Electronic device, application addition method, and program

The described method allows for efficient application addition to vehicle ECUs and SEs using a relay device for authentication and installation, overcoming network dependency issues.

JP7732289B2Active Publication Date: 2025-09-02DAI NIPPON PRINTING CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021145158
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-07
Publication Date
2025-09-02
Estimated Expiration
2041-09-07

AI Technical Summary

Technical Problem

Existing methods for adding applications to electronic devices in vehicles, such as ECUs or SEs, are inefficient when mobile communication networks are unavailable.

Method used

An electronic device and method that utilizes a relay device mounted on a mobile body to communicate with external devices, enabling authentication, acquisition, and installation of applications using a unique identification number and session key, even without a mobile communication network.

Benefits of technology

Enables efficient addition of applications to electronic devices in vehicles by establishing a secure session and installing applications via a relay device, ensuring seamless service provision.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007732289000001
    Figure 0007732289000001
  • Figure 0007732289000002
    Figure 0007732289000002
  • Figure 0007732289000003
    Figure 0007732289000003
Patent Text Reader

Abstract

To provide an electronic device, an application adding method, and a program capable of efficiently adding an application to an electronic device in a vehicle.SOLUTION: The electronic device such as the ECU 4 has: storage means for storing its own unique identification number and application list; acquisition means for acquiring an application which is identified by the stored unique identification number after the authentication process is completed between the payment terminal 2 and the electronic device and whose identifier is not shown in the application list, from the payment terminal 2 via the repeater 3; and installation means for installing the obtained application.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to the technical field of a method for providing various services, such as payment, to a vehicle user via short-range wireless communication. [Background technology]

[0002] Conventionally, various services such as payment can be provided to vehicle users via short-range wireless communication between an ECU (Electronic Control Unit) or SE (Secure Element) installed in a vehicle and a server installed outside the vehicle. For example, Patent Document 1 discloses a system in which, when a VID (Vehicle Interface Device) installed in a vehicle receives a request for payment account information from a dealer access device, the system determines whether the user's mobile communication device is inside the vehicle, and if it determines that the mobile communication device is inside the vehicle, transmits payment account information read from a payment card inserted in the VID to the dealer access device. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2020-53066 Summary of the Invention [Problem to be solved by the invention]

[0004] The various services described above are realized by applications installed in, for example, an ECU or an SE, but when installing such an application, it is necessary to install and add the application to the ECU or SE by transmitting the application (application file) from a server to the ECU or SE using, for example, a mobile communication network. However, if a mobile communication network is not available, it is not possible to efficiently add the application. Therefore, the present invention has been made in consideration of the above points and aims to provide an electronic device, an application addition method, and a program that enable applications to be added to an electronic device in a vehicle more efficiently. [Means for solving the problem]

[0005] In order to solve the above problem, the invention of claim 1 provides an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, the electronic device comprising: a storage means for storing a unique identification number of the electronic device and a list indicating identifiers of applications installed on the electronic device; an authentication means for executing an authentication process with the external device via the relay device; an acquisition means for acquiring, after the authentication process is completed, from the external device via the relay device, an application identified by the unique identification number stored in the storage means and whose identifier is not indicated in the list; and an installation means for installing the application acquired by the acquisition means. The acquisition means acquires a specific unique identification number and an identifier of a specific application from the external device via the relay device, and if the specific unique identification number matches the unique identification number stored in the storage means and the identifier of the specific application is not included in the list, transmits a request for the application to the external device via the relay device, thereby acquiring the application from the external device via the relay device. It is characterized by: The invention described in claim 2 is an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, comprising: a storage means for storing a unique identification number of the electronic device and a list indicating identifiers of applications installed on the electronic device; an authentication means for performing an authentication process with the external device via the relay device; an acquisition means for acquiring, after the authentication process is completed, from the external device via the relay device, an application identified by the unique identification number stored in the storage means and whose identifier is not shown in the list; and an installation means for installing the application acquired by the acquisition means, wherein the electronic device is composed of a secure element and an ECU (Electronic Control Unit) mounted on the mobile body, the secure element including the authentication means and the acquisition means, the acquisition means acquiring the application encrypted using a session key generated in the authentication process and common to the external device, and decrypting the application using the session key, the ECU including the storage means and the installation means, and the installation means installing the decrypted application.

[0006] Claim 3 The invention described in claim 1 or 2 In the electronic device described above, the acquisition means is characterized in that it acquires the application from the external device via the relay device by transmitting the unique identification number and the list to the external device via the relay device.

[0009] Claim 4The invention described in is a terminal device capable of communicating with an electronic device installed in a mobile body or an electronic device carried by a passenger of the mobile body via a relay device mounted on the mobile body, wherein the electronic device stores a unique identification number of the electronic device and a list indicating identifiers of applications installed on the electronic device, and the terminal device is characterized by comprising: an authentication means for performing an authentication process with the electronic device via the relay device; an acquisition means for acquiring the unique identification number and the list from the electronic device via the relay device after the authentication process is completed; and a transmission means for transmitting, via the relay device, an application identified by the unique identification number acquired by the acquisition means and whose identifier is not indicated in the list.

[0010] Claim 5 The invention described in is an application addition method executed by an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, the method comprising the steps of: storing a list indicating a unique identification number of the electronic device and identifiers of applications installed on the electronic device in a storage means; performing authentication processing with the external device via the relay device; and, after the authentication processing is completed, acquiring from the external device via the relay device an application identified by the unique identification number stored in the storage means and whose identifier is not indicated in the list. acquisition and installing the acquired application. In the acquisition step, a specific unique identification number and an identifier of a specific application are acquired from the external device via the relay device, and if the specific unique identification number matches the unique identification number stored in the storage means and the identifier of the specific application is not shown in the list, a request for the application is transmitted to the external device via the relay device, thereby acquiring the application from the external device via the relay device. It is characterized by: The invention described in claim 6 is an application adding method executed by an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, the electronic device being composed of a secure element mounted on the mobile body and an ECU (Electronic Control Unit), the method including: a step by the ECU storing in a storage means a list indicating a unique identification number of the electronic device and identifiers of applications installed on the electronic device; a step by the secure element performing an authentication process with the external device via the relay device; an acquisition step by the secure element acquiring from the external device via the relay device, after the authentication process is completed, an application identified by the unique identification number stored in the storage means and whose identifier is not shown in the list; and an installation step by the ECU installing the acquired application, wherein in the acquisition step, the application encrypted with a session key generated in the authentication process and common to the external device is acquired, and the application is decrypted using the session key; and in the installation step, the decrypted application is installed.

[0011] The invention described in claim 7 is a method for making a computer included in an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body function as: a storage means for storing a unique identification number of the electronic device and a list indicating identifiers of applications installed on the electronic device; an authentication means for executing an authentication process with the external device via the relay device; an acquisition means for acquiring, after the authentication process is completed, from the external device via the relay device, an application identified by the unique identification number stored in the storage means and whose identifier is not indicated in the list; and an installation means for installing the application acquired by the acquisition means. a program, wherein the acquisition means acquires a specific unique identification number and an identifier of a specific application from the external device via the relay device, and, if the specific unique identification number matches a unique identification number stored in the storage means and the identifier of the specific application is not included in the list, transmits a request for the application to the external device via the relay device, thereby acquiring the application from the external device via the relay device; It is characterized by: The invention described in claim 8 is a program that causes a computer included in an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, the electronic device being composed of a secure element and an ECU (Electronic Control Unit) mounted on the mobile body, to function as: a storage means that stores a unique identification number of the electronic device and a list indicating identifiers of applications installed on the electronic device; an authentication means that performs an authentication process with the external device via the relay device; an acquisition means that, after the authentication process is completed, acquires from the external device via the relay device an application identified by the unique identification number stored in the storage means and whose identifier is not shown in the list; and an installation means that installs the application acquired by the acquisition means, wherein the acquisition means acquires the application encrypted using a session key generated in the authentication process and common to the external device, and decrypts the application using the session key; and the installation means installs the decrypted application. [Effects of the Invention]

[0012] According to the present invention, applications can be added to electronic devices in a vehicle more efficiently. [Brief explanation of the drawings]

[0013] [Figure 1] 1 is a diagram illustrating an example of a schematic configuration of a payment processing system S according to an embodiment of the present invention. [Figure 2] FIG. 2 is a diagram illustrating an example of a schematic configuration of a payment terminal 2. [Figure 3] FIG. 2 is a diagram illustrating an example of a schematic configuration of an ECU 4. [Figure 4] FIG. 1 is a diagram illustrating an example of a schematic configuration of an eSE5. [Figure 5] 1 is a conceptual diagram showing the positional relationship between a reader / writer 22 embedded in the ground of a pay-by-the-hour parking lot and a vehicle C. FIG. [Figure 6] 10 is a sequence diagram showing an example of a transaction carried out in the payment processing system S before the start of a secure session. FIG. [Figure 7] 10 is a sequence diagram showing an example of a transaction carried out after a secure session is started in the payment processing system S. FIG. [Figure 8]10 is a sequence diagram showing an example of a transaction carried out after a secure session is started in the payment processing system S. FIG. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings. The embodiment described below is an embodiment in which the present invention is applied to a payment processing system in which payment processing is performed between a payment terminal installed outside a vehicle and an ECU (Electronic Control Unit) installed in the vehicle. The payment terminal is an example of an external device, and the ECU is an example of an electronic device. The vehicle is an example of a mobile object, such as a two-wheeled automobile, a four-wheeled automobile, or a bicycle.

[0015] [1. Overview of payment processing system S] First, the schematic configuration of a payment processing system S according to this embodiment will be described with reference to Fig. 1 etc. Fig. 1 is a diagram showing an example of the schematic configuration of the payment processing system S according to this embodiment. As shown in Fig. 1, the payment processing system S is configured to include a management server 1, a payment terminal 2, a repeater 3 (an example of a repeater device), an ECU (Electronic Control Unit) 4, and an eSE (embedded Secure Element) 5. The management server 1 and the payment terminal 2 (an example of a terminal device) are each connected to a network NW configured, for example, by the Internet, and the management server 1 and the payment terminal 2 are capable of communicating via the network NW.

[0016] The management server 1 is a server for managing specific applications that can be provided to specific devices (e.g., specific ECUs or eSEs). The specific applications are software required to use various services such as payment services. A unique identifier is assigned to each specific application. The specific application is provided to the payment terminal 2 via the network NW together with the unique identification number of the specific device (e.g., specific ECU or eSE) that can provide the application. The unique identification number of the specific device may be a number that identifies the model of the vehicle C.

[0017] The payment terminal 2 is installed in locations such as stores with drive-through facilities, parking lots, and gas stations, and is a terminal that performs payment processing between the payment terminal 2 and the ECU 4 for payment when a user purchases a product or receives a service. Such locations are outside the vehicle C and are vehicle visit locations that the vehicle C can visit while traveling. Payment methods used in the payment processing include, but are not limited to, electronic money payment and credit card payment. When the payment method is credit card payment, the payment terminal 2 may access a server that manages credit card information via the network NW to perform a credit inquiry.

[0018] Fig. 2 is a diagram showing an example of the general configuration of the payment terminal 2. As shown in Fig. 2, the payment terminal 2 is composed of a storage unit 21, a reader / writer 22, a CPU (Central Processing Unit), etc. The management server 1 includes a processing unit 23 that stores software such as an operating system (OS) and applications. The applications include an authentication processing program and a payment processing program. The storage unit 21 also stores authentication data used in authentication processing to establish a secure channel with the eSE 5. The authentication data is, for example, a key set including a secure channel encryption key, a secure channel MAC (Message Authentication Code) key, and a data encryption key. The storage unit 21 also stores a specific application provided by the management server 1 and a unique identification number of a specific device in association with each other. This allows a specific application to be identified by the unique identification number of a specific device.

[0019] The reader / writer 22 is equipped with an antenna and is capable of performing short-range wireless communication with the repeater 3 within a range where short-range wireless communication is possible. The protocol for short-range wireless communication between the reader / writer 22 and the repeater 3 may be, for example, a UWB protocol. In this case, the reader / writer 22 periodically checks (confirms its location) whether or not the repeater 3 with which it is communicating is present within a preset distance range, and performs short-range wireless communication with the repeater 3 that is confirmed to be present within the distance range. The reader / writer 22 may be embedded in the ground, for example, outside the housing of the payment terminal 2, through which the vehicle C passes.

[0020] The processing unit 23 is an example of the authentication means, acquisition means, and transmission means of the present invention. The processing unit 23 executes authentication processing for establishing a secure session with the eSE 5 via the relay 3 in accordance with an authentication processing program. In this authentication processing, mutual authentication using, for example, a General Vehicle Authentication System (GVAS) may be performed. When the authentication processing with the eSE 5 is completed and a secure session with the eSE 5 is established, the processing unit 23 encrypts an application identified by the unique identification number of the ECU 4 connected to the authenticated eSE 5 but not installed in the ECU 4 using a session key generated by the authentication processing (i.e., a session key shared with the eSE 5), and provides the encrypted application to the eSE 5. Such an application is, for example, an application required for using a payment service provided to the ECU 4 connected to the authenticated eSE 5 after the authentication processing is completed. After the secure session between the eSE 5 and the payment terminal 2 is established, the processing unit 23 executes payment processing in accordance with the payment processing program.

[0021] The repeater 3, ECU 4, and eSE 5 are installed, for example, in a center console in the vehicle C. In the vehicle C, the repeater 3 and the ECU 4 are electrically connected, and the ECU 4 and the eSE 5 are also electrically connected. The repeater 3 and the eSE 5 may be electrically connected. The repeater 3 is equipped with an antenna and is capable of short-range wireless communication with the reader / writer 22. Furthermore, the repeater 3 performs short-range wireless communication with an electronic device of a passenger (user) of the vehicle C within a range where short-range wireless communication is possible. The electronic device of the passenger of the vehicle C is, for example, a contactless IC card or a smartphone carried by the passenger. The protocol for short-range wireless communication between the electronic device of the passenger of the vehicle C and the repeater 3 may be, for example, an NFC protocol (for example, a protocol specified in ISO 14443). The contactless IC card may be configured to include a secure element, such as a UICC (Universal Integrated Circuit Card) with high tamper resistance.

[0022] FIG. 3 is a diagram showing an example of a schematic configuration of the ECU 4. As shown in FIG. 3, the ECU 4 is configured to include an interface (I / F) unit 41, an interface (I / F) unit 42, a storage unit 43, and a control unit 44. The interface unit 41 serves as an interface with the repeater 3. The interface unit 42 serves as an interface with the eSE 5. Examples of interfaces include SPI (Serial Peripheral Interface), I 2 C (Inter-Integrated Circuit), and ISO7816 interfaces. 4 and eSE5 constitute the electronic device of the present invention.

[0023] The memory unit 43 stores software such as an OS and applications. The applications include payment processing programs required to use the payment service. The memory unit 43 also stores payment data. The payment data includes information required for payment depending on the payment method. For example, if the payment method is credit card payment, the payment data includes data such as the credit card number, the cardholder's name, and expiration date required for credit card payment. If the payment method is electronic money payment, the payment data includes data such as the electronic money number and electronic value required for electronic money payment. Furthermore, the memory unit 43 (an example of a storage means) stores the unique identification number of the ECU 4 and a list indicating the identifiers of applications installed in the ECU 4 (hereinafter referred to as the "application list").

[0024] The control unit 44 is configured with a CPU, RAM, ROM, etc. The control unit 44 is an example of the acquisition means and installation means of the present invention. When a secure session is established between the eSE 5 and the payment terminal 2 and an application (payment processing program) is provided from the payment terminal 2 via the repeater 3 and the eSE 5, the control unit 44 acquires and installs the application. That is, the control unit 44 unpacks a file related to the downloaded application and sets it to an operable state on the OS. After a secure session is established between the eSE 5 and the payment terminal 2, the control unit 44 executes payment processing in accordance with the payment processing program. The control unit 44 may also be used to control engine start and door lock / unlock of the vehicle C. When a multimedia terminal such as a display is provided on the console of the vehicle C, the multimedia terminal is electrically connected to the control unit 44 via an interface unit (not shown) and controlled by the control unit 44.

[0025] The eSE 5 is installed, for example, inside the center console of the vehicle C, and is a secure element such as an eUICC (embedded universal integrated circuit card) with high tamper resistance. FIG. 4 is a diagram showing an example of a schematic configuration of the eSE 5. As shown in FIG. 4, the eSE 5 is configured with an interface (I / F) unit 51, a RAM (random access memory) 52, an NVM (nonvolatile memory) 53, a CPU 54, etc. The interface unit 51 serves as an interface with the ECU 4 and is electrically connected to the ECU 4. The NVM 53 stores software such as an OS and applications. The applications include an authentication processing program.

[0026] NVM 53 stores authentication data (e.g., a key set including a secure channel encryption key, a secure channel MAC key, and a data encryption key) used in authentication processing to establish a secure channel with payment terminal 2. NVM 53 may also store a unique identification number of ECU 4 and an application list indicating identifiers of applications installed in eSE 5. CPU 54 is an example of an authentication means and an acquisition means of the present invention. CPU 54 executes authentication processing to establish a secure session with payment terminal 2 via repeater 3 in accordance with an authentication processing program. When authentication processing with payment terminal 2 is completed and a secure session with payment terminal 2 is established, and an application (payment processing program) encrypted with a session key shared with payment terminal 2 is provided, CPU 54 acquires the application, decrypts the application with the session key, and provides the application to ECU 4.

[0027] [2. Operation of payment processing system S] Next, the operation of the payment processing system S will be described with reference to Fig. 5 to Fig. 8. Fig. 5 is a schematic diagram showing the positional relationship between a reader / writer 22 embedded in the ground of a pay-by-time parking lot and a vehicle C. Fig. 6 is a sequence diagram showing an example of a transaction carried out before the start of a secure session in the payment processing system S. Figs. 7 and 8 are sequence diagrams showing an example of a transaction carried out after the start of a secure session in the payment processing system S.

[0028] 5A, the reader / writer 22 of the payment terminal 2 actively transmits radio waves D and periodically checks whether a communication partner (i.e., the payment terminal 2) is present within a predetermined distance range H, as shown in FIG. 5A. In the example of FIG. 5A, the vehicle C equipped with the repeater 3 is not within the distance range H, so the presence of the repeater 3 within the distance range H is not confirmed (detected) (standby state). On the other hand, in the example of FIG. 5B, the vehicle C equipped with the repeater 3 enters the distance range H, and the presence of the repeater 3 within the distance range H is confirmed (communication starts). Note that the example of FIG. 5B illustrates a case in which the vehicle C is parked. However, even when the vehicle C passes a predetermined position, such as in an electronic toll collection system (ETC), the ECU 4 may confirm that it is present within the distance range H, and as a result, communication may start. Alternatively, the repeater 3 equipped in the vehicle C may actively transmit radio waves and periodically check whether a communication partner (i.e., the payment terminal 2) is present within a predetermined distance range.

[0029] 6, when processing unit 23 of payment terminal 2 confirms that repeater 3 is present within distance range H (step S1), it starts short-range wireless communication with repeater 3 (step S2) and transmits a SELECT command to select an application (authentication processing program) for performing authentication processing to repeater 3 via reader / writer 22 (step S3). The SELECT command includes an identifier (AID) of the application to be selected.

[0030] Next, when the relay 3 receives the SELECT command from the payment terminal 2, it transmits the SELECT command to the ECU 4 (step S4). Note that if the relay 3 and the eSE 5 are electrically connected, the relay 3 may transmit a command directly to the eSE 5 without going through the ECU 4, or may receive a response directly from the ECU 4. Next, when the control unit 44 of the ECU 4 receives the SELECT command from the relay 3 via the interface unit 41, it transmits the SELECT command to the eSE 5 via the interface unit 42 (step S5).

[0031] Next, when the CPU 54 of the eSE 5 receives the SELECT command from the ECU 4 (or the repeater 3) via the interface unit 51, it selects an application (authentication processing program) in accordance with the SELECT command (i.e., by interpreting the command) (step S6). Next, the CPU 54 of the eSE 5 transmits a response to the SELECT command to the ECU 4 (or the repeater 3) via the interface unit 51 (step S7). This response includes, for example, SW "9000" and FCI (File Control Information) in TLV format.

[0032] Next, when the control unit 44 of the ECU 4 receives the response from the eSE 5 via the interface unit 42, the control unit 44 transmits the response to the repeater 3 via the interface unit 41 (step S8). Next, when the repeater 3 receives the response from the ECU 4 (or the eSE 5), the repeater 3 transmits the response to the payment terminal 2 (step S9).

[0033] Next, when the processing unit 23 of the payment terminal 2 receives a response from the repeater 3 via the reader / writer 22, it starts mutual authentication processing with the eSE 5 (step S10). Note that although the example in FIG. 6 shows mutual authentication processing, it may be one-sided authentication processing. When the mutual authentication processing starts, the processing unit 23 of the payment terminal 2 sends an INITALIZE UPDATE command to the repeater 3 via the reader / writer 22 (step S11). Here, the INITALIZE UPDATE command is used to start mutual authentication processing for establishing a secure channel between the payment terminal 2 and the eSE 5. The INITALIZE UPDATE command is a command for notifying the start of the encryption to the eSE 5. The INITALIZE UPDATE command includes a random number and a Key Version Number. The Key Version Number is data used to identify authentication data that is the basis of encryption calculations.

[0034] Next, when the relay 3 receives the INITALIZE UPDATE command from the payment terminal 2, it transmits the INITALIZE UPDATE command to the ECU 4 (or eSE 5) (step S12). Next, when the control unit 44 of the ECU 4 receives the INITALIZE UPDATE command from the relay 3 via the interface unit 41, it transmits the INITALIZE UPDATE command to the eSE 5 via the interface unit 42 (step S13).

[0035] Next, when the CPU 54 of the eSE 5 receives an INITALIZE UPDATE command from the ECU 4 (or the repeater 3) via the interface unit 51, it generates a random number, a session key, and ciphertext A (Card Cryptogram) in response to the INITALIZE UPDATE command (step S14). Here, the session key is an encryption key used in a secure channel, and is generated, for example, based on the random number included in the INITALIZE UPDATE command, the random number generated in step S14, and authentication data stored in the NVM 24. Next, the CPU 54 of the eSE 5 transmits a response including the random number and ciphertext A (Card Cryptogram) generated in step S14 to the ECU 4 (or the repeater 3) via the interface unit 51 (step S15).

[0036] Next, when the control unit 44 of the ECU 4 receives the response from the eSE 5 via the interface unit 42, the control unit 44 transmits the response to the repeater 3 via the interface unit 41 (step S16). Next, when the repeater 3 receives the response from the ECU 4 (or the eSE 5), the repeater 3 transmits the response to the payment terminal 2 (step S17).

[0037] Next, when the processing unit 23 of the payment terminal 2 receives a response from the repeater 3 via the reader / writer 22, it generates a session key and ciphertext A (Card Cryptogram) in the same manner as the eSE 5 according to the authentication processing program (step S18). Next, the processing unit 23 of the payment terminal 2 verifies the legitimacy of the eSE 5 by comparing the ciphertext A (Card Cryptogram) included in the response received from the repeater 3 with the ciphertext A (Card Cryptogram) generated in step S18 (step S19). Next, if the processing unit 23 of the payment terminal 2 successfully verifies the legitimacy of the eSE 5 (i.e., authentication is successful), it generates ciphertext B (Host Cryptogram) (step S20). Next, the processing unit 23 of the payment terminal 2 transmits an EXTERNAL AUTHENTICATE command including the ciphertext B (Host Cryptogram) generated in step S20 to the repeater 3 via the reader / writer 22 (step S21). If the validity verification fails (that is, if authentication fails), error processing is performed.

[0038] Next, when the relay 3 receives the EXTERNAL AUTHENTICATE command from the payment terminal 2, it transmits the EXTERNAL AUTHENTICATE command to the ECU 4 (or eSE 5) (step S22). Next, when the control unit 44 of the ECU 4 receives the EXTERNAL AUTHENTICATE command from the relay 3 via the interface unit 41, it transmits the EXTERNAL AUTHENTICATE command to the eSE 5 via the interface unit 42 (step S23).

[0039] Next, when the CPU 54 of the eSE 5 receives an EXTERNAL AUTHENTICATE command from the ECU 4 (or the repeater 3) via the interface unit 51, it generates ciphertext B (Host Cryptogram) in response to the EXTERNAL AUTHENTICATE command in accordance with the authentication processing program using the same method as the payment terminal 2 (step S24). Next, the CPU 54 of the eSE 5 verifies the legitimacy of the payment terminal 2 by comparing the ciphertext B (Host Cryptogram) included in the EXTERNAL AUTHENTICATE command with the ciphertext B (Host Cryptogram) generated in step S24 (step S25 ... If the validity verification is successful (i.e., authentication is successful), a response indicating the successful authentication is transmitted to the ECU 4 (or the relay 3) via the interface unit 51 (step S26). If the validity verification is unsuccessful (i.e., authentication is unsuccessful), an error process is performed.

[0040] Next, when the control unit 44 of the ECU 4 receives the response from the eSE 5 via the interface unit 42, it transmits the response to the relay 3 via the interface unit 41 (step S27). Next, when the relay 3 receives the response from the ECU 4 (or the eSE 5), it transmits the response to the payment terminal 2 (step S28). Next, when the processing unit 23 of the payment terminal 2 receives the response from the relay 3 via the reader / writer 22, it ends the mutual authentication process with the eSE 5 (step S29). This establishes a secure channel between the payment terminal 2 and the eSE 5.

[0041] Next, in FIG. 7, when a secure session is initiated (step S31), the processing unit 23 of the payment terminal 2 encrypts the GET STATUS command, which indicates a request to obtain the installation status of the application in the ECU 4, with the session key, and transmits the encrypted GET STATUS command (hereinafter referred to as the "encrypted GET STATUS command") to the repeater 3 via the reader / writer 22 (step S32).

[0042] Next, when the relay 3 receives the encrypted GET STATUS command from the payment terminal 2, it transmits the encrypted GET STATUS command to the ECU 4 (or eSE 5) (step S33). Next, when the control unit 44 of the ECU 4 receives the encrypted GET STATUS command from the relay 3 via the interface unit 41, it transmits the encrypted GET STATUS command to the eSE 5 via the interface unit 42 (step S34).

[0043] Next, when the CPU 54 of the eSE 5 receives the encrypted GET STATUS command from the ECU 4 (or the relay 3) via the interface unit 51, it decrypts the encrypted GET STATUS command with the session key and transmits the decrypted GET STATUS command to the ECU 4 via the interface unit 51 (step S35). Next, when the control unit 44 of the ECU 4 receives the GET STATUS command from the eSE 5, it reads out the unique identification number and application list of the ECU 4 from the storage unit 43 in response to the GET STATUS command (step S36). Next, the control unit 44 of the ECU 4 transmits a response including the unique identification number and application list read out in step S36 to the eSE 5 via the interface unit 42 (step S37).

[0044] Next, when the CPU 54 of the eSE 5 receives the response from the ECU 4 via the interface unit 51, it encrypts the response with the session key and transmits the encrypted response (hereinafter referred to as the "encrypted response") to the ECU 4 (or the relay 3) via the interface unit 51 (step S38). Next, when the control unit 44 of the ECU 4 receives the encrypted response from the eSE 5 via the interface unit 42, it transmits the encrypted response to the relay 3 via the interface unit 41 (step S39). Next, when the relay 3 receives the encrypted response from the ECU 4 (or the eSE 5), it transmits the encrypted response to the payment terminal 2 (step S40).

[0045] Next, when processing unit 23 of payment terminal 2 receives the encrypted response from repeater 3 via reader / writer 22, it decrypts the encrypted response and acquires the unique identification number and the application list from the decrypted response (step S41). Next, processing unit 23 of payment terminal 2 determines whether there is an application to be added to ECU 4 based on the unique identification number and the application list acquired in step S41 (step S42).

[0046] In the determination of step S42, if a unique identification number (i.e., a unique identification number of a specific device) that matches the unique identification number acquired in step S41 is stored in storage unit 43, and the identifier of the application associated with that unique identification number (i.e., the application identified by that unique identification number) is not shown (registered) in the application list, it is determined that an application to be added exists. In other words, the application to be added is an application identified by the unique identification number acquired in step S41 but whose identifier is not shown in the application list. If it is determined that an application to be added exists (step S42: YES), the application is identified and the process proceeds to step S43, and if it is determined that the application does not exist (step S42: NO), the process proceeds to step S70.

[0047] In step S43, the processing unit 23 of the payment terminal 2 encrypts the LOAD (APPLICATION LOAD) command that provides the application identified in step S42 with the session key, and transmits the encrypted LOAD command (hereinafter referred to as the "encrypted LOAD command") to the repeater 3 via the reader / writer 22. The LOAD command, also known as the APPLICATION LOAD command, is a command for loading an application, and its data portion includes the application identified in step S42. However, if the size of the application exceeds the amount of data that can be transmitted at one time, the application is divided into multiple blocks (divided data), and each block is transmitted over multiple levels by the LOAD command.

[0048] Next, when the relay device 3 receives the encrypted LOAD command from the payment terminal 2, it transmits the encrypted LOAD command to the ECU 4 (or eSE 5) (step S44). Next, when the control unit 44 of the ECU 4 receives the encrypted LOAD command from the relay device 3 via the interface unit 41, it transmits the encrypted LOAD command to the eSE 5 via the interface unit 42 (step S45).

[0049] Next, when the CPU 54 of the eSE 5 receives an encrypted LOAD command from the ECU 4 (or the relay 3) via the interface unit 51, it decrypts the encrypted LOAD command with the session key and transmits the decrypted LOAD command to the ECU 4 via the interface unit 51 (step S46). Next, when the control unit 44 of the ECU 4 receives the LOAD command from the eSE 5, it acquires an application (payment processing program) from the LOAD command (step S47). The application (or block) is stored in RAM. Next, the control unit 44 of the ECU 4 transmits a response to the LOAD command to the eSE 5 via the interface unit 42 (step S48). Note that when an application is transmitted using multiple LOAD commands, the final response when acquisition of all blocks related to the application has been completed contains SW “9000” indicating normal completion, and the response when acquisition of all blocks has not yet been completed contains SW “91XX”. Here, “XX” indicates the byte length of the next LOAD command.

[0050] Next, when the CPU 54 of the eSE 5 receives the response from the ECU 4 via the interface unit 51, it encrypts the response with the session key and transmits the encrypted response to the ECU 4 (or the relay 3) via the interface unit 51 (step S49). Next, when the control unit 44 of the ECU 4 receives the encrypted response from the eSE 5 via the interface unit 42, it transmits the encrypted response to the relay 3 via the interface unit 41 (step S50). Next, when the relay 3 receives the encrypted response from the ECU 4 (or the eSE 5), it transmits the encrypted response to the payment terminal 2 (step S51).

[0051] Next, when processing unit 23 of payment terminal 2 receives the encrypted response from repeater 3 via reader / writer 22, it decrypts the encrypted response. Next, when transmission of the application is completed (for example, when transmission of all blocks related to the application is completed), processing unit 23 of payment terminal 2 encrypts an INSTALL command for installing the loaded application with the session key, and transmits the encrypted INSTALL command (hereinafter referred to as the "encrypted INSTALL command") to repeater 3 via reader / writer 22, as shown in Fig. 8 (step S52).

[0052] Next, when the repeater 3 receives the encrypted INSTALL command from the payment terminal 2, it transmits the encrypted INSTALL command to the ECU 4 (or eSE 5) (step S53). Next, when the control unit 44 of the ECU 4 receives the encrypted INSTALL command from the repeater 3 via the interface unit 41, it transmits the encrypted INSTALL command to the eSE 5 via the interface unit 42 (step S54).

[0053] Next, when the CPU 54 of the eSE 5 receives the encrypted INSTALL command from the ECU 4 (or the relay 3) via the interface unit 51, it decrypts the encrypted INSTALL command with the session key and transmits the decrypted INSTALL command to the ECU 4 via the interface unit 51 (step S55). Next, when the control unit 44 of the ECU 4 receives the INSTALL command from the eSE 5, it installs the acquired application in response to the INSTALL command (step S56). When the installation of the application is complete, the control unit 44 of the ECU 4 transmits a response indicating successful completion to the eSE 5 via the interface unit 42 (step S57). Note that if the application is not installed successfully, the control unit 44 of the ECU 4 performs rollback processing.

[0054] Next, when the CPU 54 of the eSE 5 receives the response from the ECU 4 via the interface unit 51, it encrypts the response with the session key and transmits the encrypted response to the ECU 4 (or the relay 3) via the interface unit 51 (step S58). Next, when the control unit 44 of the ECU 4 receives the encrypted response from the eSE 5 via the interface unit 42, it transmits the encrypted response to the relay 3 via the interface unit 41 (step S59). Next, when the relay 3 receives the encrypted response from the ECU 4 (or the eSE 5), it transmits the encrypted response to the payment terminal 2 (step S60).

[0055] Next, when processing unit 23 of payment terminal 2 receives the encrypted response from repeater 3 via reader / writer 22, it decrypts the encrypted response. Next, processing unit 23 of payment terminal 2 encrypts a SELECT command for selecting an application (payment processing program) for performing payment processing with the session key, and transmits the encrypted SELECT command to repeater 3 via reader / writer 22 (step S61). The SELECT command includes an identifier (AID) of the application to be selected.

[0056] Next, when the repeater 3 receives the encrypted SELECT command from the payment terminal 2, it transmits the encrypted SELECT command to the ECU 4 (or eSE 5) (step S62). Next, when the control unit 44 of the ECU 4 receives the encrypted SELECT command from the repeater 3 via the interface unit 41, it transmits the encrypted SELECT command to the eSE 5 via the interface unit 42 (step S63).

[0057] Next, when the CPU 54 of the eSE 5 receives the encrypted SELECT command from the ECU 4 (or the relay 3) via the interface unit 51, the CPU 54 decrypts the encrypted SELECT command with the session key and transmits the decrypted SELECT command via the interface unit 51. The control unit 44 of the ECU 4 then transmits a response to the SELECT command to the eSE 5 via the interface unit 42 (step S66).

[0058] Next, when the CPU 54 of the eSE 5 receives the response from the ECU 4 via the interface unit 51, it encrypts the response with the session key and transmits the encrypted response to the ECU 4 (or the relay 3) via the interface unit 51 (step S67). Next, when the control unit 44 of the ECU 4 receives the encrypted response from the eSE 5 via the interface unit 42, it transmits the encrypted response to the relay 3 via the interface unit 41 (step S68). Next, when the relay 3 receives the encrypted response from the ECU 4 (or the eSE 5), it transmits the encrypted response to the payment terminal 2 (step S69).

[0059] Next, when processing unit 23 of payment terminal 2 receives the encrypted response from repeater 3 via reader / writer 22, it decrypts the encrypted response and proceeds to step S70. In step S70, processing unit 23 of payment terminal 2 encrypts a GET DATA command indicating a request to acquire payment data with the session key, and transmits the encrypted GET DATA command to repeater 3 via reader / writer 22.

[0060] Next, when the repeater 3 receives the encrypted GET DATA command from the payment terminal 2, it transmits the encrypted GET DATA command to the ECU 4 (or eSE 5) (step S71). Next, when the control unit 44 of the ECU 4 receives the encrypted GET DATA command from the repeater 3 via the interface unit 41, it transmits the encrypted GET DATA command to the eSE 5 via the interface unit 42 (step S72).

[0061] Next, when the CPU 54 of the eSE 5 receives the encrypted GET DATA command from the ECU 4 (or the repeater 3) via the interface unit 51, it decrypts the encrypted GET DATA command with the session key and transmits the decrypted GET DATA command to the ECU 4 via the interface unit 51 (step S73). Next, when the control unit 44 of the ECU 4 receives the GET DATA command from the eSE 5, it reads out payment data from the storage unit 43 using the selected application (payment processing program) in response to the GET DATA command (step S74). Next, the control unit 44 of the ECU 4 transmits a response including the payment data read out in step S74 to the eSE 5 via the interface unit 42 (step S75).

[0062] Next, when the CPU 54 of the eSE 5 receives the response from the ECU 4 via the interface unit 51, it encrypts the response with the session key and transmits the encrypted response to the ECU 4 (or the relay 3) via the interface unit 51 (step S76). Next, when the control unit 44 of the ECU 4 receives the encrypted response from the eSE 5 via the interface unit 42, it transmits the encrypted response to the relay 3 via the interface unit 41 (step S77). Next, when the relay 3 receives the encrypted response from the ECU 4 (or the eSE 5), it transmits the encrypted response to the payment terminal 2 (step S78).

[0063] Next, when the processing unit 23 of the payment terminal 2 receives the encrypted response from the repeater 3 via the reader / writer 22, it decrypts the encrypted response and executes the payment for the fee payment based on the payment data included in the decrypted response (step S79). For example, the processing unit 23 of the payment terminal 2 executes the payment for the fee payment based on the payment method specified by the payment data. A process is executed to charge (e.g., debit) the parking fee to the user.

[0064] In the above example, the payment terminal 2 is configured to obtain the unique identification number and the application list from the ECU 4 and determine whether there is an application to be added. Alternatively, the ECU 4 may obtain the unique identification number of a specific device and the identifier of a specific application from the payment terminal 2 via the repeater 3 or the like, and determine whether the unique identification number of the specific device matches the unique identification number stored in the memory unit 43 and whether the identifier of the specific application is listed in the application list. If the ECU 4 determines that the two unique identification numbers match and that the identifier of the specific application is listed in the application list, the ECU 4 may obtain the specific application by transmitting a request for the specific application to the payment terminal 2 via the repeater 3.

[0065] Furthermore, although the above example has been described taking the case of adding an application that is not listed in the application list of the ECU 4 as an example, it is also applicable to the case of adding an application that is not listed in the application list of the eSE 5. In this case, the eSE 5 transmits the unique identification number and application list of the eSE 5 to the payment terminal 2. Then, when the payment terminal 2 determines based on the unique identification number and the application list that there is an application that should be added to the eSE 5, it provides the application to the eSE 5 and causes the application to be installed in the eSE 5.

[0066] As described above, according to the above embodiment, an electronic device such as the ECU 4 stores its own unique identification number and application list, and after the authentication process between the payment terminal 2 and the electronic device is completed, an application identified by the stored unique identification number and whose identifier is not shown in the application list is obtained from the payment terminal 2 via the repeater 3, and the obtained application is installed, so that applications can be more efficiently added to the electronic device in the vehicle C. This embodiment is particularly effective in cases where the vehicle C is not equipped with a device capable of connecting to a mobile communication network having a base station for wireless communication, or where the vehicle C is equipped with a device capable of connecting to the mobile communication network but is located in an area where radio waves from the base station cannot reach.

[0067] In the above embodiment, a payment processing program has been described as an example of an application to be added, but the present invention is not limited to this and may include other applications required for using various services. While the ECU 4 has been described as an example of an electronic device of the present invention, the electronic device may also be an electronic device of a passenger in vehicle C. In this case, the electronic device stores a unique identification number specific to the electronic device and a list indicating the identifiers of applications installed on the electronic device. The electronic device then performs the authentication process as described above by communicating with the payment terminal 2 via the repeater 3. After the authentication process is completed, the electronic device acquires, from the payment terminal 2 via the repeater 3, an application identified by the stored unique identification number but whose identifier is not shown in the application list, and installs the acquired application. [Explanation of symbols]

[0068] 1 Management Server 2. Payment terminal 3 Repeater 4 ECU 5 eSE 21 Memory section 22 Reader / Writer 23 Processing section 21 Antenna 41 Interface section 42 Interface section 43 Storage section 44 Control Unit 51 Interface section 52 RAM 53 NVM 54 CPU S Payment Processing System

Claims

1. An electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, a storage means for storing a list indicating the unique identification number of the electronic device and the identifiers of applications installed on the electronic device; an authentication unit that executes an authentication process between the relay device and the external device; an acquisition means for acquiring, after the authentication process is completed, from the external device via the relay device, an application identified by the unique identification number stored in the storage means and whose identifier is not shown in the list; an installation means for installing the application acquired by the acquisition means; Equipped with The electronic device is characterized in that the acquisition means acquires a specific unique identification number and an identifier of a specific application from the external device via the relay device, and if the specific unique identification number matches the unique identification number stored in the memory means and the identifier of the specific application is not shown in the list, the electronic device acquires the application from the external device via the relay device by sending a request for the application to the external device via the relay device.

2. An electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, a storage means for storing a list indicating the unique identification number of the electronic device and the identifiers of applications installed on the electronic device; an authentication unit that executes an authentication process between the relay device and the external device; an acquisition means for acquiring, after the authentication process is completed, from the external device via the relay device, an application identified by the unique identification number stored in the storage means and whose identifier is not shown in the list; an installation means for installing the application acquired by the acquisition means; Equipped with the electronic device is configured by a secure element and an ECU (Electronic Control Unit) mounted on the mobile object, the secure element includes the authentication means and the acquisition means, and the acquisition means acquires the application encrypted with a session key that is generated in the authentication process and is common to the external device, and decrypts the application with the session key; The electronic device is characterized in that the ECU includes the storage means and the installation means, and the installation means installs the decrypted application.

3. The electronic device according to claim 1 or 2, characterized in that the acquisition means acquires the application from the external device via the relay device by transmitting the unique identification number and the list to the external device via the relay device.

4. A terminal device capable of communicating with an electronic device installed in a mobile body or an electronic device carried by a passenger of the mobile body via a relay device mounted on the mobile body, the electronic device stores a unique identification number of the electronic device and a list indicating identifiers of applications installed on the electronic device; The terminal device an authentication unit that performs an authentication process between the electronic device and the relay device; an acquisition means for acquiring the unique identification number and the list from the electronic device via the relay device after the authentication process is completed; a transmitting means for transmitting, via the relay device, an application identified by the unique identification number acquired by the acquiring means and whose identifier is not shown in the list; A terminal device comprising:

5. 1. A method for adding an application executed by an electronic device capable of communicating with an external device installed outside a mobile object via a relay device mounted on the mobile object, the method comprising: storing in a storage means a list indicating the unique identification number of the electronic device and identifiers of applications installed on the electronic device; performing an authentication process between the relay device and the external device via the relay device; an acquisition step of acquiring, after the authentication process is completed, from the external device via the relay device, an application identified by the unique identification number stored in the storage means and whose identifier is not shown in the list; installing the obtained application; Including, In the acquisition step, a specific unique identification number and an identifier of a specific application are acquired from the external device via the relay device, and if the specific unique identification number matches the unique identification number stored in the memory means and the identifier of the specific application is not shown in the list, a request for the application is sent to the external device via the relay device, thereby acquiring the application from the external device via the relay device.

6. A method for adding an application executed by an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, the electronic device being composed of a secure element mounted on the mobile body and an ECU (Electronic Control Unit), a step of the ECU storing in a storage means a list indicating the unique identification number of the electronic device and identifiers of applications installed on the electronic device; a step of performing an authentication process between the secure element and the external device via the relay device; an acquisition step in which the secure element acquires, after the authentication process is completed, from the external device via the relay device, an application identified by the unique identification number stored in the storage means and whose identifier is not shown in the list; an installation step in which the ECU installs the acquired application; Including, In the obtaining step, the application encrypted with a session key generated in the authentication process and shared with the external device is obtained, and the application is decrypted with the session key; In the installing step, the decrypted application is installed.

7. A computer included in an electronic device capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body, a storage means for storing a list indicating the unique identification number of the electronic device and the identifiers of applications installed on the electronic device; an authentication unit that executes an authentication process between the relay device and the external device; an acquisition means for acquiring, after the authentication process is completed, from the external device via the relay device, an application identified by the unique identification number stored in the storage means and whose identifier is not shown in the list; a program that functions as an installation unit that installs the application acquired by the acquisition unit, The acquisition means acquires a specific unique identification number and an identifier of a specific application from the external device via the relay device, and if the specific unique identification number matches the unique identification number stored in the storage means and the identifier of the specific application is not shown in the list, the program acquires the application from the external device via the relay device by sending a request for the application to the external device via the relay device.

8. A computer included in an electronic device that is capable of communicating with an external device installed outside a mobile body via a relay device mounted on the mobile body and that is configured by a secure element mounted on the mobile body and an ECU (Electronic Control Unit), a storage means for storing a list indicating the unique identification number of the electronic device and the identifiers of applications installed on the electronic device; an authentication unit that executes an authentication process between the relay device and the external device; an acquisition means for acquiring, after the authentication process is completed, from the external device via the relay device, an application identified by the unique identification number stored in the storage means and whose identifier is not shown in the list; a program that functions as an installation unit that installs the application acquired by the acquisition unit, the acquisition means acquires the application encrypted with a session key that is generated in the authentication process and is common to the external device, and decrypts the application with the session key; The program is characterized in that the installation means installs the decrypted application.

Citation Information

Patent Citations

  • Correction program confirmation method, correction program confirmation program, and information processing apparatus

    JP2015079440A

  • Program update system, program update method and computer program

    JP2019168977A

  • Mechanism for secure in-vehicle payment transaction

    JP2020053066A

  • Application server device and electronic control device

    JP2020140636A