eSE 5 receives an INITALIZE UPDATE command from the ECU 4 (or the repeater 3) via the interface unit 51, it generates a random number, a session key, and ciphertext A (Card Cryptogram) in response to the INITALIZE UPDATE command (step S14). Here, the session key is an encryption key used in a secure channel, and is generated, for example, based on the random number included in the INITALIZE UPDATE command, the random number generated in step S14, and authentication data stored in the NVM 24. Next, the CPU 54 of the eSE 5 transmits a response including the random number and ciphertext A (Card Cryptogram) generated in step S14 to the ECU 4 (or the repeater 3) via the interface unit 51 (step S15).
[0039] Next, when the control unit 44 of the ECU 4 receives the response from the eSE 5 via the interface unit 42, the control unit 44 transmits the response to the repeater 3 via the interface unit 41 (step S16). Next, when the repeater 3 receives the response from the ECU 4 (or the eSE 5), the repeater 3 transmits the response to the payment terminal 2 (step S17).
[0040] Next, when the processing unit 23 of the payment terminal 2 receives a response from the repeater 3 via the reader / writer 22, it generates a session key and ciphertext A (Card Cryptogram) in the same manner as the eSE 5 according to the authentication processing program (step S18). Next, the processing unit 23 of the payment terminal 2 verifies the legitimacy of the eSE 5 by comparing the ciphertext A (Card Cryptogram) included in the response received from the repeater 3 with the ciphertext A (Card Cryptogram) generated in step S18 (step S19). Next, if the processing unit 23 of the payment terminal 2 successfully verifies the legitimacy of the eSE 5 (i.e., authentication is successful), it generates ciphertext B (Host Cryptogram) (step S20). Next, the processing unit 23 of the payment terminal 2 transmits an EXTERNAL AUTHENTICATE command including the ciphertext B (Host Cryptogram) generated in step S20 to the repeater 3 via the reader / writer 22 (step S21). If the validity verification fails (that is, if authentication fails), error processing is performed.
[0041] Next, when the relay 3 receives the EXTERNAL AUTHENTICATE command from the payment terminal 2, it transmits the EXTERNAL AUTHENTICATE command to the ECU 4 (or eSE 5) (step S22). Next, when the control unit 44 of the ECU 4 receives the EXTERNAL AUTHENTICATE command from the relay 3 via the interface unit 41, it transmits the EXTERNAL AUTHENTICATE command to the eSE 5 via the interface unit 42 (step S23).
[0042] Next, when the CPU 54 of the eSE 5 receives the EXTERNAL AUTHENTICATE command from the ECU 4 (or the repeater 3) via the interface unit 51, it generates ciphertext B (Host Cryptogram) in response to the EXTERNAL AUTHENTICATE command in accordance with the authentication processing program using the same method as the payment terminal 2 (step S24). Next, the CPU 54 of the eSE 5 verifies the legitimacy of the payment terminal 2 by comparing the ciphertext B (Host Cryptogram) included in the EXTERNAL AUTHENTICATE command with the ciphertext B (Host Cryptogram) generated in step S24 (step S25). Next, if the CPU 54 of the eSE 5 succeeds in verifying the legitimacy of the payment terminal 2 (i.e., authentication is successful), it transmits a response indicating successful authentication to the ECU 4 (or the repeater 3) via the interface unit 51 (step S26). Note that if the legitimacy verification fails (i.e., authentication is unsuccessful), error processing is performed.
[0043] Next, when the control unit 44 of the ECU 4 receives the response from the eSE 5 via the interface unit 42, it transmits the response to the relay 3 via the interface unit 41 (step S27). Next, when the relay 3 receives the response from the ECU 4 (or the eSE 5), it transmits the response to the payment terminal 2 (step S28). Next, when the processing unit 23 of the payment terminal 2 receives the response from the relay 3 via the reader / writer 22, it ends the mutual authentication process with the eSE 5 (step S29). This establishes a secure channel between the payment terminal 2 and the eSE 5.
[0044] 7, when a secure session is started (step S31), processing unit 23 of payment terminal 2 encrypts a SELECT command for selecting an application (payment processing program) for performing payment processing with the session key, and transmits the encrypted SELECT command (hereinafter referred to as the "encrypted SELECT command") to repeater 3 via reader / writer 22 (step S32). The SELECT command includes an identifier (AID) of the application to be selected.
[0045] Next, when the repeater 3 receives the encrypted SELECT command from the payment terminal 2, it transmits the encrypted SELECT command to the ECU 4 (or eSE 5) (step S33). Next, when the control unit 44 of the ECU 4 receives the encrypted SELECT command from the repeater 3 via the interface unit 41, it transmits the encrypted SELECT command to the eSE 5 via the interface unit 42 (step S34).
[0046] Next, when the CPU 54 of the eSE 5 receives the encrypted SELECT command from the ECU 4 (or the repeater 3) via the interface unit 51, it decrypts the encrypted SELECT command with the session key and transmits the decrypted SELECT command to the ECU 4 via the interface unit 51 (step S35). Next, when the control unit 44 of the ECU 4 receives the SELECT command from the eSE 5, it selects an application (payment processing program) in accordance with the SELECT command (step S36). Next, the control unit 44 of the ECU 4 transmits a response to the SELECT command to the eSE 5 via the interface unit 42 (step S37).
[0047] Next, when the CPU 54 of the eSE 5 receives the response from the ECU 4 via the interface unit 51, it encrypts the response with the session key and transmits the encrypted response (hereinafter referred to as the "encrypted response") to the ECU 4 (or the relay 3) via the interface unit 51 (step S38). Next, when the control unit 44 of the ECU 4 receives the encrypted response from the eSE 5 via the interface unit 42, it transmits the encrypted response to the relay 3 via the interface unit 41 (step S39). Next, when the relay 3 receives the encrypted response from the ECU 4 (or the eSE 5), it transmits the encrypted response to the payment terminal 2 (step S40).
[0048] Next, when processing unit 23 of payment terminal 2 receives the encrypted response from repeater 3 via reader / writer 22, it decrypts the encrypted response. Next, processing unit 23 of payment terminal 2 encrypts a GET DATA command indicating a request to acquire a unique identification number and a version number with the session key, and transmits the encrypted GET DATA command (hereinafter referred to as the "encrypted GET DATA command") to repeater 3 via reader / writer 22 (step S41). Here, the unique identification number related to the acquisition request is the unique identification number of ECU 4, and the version number related to the acquisition request is the version number of an application (payment processing program) selected from the applications installed in ECU 4.
[0049] Next, when the repeater 3 receives the encrypted GET DATA command from the payment terminal 2, it transmits the encrypted GET DATA command to the ECU 4 (or eSE 5) (step S42). Next, when the control unit 44 of the ECU 4 receives the encrypted GET DATA command from the repeater 3 via the interface unit 41, it transmits the encrypted GET DATA command to the eSE 5 via the interface unit 42 (step S43).
[0050] Next, when the CPU 54 of the eSE 5 receives the encrypted GET DATA command from the ECU 4 (or the repeater 3) via the interface unit 51, it decrypts the encrypted GET DATA command with the session key and transmits the decrypted GET DATA command to the ECU 4 via the interface unit 51 (step S44). Next, when the control unit 44 of the ECU 4 receives the GET DATA command from the eSE 5, it reads the unique identification number of the ECU 4 and the version number of the selected application (payment processing program) from the storage unit 43 in response to the GET DATA command (step S45). Next, the control unit 44 of the ECU 4 transmits a response including the unique identification number and version number read in step S45 to the eSE 5 via the interface unit 42 (step S46).
[0051] Next, when the CPU 54 of the eSE 5 receives the response from the ECU 4 via the interface unit 51, it encrypts the response with the session key and transmits the encrypted response to the ECU 4 (or the relay 3) via the interface unit 51 (step S47). Next, when the control unit 44 of the ECU 4 receives the encrypted response from the eSE 5 via the interface unit 42, it transmits the encrypted response to the relay 3 via the interface unit 41 (step S48). Next, when the relay 3 receives the encrypted response from the ECU 4 (or the eSE 5), it transmits the encrypted response to the payment terminal 2 (step S49).
[0052] Next, when the processing unit 23 of the payment terminal 2 receives the encrypted response from the repeater 3 via the reader / writer 22, the processing unit 23 decrypts the encrypted response and acquires the unique identification number and version number from the decrypted response (step S50). In this way, the processing unit 23 acquires the unique identification number and version number from the ECU 4 via the repeater 3 or the like. Next, as shown in FIG. 8 , the processing unit 23 of the payment terminal 2 determines whether or not there is a patch application target device list (i.e., whether or not it is stored in the storage unit 21) that registers the combination of the unique identification number and version number acquired in step S50 in association with the identifier of the application currently selected by the ECU 4 (step S51). If it is determined that such a patch application target device list exists (step S51: YES), the patch application target device list is identified, and the process proceeds to step S52. If it is determined that there is no patch application target device list (step S51: NO), the process proceeds to step S63.
[0053] In addition, if only one application that may be patched is installed in ECU4, the processing unit 23 of the payment terminal 2 only needs to determine whether there is a list of devices to which the patch can be applied that registers the combination of the unique identification number and version number obtained in step S50 (there is no need to refer to the application identifier).
[0054] In step S52, processing unit 23 of payment terminal 2 identifies a patch associated with the list of devices to be patched identified in step S51 from storage unit 21. Next, processing unit 23 of payment terminal 2 encrypts an UPDATE command (UPDATE PROGRAM command) including the patch identified in step S52 with the session key, and transmits the encrypted UPDATE command (hereinafter referred to as the "encrypted UPDATE command") to repeater 3 via reader / writer 22 (step S53).
[0055] Next, when the repeater 3 receives the encrypted UPDATE command from the payment terminal 2, it transmits the encrypted UPDATE command to the ECU 4 (or eSE 5) (step S54). Next, when the control unit 44 of the ECU 4 receives the encrypted UPDATE command from the repeater 3 via the interface unit 41, it transmits the encrypted UPDATE command to the eSE 5 via the interface unit 42 (step S55).
[0056] Next, when the CPU 54 of the eSE 5 receives the encrypted UPDATE command from the ECU 4 (or the relay 3) via the interface unit 51, it decrypts the encrypted UPDATE command with the session key and transmits the decrypted UPDATE command to the ECU 4 via the interface unit 51 (step S56). Next, when the control unit 44 of the ECU 4 receives the UPDATE command from the eSE 5, it acquires the patch included in the UPDATE command (step S57) and updates the selected application (payment processing program) based on the acquired patch (step S58). If the patch update is successful, the control unit 44 of the ECU 4 transmits a response indicating successful completion to the eSE 5 via the interface unit 41 (step S59). Note that if the patch update is not successful, the control unit 44 of the ECU 4 performs rollback processing.
[0057] Next, when the CPU 54 of the eSE 5 receives a response from the ECU 4 via the interface unit 51, it encrypts the response with the session key and transmits the encrypted response to the ECU 4 (or the relay 3) via the interface unit 51 (step S60). Next, when the control unit 44 of the ECU 4 receives the encrypted response from the eSE 5 via the interface unit 42, it transmits the encrypted response to the relay 3 via the interface unit 41 (step S61). Next, when the relay 3 receives the encrypted response from the ECU 4 (or the eSE 5), it transmits the encrypted response to the payment terminal 2 (step S62).
[0058] Next, when processing unit 23 of payment terminal 2 receives the encrypted response from repeater 3 via reader / writer 22, it decrypts the encrypted response and proceeds to step S63. In step S63, processing unit 23 of payment terminal 2 encrypts a GET DATA command indicating a request to acquire payment data with the session key, and transmits the encrypted GET DATA command to repeater 3 via reader / writer 22.
[0059] Next, when the repeater 3 receives the encrypted GET DATA command from the payment terminal 2, it transmits the encrypted GET DATA command to the ECU 4 (or eSE 5) (step S64). Next, when the control unit 44 of the ECU 4 receives the encrypted GET DATA command from the repeater 3 via the interface unit 41, it transmits the encrypted GET DATA command to the eSE 5 via the interface unit 42 (step S65).
[0060] Next, when the CPU 54 of the eSE 5 receives the encrypted GET DATA command from the ECU 4 (or the repeater 3) via the interface unit 51, it decrypts the encrypted GET DATA command with the session key and transmits the decrypted GET DATA command to the ECU 4 via the interface unit 51 (step S66). Next, when the control unit 44 of the ECU 4 receives the GET DATA command from the eSE 5, it reads out payment data from the storage unit 43 using the selected application (payment processing program) in response to the GET DATA command (step S67). Next, the control unit 44 of the ECU 4 transmits a response including the payment data read out in step S67 to the eSE 5 via the interface unit 42 (step S68).
[0061] Next, when the CPU 54 of the eSE 5 receives the response from the ECU 4 via the interface unit 51, it encrypts the response with the session key and transmits the encrypted response to the ECU 4 (or the relay 3) via the interface unit 51 (step S69). Next, when the control unit 44 of the ECU 4 receives the encrypted response from the eSE 5 via the interface unit 42, it transmits the encrypted response to the relay 3 via the interface unit 41 (step S70). Next, when the relay 3 receives the encrypted response from the ECU 4 (or the eSE 5), it transmits the encrypted response to the payment terminal 2 (step S71).
[0062] Next, when processing unit 23 of payment terminal 2 receives the encrypted response from repeater 3 via reader / writer 22, it decrypts the encrypted response and executes payment for the fee based on the payment data included in the decrypted response (step S72). For example, processing unit 23 of payment terminal 2 executes processing to charge (e.g., debit) the parking fee to the user using the payment method specified by the payment data.
[0063] In the above example, the payment terminal 2 is configured to determine whether there is a patch application target device list that registers a combination of the unique identification number of the ECU 4 and the version number of the application currently selected by the ECU 4. Alternatively, the ECU 4 may obtain a patch application target device list that includes the identifier of the application currently selected by the ECU 4 from the payment terminal 2 via the repeater 3 or the like, and determine whether the combination of the unique identification number and version number stored in the storage unit 43 is registered in the patch application target device list. In this case, it is determined whether a specific unique identification number registered in the patch application target device list matches the unique identification number stored in the storage unit 43, and whether a specific version number registered in the patch application target device list matches the version number (the version number of the selected application) stored in the storage unit 43.
[0064] Then, when the combination of the unique identification number and the version number stored in the storage unit 43 is registered in the patch application target device list, the ECU 4 acquires the patch associated with the patch application target device list from the payment terminal 2 via the repeater 3 or the like. The patch application target device list may be transmitted from the payment terminal 2, included in a predetermined command such as a Verify command. Furthermore, when it is determined that the combination of the unique identification number and the version number stored in the storage unit 43 is registered in the patch application target device list, a response indicating normal completion is transmitted to the payment terminal 2 via the repeater 3 or the like. As a result, an UPDATE command including the patch associated with the patch application target device list transmitted to the ECU 4 is transmitted from the payment terminal 2.
[0065] Furthermore, in the above example, the payment processing program installed in the ECU 4 has been described as an example of an application to which a patch is applied, but it may also be an authentication processing program installed in the eSE 5. In this case, before starting the mutual authentication process with the eSE 5 in step S10, the payment terminal 2 transmits to the relay 3 a GET DATA command indicating a request to acquire the unique identification number of the eSE 5 and the version number of the authentication processing program installed in the eSE 5. As a result, if there is a patch application target device list that registers a combination of the unique identification number and version number included in the response received from the eSE 5 via the relay 3 or the like in association with the identifier of the authentication processing program currently selected in the eSE 5, the payment terminal 2 provides the patch associated with this to the eSE 5 via the relay 3 or the like, thereby updating the authentication processing program.
[0066] As described above, according to the above embodiment, an electronic device such as the ECU 4 stores its own unique identification number and the version number of the selected software in advance, and after the authentication process between the payment terminal 2 and the electronic device is completed, a patch specified by the unique identification number and version number is obtained from the payment terminal 2 via the repeater 3, and the software is updated based on the obtained patch. This makes it possible to more efficiently update software installed in an electronic device in the vehicle C. This embodiment is particularly effective when the vehicle C is not equipped with a device that can connect to a mobile communication network having a base station for wireless communication, or when the vehicle C is equipped with a device that can connect to the mobile communication network but is located in an area where radio waves from the base station cannot reach.
[0067] In the above embodiment, the ECU 4 has been described as an example of the electronic device of the present invention, but it may also be an electronic device of a passenger of the vehicle C. In this case, the electronic device stores a unique identification number specific to the electronic device and a version number of the software installed on the electronic device. The electronic device then performs the authentication process as described above by communicating with the payment terminal 2 via the repeater 3. After the authentication process is completed, the electronic device obtains a patch identified by the stored unique identification number and version number from the payment terminal 2 via the repeater 3, and updates the software based on the obtained patch. [Explanation of symbols]
[0068] 1 Management Server 2. Payment terminal 3 Repeater 4 ECU 5 eSE 21 Memory section 22 Reader / Writer 23 Processing section 21 Antenna 41 Interface section 42 Interface section 43 Storage section 44 Control Unit 51 Interface section 52 RAM 53 NVM 54 CPU S Payment Processing System
Claims
1. An electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, a storage means for storing a unique identification number of the electronic device and a version number of the software installed on the electronic device; an authentication unit that executes an authentication process between the relay device and the external device; an acquisition unit that acquires patch data identified by the unique identification number and version number stored in the storage unit from the external device via the relay device after the authentication process is completed; an update unit that updates the software based on the patch data acquired by the acquisition unit; Equipped with The electronic device is characterized in that the acquisition means acquires a list registering combinations of specific unique identification numbers and specific version numbers from the external device via the relay device, and acquires the patch data from the external device via the relay device if the combination of the unique identification number and the version number stored in the storage means is registered in the list.
2. An electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, a storage means for storing a unique identification number of the electronic device and a version number of the software installed on the electronic device; an authentication unit that executes an authentication process between the relay device and the external device; an acquisition unit that acquires patch data identified by the unique identification number and version number stored in the storage unit from the external device via the relay device after the authentication process is completed; an update unit that updates the software based on the patch data acquired by the acquisition unit; Equipped with the electronic device is configured by a secure element and an ECU (Electronic Control Unit) mounted on the mobile object, the secure element includes the authentication means and the acquisition means, and the acquisition means acquires the patch data encrypted with a session key that is generated in the authentication process and is common to the external device, and decrypts the patch data with the session key; The electronic device is characterized in that the ECU includes the storage means and the update means, and the update means updates the software based on the decrypted patch data.
3. The electronic device according to claim 1 or 2, characterized in that the acquisition means acquires the patch data from the external device via the relay device by transmitting the unique identification number and the version number stored in the storage means to the external device via the relay device.
4. A terminal device capable of communicating with an electronic device installed in a mobile body or an electronic device carried by a passenger of the mobile body via a relay device mounted on the mobile body, the electronic device stores a unique identification number of the electronic device and a version number of software installed on the electronic device; The terminal device an authentication unit that performs an authentication process between the electronic device and the relay device; an acquisition unit that acquires the unique identification number and the version number from the electronic device via the relay device after the authentication process is completed; a transmitting means for transmitting patch data for updating the software installed in the electronic device, the patch data corresponding to the unique identification number and the version number acquired by the acquiring means, via the relay device; A terminal device comprising:
5. 1. A software update method executed by an electronic device capable of communicating with an external device installed outside a mobile object via a relay device mounted on the mobile object, comprising: storing in a storage means a unique identification number of the electronic device and a version number of the software installed on the electronic device; performing an authentication process between the relay device and the external device via the relay device; an acquisition step of acquiring patch data identified by the unique identification number and version number stored in the storage means from the external device via the relay device after the authentication process is completed; updating the software based on the acquired patch data; Including, A software update method characterized in that in the acquisition step, a list registering combinations of specific unique identification numbers and specific version numbers is acquired from the external device via the relay device, and if the combination of the unique identification number and the version number stored in the storage means is registered in the list, the patch data is acquired from the external device via the relay device.
6. A software update method executed by an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, the electronic device being composed of a secure element mounted on the mobile body and an ECU (Electronic Control Unit), a step in which the ECU stores in a storage means the unique identification number of the electronic device and the version number of the software installed in the electronic device; a step of the secure element executing an authentication process between the secure element and the external device via the relay device; an acquisition step in which the secure element acquires patch data identified by the unique identification number and version number stored in the storage means from the external device via the relay device after the authentication process is completed; an updating step in which the ECU updates the software based on the acquired patch data; Including, In the acquiring step, the patch data encrypted with a session key generated in the authentication process and shared with the external device is acquired, and the patch data is decrypted with the session key; In the updating step, the software is updated based on the decrypted patch data.
7. A computer included in an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, a storage means for storing a unique identification number of the electronic device and a version number of the software installed on the electronic device; an authentication unit that executes an authentication process between the relay device and the external device; an acquisition unit that acquires patch data identified by the unique identification number and version number stored in the storage unit from the external device via the relay device after the authentication process is completed; a program that functions as an update unit that updates the software based on the patch data acquired by the acquisition unit, The program is characterized in that the acquisition means acquires a list registering combinations of specific unique identification numbers and specific version numbers from the external device via the relay device, and acquires the patch data from the external device via the relay device if the combination of the unique identification number and the version number stored in the storage means is registered in the list.
8. A computer included in an electronic device that is capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body and that is composed of a secure element mounted on the mobile body and an ECU (Electronic Control Unit), a storage means for storing a unique identification number of the electronic device and a version number of the software installed on the electronic device; an authentication unit that executes an authentication process between the relay device and the external device; an acquisition unit that acquires patch data identified by the unique identification number and version number stored in the storage unit from the external device via the relay device after the authentication process is completed; a program that functions as an update unit that updates the software based on the patch data acquired by the acquisition unit, the acquisition means acquires the patch data encrypted with a session key that is generated in the authentication process and is common to the external device, and decrypts the patch data with the session key; The update means updates the software based on the decrypted patch data.
Citation Information
Patent Citations
Correction program confirmation method, correction program confirmation program, and information processing apparatus
JP2015079440A
Program update system, program update method and computer program
JP2019168977A
Mechanism for secure in-vehicle payment transaction
JP2020053066A