Access management device, access management system, access management program, and access management method
The access management system addresses the challenge of managing in-vehicle device access by using manifests to control user and application authorities, ensuring secure and authorized access through private and public APIs with validity periods.
Patent Information
- Application Number
- JP2024567741
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-12-28
- Filing Date
- 2023-12-22
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2043-12-22
AI Technical Summary
Existing systems fail to appropriately manage access to in-vehicle devices using application programs, lacking comprehensive control over user and application authorities.
An access management system and device that utilize manifests to manage access permissions for both application programs and users, integrating program and user authorities to control access to in-vehicle devices via private and public APIs, with validity periods for access.
Enables precise and centralized management of access to in-vehicle devices based on application and user permissions, ensuring secure and authorized usage.
Smart Images

Figure 0007772258000001 
Figure 0007772258000002 
Figure 0007772258000003
Abstract
Description
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This international application claims priority based on Japanese Patent Application No. 2022-212240, filed with the Japan Patent Office on December 28, 2022, the entire contents of which are incorporated herein by reference. [Technical Field]
[0002] The present disclosure relates to a technique for managing access to an in-vehicle device using an application program installed in a vehicle. [Background technology]
[0003] When using an application program installed in a vehicle, a technique is known for determining whether a user has access authority.
[0004] For example, in the technology described in Patent Document 1 below, when a vehicle application program that controls vehicle functions is executed, an authentication level and user authority required for execution are specified. A user who is authenticated based on the authentication level and user authority can use the application program.
[0005] The authentication level is expressed in ascending order of security level according to the level of security when authenticating a user, for example, from level 1 to level 3. User authority includes, for example, vehicle owner, family member, guest, service provider, etc.
[0006] For example, to use a certain application program, authentication level 1 is designated as the authentication level and owner or family is designated as the user authority. [Prior art documents] [Patent documents]
[0007] [Patent Document 1] Japanese Patent Application Publication No. 2022-57228 Summary of the Invention
[0008] As a result of detailed investigations by the inventors, it has been found that when an application program is used, it is necessary to appropriately manage access of the application program to the in-vehicle device.
[0009] One aspect of the present disclosure is to provide a technique for appropriately managing access to an in-vehicle device using an application program.
[0010] An in-vehicle access management device according to one embodiment of the present disclosure is an access management device that manages vehicle data obtained from multiple vehicles and communicates with a server that provides vehicle-related services based on the vehicle data, and is equipped with a memory unit and an access management unit.
[0011] The memory unit stores a first manifest that indicates the correspondence between an application program and a program authority for the application program to access an in-vehicle device, and a second manifest that indicates the correspondence between a user and a user authority for the user to access an in-vehicle device using the application program.
[0012] The access management unit manages access to the in-vehicle device by a user using an application program, based on the first manifest and the second manifest stored in the storage unit.
[0013] In addition, an access management system according to another aspect of the present disclosure includes a server that manages vehicle data obtained from multiple vehicles and provides services related to the vehicles based on the vehicle data, and an on-board access management device that communicates with the server.
[0014] The access management device includes a device storage unit, an access management unit, and a first management unit.
[0015] The device memory unit stores a first manifest that indicates the correspondence between an application program and the program authority with which the application program accesses the vehicle-mounted device, and a second manifest that indicates the correspondence between a user and the user authority with which the user accesses the vehicle-mounted device using the application program.
[0016] The access management unit manages access to the in-vehicle device by a user using an application program based on the first manifest and the second manifest stored in the device storage unit. The first management unit manages storage of data received from the server.
[0017] The server includes a communication unit, a server storage unit, and a second management unit.
[0018] The communication unit communicates with the vehicle. The second management unit stores the first manifest and the second manifest in the server storage unit.
[0019] The second management unit transmits the first manifest and the second manifest stored in the server storage unit from the communication unit to the vehicle.
[0020] The first management unit stores the first manifest and the second manifest acquired from the server through communication in the device storage unit.
[0021] An access management program according to another aspect of the present disclosure is an access management program that causes a computer to function as the above-described access management device.
[0022] An access management method according to another aspect of the present disclosure is an access management method using the above-described access management system.
[0023] According to this configuration, access to the in-vehicle device can be appropriately managed based on the first manifest corresponding to the application program and the second manifest corresponding to the user who uses the application program. [Brief explanation of the drawings]
[0024] [Figure 1] FIG. 1 is a block diagram showing the configuration of an access control system. [Figure 2] FIG. 2 is a block diagram showing the configuration of an access management device. [Figure 3] FIG. 10 is another block diagram showing the configuration of the access management device. [Figure 4] FIG. 2 is an explanatory diagram showing the relationship between access rights of an application program, a user, an in-vehicle device, and data. [Figure 5] FIG. 10 is a sequence diagram showing an access management process. [Figure 6] FIG. 10 is a sequence diagram showing another access management process. DETAILED DESCRIPTION OF THE INVENTION
[0025] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.
[0026] [1. Configuration] The access management system 2 shown in Fig. 1 includes a management server 10, a service server 30, and an access management device 60. The access management device 60 is mounted on a vehicle 50. Although three vehicles 50 are illustrated in Fig. 1, the number of vehicles 50 is not limited to three and may be any number. Each vehicle 50 has a common configuration in that it includes an exterior communication device 54, an access management device 60, and an in-vehicle device 100.
[0027] The management server 10 , the service server 30 , and the access management device 60 communicate with each other via a network 4 .
[0028] The management server 10 includes a communication unit 12, a storage unit 14, and a manifest management unit 20. The management server 10 communicates with the service server 30, the access management device 60, and a mobile terminal (not shown) via the communication unit 12. The management server 10 and the service server 30 manage vehicle data acquired from a plurality of vehicles 50, and provide vehicle services related to the vehicles 50 based on the vehicle data. The vehicle data includes, for example, the position and speed of the vehicle 50, and operation data of the vehicle 50 such as the steering wheel, accelerator, and brake.
[0029] A program manifest is stored in the storage unit 14. In the program manifest, application programs that are used by the service user 200 (described later) among the application programs installed in the vehicle 50 are set as application programs. An application program is also abbreviated as an app.
[0030] The apps installed in the vehicle 50 are installed in the access management device 60 and an in-vehicle electronic control device 52 (described later) other than the access management device 60. The apps installed in the vehicle 50 are also called in-vehicle apps.
[0031] The manifest management unit 20 includes a CPU 22, a ROM 24, a RAM 26, etc. Various functions of the manifest management unit 20 are realized by the CPU 22 executing a program stored in a non-transient physical recording medium such as the ROM 24. Furthermore, the execution of this program results in the execution of a method corresponding to the program.
[0032] The manifest management unit 20 manages the program manifest stored in the memory unit 14. The program manifest indicates the correspondence between an app and a program authority, which is the authority for the app to access the in-vehicle device 100 installed in the vehicle 50. The in-vehicle device is also called a device. The manifest management unit 20 provided in the management server 10 is also called a first manifest management unit.
[0033] 4 shows an example of a program manifest that indicates the correspondence between an application and the program authority for the application to access the in-vehicle device 100. In FIG. 4, a circle indicates that the application has the program authority, i.e., the application can access the in-vehicle device 100, and an × indicates that the application does not have the program authority, i.e., the application cannot access the in-vehicle device 100.
[0034] The in-vehicle device 100 is a device related to the vehicle 50, and may include, for example, a WiFi communication device for communicating with the management server 10, a Bluetooth communication device for directly communicating with a mobile device such as a smartphone, a GNSS sensor for detecting the position, a front camera for capturing images outside the vehicle, and an in-vehicle camera for capturing images inside the vehicle. WiFi and Bluetooth are registered trademarks. GNSS is an abbreviation for Global Navigation Satellite System.
[0035] 1, these in-vehicle devices 100 may be built into the access management device 60, or may be controlled by the electronic control device 52 and connected to a bus that enables communication between the access management device 60 and the electronic control device 52. The electronic control device is also called an ECU.
[0036] Note that a mobile terminal such as a smartphone that can communicate with the management server 10 and the vehicle 50 may be regarded as part of the in-vehicle device 100 and may be subject to access management.
[0037] For example, as shown in Fig. 4, the in-vehicle device 100 that a driving diagnosis application can access is different from the in-vehicle device 100 that a drive recorder application can access. In this way, a program manifest with different access permissions specified is set depending on the application.
[0038] When an application is installed in the vehicle 50, the program manifest is acquired from the management server 10 and stored in the storage unit 64 of the access management device 60.
[0039] The apps set in the program manifest may be apps that come standard with the vehicle 50, or apps that are not standardly installed in the vehicle 50 but were developed later and added to the vehicle 50.
[0040] Furthermore, the in-vehicle device 100 set in the program manifest may be one that is installed as standard in the vehicle 50, or one that is not installed as standard in the vehicle 50 but that is added to the vehicle 50 later.
[0041] The in-vehicle devices 100 that the application accesses include those that the application can access via a private API and those that the application can access via a public API. API stands for Application Programming Interface. The access management device 60 provides the application with the private API and the public API.
[0042] An in-vehicle device 100 that is accessed via a private API requires access authority. An in-vehicle device 100 that is accessed via a public API does not require access authority. Whether to access via a private API or a public API is determined for each in-vehicle device 100.
[0043] Alternatively, the method of accessing the in-vehicle device 100 may be changed, for example, so that when the in-vehicle device 100 reads the status of the in-vehicle camera, it accesses via a public API, and when the in-vehicle camera is turned on or images captured by the in-vehicle camera are read, it accesses via a private API.
[0044] When an application accesses the in-vehicle device 100 via a private API that requires access authority, a valid period for access is set. The valid period for access is included in the program manifest and is managed by the management server 10.
[0045] The service server 30 includes a communication unit 32, a storage unit 34, and a manifest management unit 40. The service server 30 communicates with the management server 10, the vehicle 50, and a mobile terminal (not shown) via the communication unit 32.
[0046] The manifest management unit 40 includes a CPU 42, a ROM 44, a RAM 46, etc. The various functions of the manifest management unit 40 are realized by the CPU 42 executing a program stored in a non-transient physical recording medium such as the ROM 44. Furthermore, the execution of this program results in the execution of a method corresponding to the program. The manifest management unit 40 included in the service server 30 is also referred to as a second manifest management unit.
[0047] The manifest management unit 40 manages the user manifest stored in the storage unit 34. The user manifest indicates the correspondence between the ID of the service user 200 who accesses the in-vehicle device 100 using an app and the user authority for the service user 200 to access the in-vehicle device 100.
[0048] 4 is an ID managed by the service server 30 in association with the service user 200. Also, the service user ID shown in FIG. 4 is an ID managed by the management server 10 in association with the user ID.
[0049] The storage unit 34 stores a user manifest.
[0050] As with the program manifest, the in-vehicle device 100 set in the user manifest may be one that is installed as standard in the vehicle 50, or one that is not installed as standard in the vehicle 50 but is added to the vehicle 50 later.
[0051] Fig. 4 shows an example of correspondence between the service user 200 and the user authority for the service user 200 to access the in-vehicle device 100. As shown in Fig. 4, the user authority includes not only the authority to access the in-vehicle device 100 but also authority regarding how to access data, such as whether the service user 200 can save, refer to, or edit data stored in the in-vehicle device 100 that the service user 200 can access.
[0052] The user authority may also include authority regarding data items or data types that indicate which data the service user 200 can access from among the data stored in the in-vehicle device 100 that the service user 200 can access.
[0053] In FIG. 4, a circle indicates that the user has authority, and a cross indicates that the user does not have authority.
[0054] For example, as shown in Fig. 4, the in-vehicle device 100 that can be accessed by an administrator who is a user is different from the in-vehicle device 100 that can be accessed by a guest. In this way, different user manifests are set depending on the user.
[0055] The program manifest and the user manifest may be set as one manifest, as shown in Fig. 4. Alternatively, the program manifest and the user manifest may be set as separate manifests.
[0056] 4, with regard to the user authority of the driving diagnosis app, the in-vehicle device 100 that can be accessed when the user's attribute is an administrator is different from the in-vehicle device 100 that can be accessed when the user's attribute is a guest. With regard to the user authority of the drive recorder app, the in-vehicle device 100 that can be accessed when the user is an administrator is different from the in-vehicle device 100 that can be accessed when the user is a guest.
[0057] The storage unit 34 also stores data other than the above-mentioned user manifest.
[0058] In addition to the above, user rights also include the following rights (1) and (2).
[0059] (1) Among the multiple in-vehicle devices 100 that the application can access, the in-vehicle devices 100 that the user can access.
[0060] (2) The operations permitted for the in-vehicle device 100 include starting and shutting down the in-vehicle device 100, for example.
[0061] The vehicle 50 includes a plurality of ECUs 52 that execute vehicle control, an external communication device 54 that communicates with the outside of the vehicle 50 via a network 4 or the like, an access management device 60, and an in-vehicle device 100. ECU is an abbreviation for Electronic Control Unit.
[0062] The ECU 52 includes one or more microcomputers and executes vehicle control. The external communication device 54 communicates with the outside of the vehicle 50 via the network 4 or the like.
[0063] The access management device 60 manages access by the service user 200 to the in-vehicle device 100 using the in-vehicle application.
[0064] 2, the access management device 60 includes a communication unit 62, a storage unit 64, and a control unit 70. The control unit 70 includes an access management unit 72 and a manifest management unit 74. The access management device 60 communicates with the management server 10 and the service server 30 via the communication unit 62.
[0065] 3, the control unit 70 includes, as its hardware configuration, a CPU 80, a ROM 82, a RAM 84, etc. Various functions of the control unit 70, including the access management unit 72 and the manifest management unit 74, are realized by the CPU 80 executing a program stored in a non-transient tangible recording medium such as the ROM 82. Furthermore, by executing this program, a method corresponding to the program is executed.
[0066] The access management unit 72 manages the service user 200's access to the in-vehicle device 100 using the in-vehicle application based on the program manifest and the user manifest stored in the storage unit 64. The access management unit 72 also manages and provides the private API and public API described above.
[0067] The program manifest stored in the memory unit 64 specifies the correspondence between the in-vehicle applications installed in the access management device 60 and the ECU 52 other than the access management device 60, and the program permissions for the in-vehicle applications to access the in-vehicle device 100.
[0068] That is, in the vehicle 50, the access management device 60 centrally manages access by the service user 200 to the in-vehicle device 100 using the in-vehicle application based on the program manifest and the user manifest.
[0069] The manifest management unit 74 stores the program manifest acquired from the management server 10 and the user manifest acquired from the service server 30 in the storage unit 64 .
[0070] The manifest management unit 74 may receive an integrated manifest that integrates the program manifest and the user manifest from the management server 10, which has acquired the user manifest from the service server 30, and store the integrated manifest in the memory unit 64. The manifest management unit 74 in the access management device 60 provided in the vehicle 50 is also referred to as a third manifest management unit.
[0071] As shown in FIG. 4, the integrated manifest is a manifest in which access rights to the in-vehicle device 100 are set for each application and for each user indicated by a user ID or for each user attribute.
[0072] A user attribute is set for one or more users having the same attribute. The user attribute indicates, for example, the level of access to the in-vehicle device 100. The higher the access level, the more in-vehicle devices 100 the user can access, or the more specific in-vehicle devices 100 the user can access.
[0073] Furthermore, the integrated manifest may be divided for each application and stored in the storage unit 64. For example, a driving diagnosis application has a manifest in which access permissions for the driving diagnosis application are set for each user or each user attribute, and a drive recorder application has a manifest in which access permissions for the drive recorder application are set for each user or each user attribute.
[0074] When apps are installed in the vehicle 50, the manifest management unit 74 stores the manifests of these apps in the storage unit 64. Each app refers to the manifest related to its own app stored in the storage unit 64, and requests access to the in-vehicle device 100 using a private API or a public API based on user attributes.
[0075] The application to be installed in the vehicle 50 is stored in the access management device 60 and another ECU 52 and then installed.
[0076] [2. Processing] Next, the access management process executed by the access management system 2 will be described with reference to the sequence diagrams of Fig. 5 and Fig. 6. The service user 200 shown in Fig. 5 is, for example, a business operator that develops or uses an app, or a driver who is an employee of the business operator and drives the vehicle 50, or the manufacturer of the vehicle 50, or a management company that manages data on the vehicle 50.
[0077] (1) Pre-processing 5 is executed as a pre-processing before the service user 200 uses the app between the management server 10, the service server 30, and the service user 200. The processing by the service user 200 is performed via an information processing terminal such as a smartphone or a PC.
[0078] 5, the service user 200 applies to have the service user 200 registered in the management server 10. For example, the name of a business operator is applied as the service user 200.
[0079] In S2, the manifest management unit 20 of the management server 10 stores and registers the requested business name in the storage unit 14. In S3, the manifest management unit 20 of the management server 10 issues an ID of the service user 200 to the service user 200. If the service user 200 is a business, a business ID is issued.
[0080] In S4, the service user 200 requests that the device ID of the in-vehicle device 100 used in the vehicle 50 be registered in the management server 10 and the service server 30. In S5, the manifest management unit 40 of the service server 30 stores and registers the device ID requested by the service user 200 in the storage unit 34.
[0081] In S6, the manifest management unit 20 of the management server 10 stores and registers the device ID requested by the service user 200 in the storage unit 14. If the in-vehicle device 100 indicated by the device ID registered in the storage unit 14 is accessed via a private API that requires access authority, the manifest management unit 20 of the management server 10 stores and registers in the storage unit 14 the validity period during which the in-vehicle device 100 can be accessed.
[0082] In S7, the service user 200 applies for the application developed by the service user 200 to be registered in the management server 10. In S8, the manifest management unit 20 of the management server 10 stores and registers the application requested by the service user 200 in the storage unit 14. In S9, the manifest management unit 20 of the management server 10 issues to the service user 200 an ID of the application requested by the service user 200.
[0083] In S10, the service user 200 requests that the application ID issued by the management server 10 be registered in the service server 30. In S11, the manifest management unit 40 of the service server 30 stores and registers the application ID requested by the service user 200 in the storage unit 34.
[0084] In S12, the service user 200 requests the management server 10 to register an application ID registered in the management server 10 in association with the device ID of the in-vehicle device 100 used by the application indicated by the application ID.
[0085] In S13, the manifest management unit 20 of the management server 10 associates the application ID and the device ID stored in the storage unit 14, and stores and registers them in the storage unit 14 as a program manifest.
[0086] In S14, the service user 200 requests the service server 30 to register a user ID set for each employee of the business, for example. In S15, the manifest management unit 40 of the service server 30 stores and registers the user ID requested by the service user 200 in the storage unit 34.
[0087] In S16, the service user 200 requests the management server 10 to issue the requested number of service user IDs. In S17, the manifest management unit 20 of the management server 10 issues the requested number of service user IDs to the service user 200.
[0088] In S18, the service user 200 requests the service server 30 to register the correspondence between the user ID and the service user ID. In S19, the manifest management unit 40 of the service server 30 stores and registers the requested correspondence between the user ID and the service user ID in the storage unit 34.
[0089] A service user ID is set corresponding to a user ID and managed by the management server 10. The user ID is managed by the service server 30. In the example shown in Fig. 4, there is a one-to-one correspondence between the user ID and the service user ID, but one service user ID may correspond to multiple user IDs.
[0090] In S20, the service user 200 requests the service server 30 to register a user manifest corresponding to each service user ID set by the service user 200. In S21, the manifest management unit 40 of the service server 30 stores and registers the user manifest for each service user ID in the storage unit 34.
[0091] In S22, the service user 200 requests the service server 30 to register the correspondence between the user ID and the device ID used by the user, based on, for example, a usage plan of which vehicle 50 the service user 200 will board and when.
[0092] In S23, the manifest management unit 40 of the service server 30 stores and registers in the storage unit 34 the correspondence between the requested user ID and the service user ID.
[0093] (2) Processing at the time of use The access management process shown in FIG. 6 is executed among the management server 10, the service server 30, the access management device 60, and the service user 200 when the service user 200 uses an application.
[0094] In S30, the service user 200 starts up the access management device 60, for example, by turning on the start switch of the vehicle 50.
[0095] In S31, the access management unit 72 of the access management device 60 checks with the management server 10 whether there are any apps that have not been installed on the vehicle 50, and if there are any apps that have not been installed, which in-vehicle device 100 the apps use.
[0096] If there is an application that has not been installed on the vehicle 50, the manifest management unit 20 of the management server 10 transmits the application that has not been installed and a program manifest corresponding to the application to the vehicle 50 in S32.
[0097] The program manifest sets a validity period during which the in-vehicle device 100 can be accessed when the in-vehicle device 100 is accessed via a private API that requires access authority. The program manifest is transmitted to the vehicle 50 prior to or simultaneously with the installation of the app.
[0098] In S33, the manifest management unit 74 of the access management device 60 stores and registers the application received from the management server 10 in the storage unit 64 or in another storage unit (not shown) of the ECU 52 other than the storage unit 64.
[0099] Furthermore, in S33, the manifest management unit 74 of the access management device 60 stores and registers the program manifest received from the management server 10 in the storage unit 64. The aforementioned validity period is set in the program manifest.
[0100] In S34, the access management unit 72 of the access management device 60 starts the app managed by the access management unit 72. If the program manifest has not been stored correctly, the access management unit 72 does not start the app, or, even if the app is started, prohibits access by the app to all of the in-vehicle devices 100.
[0101] In S35, the service user 200 notifies the service server 30 using a mobile terminal or the like that he or she will log in with a user ID.
[0102] In S36, the service user 200 requests the access management device 60 to log in using a user ID on a mobile terminal or the like. In S37 and S38, the access management unit 72 of the access management device 60 notifies the management server 10 and the service server 30 of the user ID and the device ID used with the user ID as user information for logging in, and requests the log in. The access management unit 72 may request the management server 10 to log in, and the management server 10 may request the service server 30 to log in.
[0103] When a login request is received from the vehicle 50, the service server 30 reads out the service user ID corresponding to the user ID and the user manifest corresponding to the service user ID from the storage unit 34. Then, in S39 and S40, the service server 30 transmits the service user ID and the corresponding user manifest to the management server 10 and the vehicle 50. The user manifest is transmitted to the vehicle 50 in response to the login request from the vehicle 50.
[0104] The service server 30 may transmit the service user ID and a user manifest corresponding to the service user ID to the management server 10, and the management server 10 may transmit them to the vehicle 50. The user manifest may specify access authority to the in-vehicle device 100 for the service user ID. The user manifest may also specify attributes for the service user ID and access authority to the in-vehicle device 100 for the attributes.
[0105] In S41, the manifest management unit 74 of the access management device 60 stores the service user ID and the user manifest received from the service server 30 in the storage unit 64.
[0106] In S42, the access management unit 72 manages access to the in-vehicle device 100 by the service user 200 using the application, based on the program manifest and the user manifest stored in the storage unit 64.
[0107] In S43 and S44, the access management device 60 transmits the service user ID, the device ID used by the service user 200 indicated by the service user ID, and the vehicle data obtained from the vehicle-mounted device 100 indicated by the device ID to the management server 10 and the service server 30.
[0108] In the embodiment described above, the management server 10 and the service server 30 correspond to the servers, the communication unit 12 corresponds to the first communication unit, and the communication unit 32 corresponds to the second communication unit.
[0109] Furthermore, manifest management units 20 and 40 correspond to the second management unit, manifest management unit 20 corresponds to the third management unit, manifest management unit 40 corresponds to the fourth management unit, and storage units 14 and 34 correspond to the server storage units. Storage unit 14 corresponds to the first server storage unit, storage unit 34 corresponds to the second server storage unit, and storage unit 64 corresponds to the device storage unit. Furthermore, manifest management unit 74 corresponds to the first management unit.
[0110] Furthermore, the program manifest corresponds to the first manifest, the user manifest corresponds to the second manifest, the private API corresponds to the first API, and the public API corresponds to the second API.
[0111] In addition, S13 corresponds to processing by the third management unit of the management server, S21 corresponds to processing by the fourth management unit of the service server, S33 and S41 correspond to processing by the manifest management unit of the access management device, and S42 corresponds to processing by the access management unit of the access management device.
[0112] [3.Effects] According to the embodiment described above, the following effects can be obtained.
[0113] (3a) Applicable access to the in-vehicle device 100 can be appropriately managed based on the program manifest and the user manifest.
[0114] (3b) A program manifest and a user manifest are set for an added application and an in-vehicle device 100 in addition to the application and the in-vehicle device 100 that are installed as standard in the vehicle 50. Therefore, for the added application and the in-vehicle device 100, access of the application to the in-vehicle device 100 can be appropriately managed based on the program manifest and the user manifest.
[0115] 4. Other Embodiments Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the above-described embodiments and can be implemented in various modified forms.
[0116] (4a) In the above-described embodiment, the access management device 60 stores the apps used by the service user 200 in the memory unit 64 of the access management device 60, but the apps may also be stored in a memory unit (not shown) of the ECU 52 other than the memory unit 64.
[0117] (4b) In the above-described embodiment, two servers, the management server 10 and the service server 30, are set as servers, but the functions of the management server 10 and the service server 30 may be combined into one server.
[0118] (4c) In the above-described embodiment, the in-vehicle applications for which the access management device 60 manages access to the in-vehicle device 100 are applications installed in the access management device 60 and the ECU 52 other than the access management device 60.
[0119] Without being limited to this, the in-vehicle application for which the access management device 60 manages access to the in-vehicle device 100 may be an application installed in at least one of the access management device 60 and an ECU 52 other than the access management device 60.
[0120] In this case, the program manifest only needs to define the correspondence between the in-vehicle applications for which the access management device 60 manages access to the in-vehicle device 100 and the program authority for the applications to access the in-vehicle device.
[0121] (4d) The access control apparatus 60 and the techniques described in this disclosure may be implemented by a special purpose computer provided by configuring a processor and memory programmed to perform one or more functions embodied in a computer program.
[0122] Alternatively, the access management device 60 and the methods described in this disclosure may be implemented by a special purpose computer provided by configuring a processor with one or more dedicated hardware logic circuits.
[0123] Alternatively, the access management device 60 and the techniques described in this disclosure may be implemented by one or more special-purpose computers configured by a processor and memory programmed to perform one or more functions in combination with a processor configured by one or more hardware logic circuits.
[0124] The computer program may be stored as instructions executed by a computer on a non-transitory computer-readable storage medium. The method for realizing the functions of each unit included in the access management device 60 does not necessarily need to include software, and all of the functions may be realized using one or more pieces of hardware.
[0125] (4e) Multiple functions possessed by one component in the above-described embodiments may be realized by multiple components, or one function possessed by one component may be realized by multiple components. Also, multiple functions possessed by multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Also, part of the configuration of the above-described embodiments may be omitted. Also, at least part of the configuration of the above-described embodiments may be added to or substituted for the configuration of another of the above-described embodiments.
[0126] (4f) In addition to the access management device 60 described above, the present disclosure can also be realized in various forms, such as an access management system 2 having the access management device 60 as a component, an access management program for causing a computer to function as the access management device 60, a non-transient physical recording medium such as a semiconductor memory on which this program is recorded, and an access management method using the access management system 2 or the access management device 60. [Technical idea disclosed in this specification] [Item 1] An in-vehicle access management device (60) that manages vehicle data acquired from a plurality of vehicles (50) and communicates with a server (10, 30) that provides services related to the vehicles based on the vehicle data, a storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access an in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the storage unit; An access control device comprising:
[0127] [Item 2] Item 1, an access management device according to the present invention, The user authority indicates at least one of the in-vehicle devices that the user can access among the in-vehicle devices that the application program can access, the data that the user can access among the data related to the in-vehicle devices, and the operations that the user is permitted to perform on the in-vehicle devices that the user can access. Access control devices.
[0128] [Item 3] Item 1 or 2, an access management device, a manifest management unit (74, S33) configured to, when acquiring the application program from the server via communication, acquire the first manifest corresponding to the application program from the server via communication and store the first manifest in the storage unit; The access control device further comprises:
[0129] [Item 4] 4. The access management device according to any one of items 1 to 3, a manifest management unit (74, S41) configured to store the second manifest acquired from the server through communication in the storage unit based on the user information; The access control device further comprises:
[0130] [Item 5] 5. The access management device according to any one of items 1 to 4, the access management unit is configured to provide, when accessing the in-vehicle device, a first API that requires access authority to the in-vehicle device and a second API that does not require the access authority to the in-vehicle device. Access control devices.
[0131] [Item 6] Item 5. The access management device according to item 5, the access management unit is configured to, when the user uses the application program to access the in-vehicle device for which the access authority is required, acquire a validity period of the access authority from the server through communication, and permit the user to access the in-vehicle device for which the access authority is required using the application program during the acquired validity period. Access control devices.
[0132] [Item 7] 7. The access management device according to any one of items 1 to 6, The first manifest specifies a correspondence between the application programs installed in the access management device and an in-vehicle electronic control device other than the access management device, and the program authority for the application programs to access the in-vehicle device. Access control devices.
[0133] [Item 8] a server (10, 30) that manages vehicle data acquired from a plurality of vehicles (50) and provides services related to the vehicles based on the vehicle data; an access control device (60) mounted on the vehicle that communicates with the server; An access control system (2) comprising: The access management device a device storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the device storage unit; a first management unit (74, S33, 341) configured to manage the storage of data received from the server; Equipped with The server a communication unit (12, 32) configured to communicate with the vehicle; A server storage unit (14, 34); a second management unit (20, 40, S13, S21) configured to store the first manifest and the second manifest in the server storage unit; Equipped with the second management unit is configured to transmit the first manifest and the second manifest stored in the server storage unit from the communication unit to the vehicle, the first management unit is configured to store the first manifest and the second manifest acquired from the server through communication in the device storage unit; Access control system.
[0134] [Item 9] Item 8. An access control system according to item 8, the second management unit is configured to transmit the first manifest stored in the server storage unit in association with the application program to the vehicle when transmitting the application program from the communication unit to the vehicle, the second management unit is configured, when acquiring the application program from the server through communication, to acquire the first manifest corresponding to the application program from the server through communication and store the first manifest in the device storage unit. Access control system.
[0135] [Item 10] 10. The access control system according to item 8 or 9, The server The system comprises a management server (10) and a service server (30), The management server The communication unit includes a first communication unit (12) that communicates with the vehicle; a first server storage unit (14) configured to store the first manifest in the server storage unit; a third management unit (20, S13) of the second management unit configured to store the first manifest in the first server storage unit; Equipped with The service server The communication unit includes a second communication unit (32) that communicates with the vehicle; a second server storage unit (34) configured to store the second manifest in the server storage unit; a fourth management unit (40, S21) of the second management unit configured to store the second manifest in the second server storage unit; Equipped with the third management unit is configured to transmit the first manifest stored in the first server storage unit from the first communication unit to the vehicle; the fourth management unit is configured to transmit the second manifest stored in the second server storage unit from the second communication unit to the vehicle, the first management unit is configured to store the first manifest acquired from the management server through communication in the device storage unit, and to store the second manifest acquired from the service server through communication in the device storage unit. Access control system.
[0136] [Item 11] An access management program installed in an in-vehicle access management device (60) that manages vehicle data acquired from a plurality of vehicles (50) and causes a computer to function to communicate with a server (10, 30) that provides services related to the vehicles based on the vehicle data, comprising: a storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access an in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the storage unit; An access control program that allows a computer to function as a
[0137] [Item 12] a server (10, 30) that manages vehicle data acquired from a plurality of vehicles (50) and provides services related to the vehicles based on the vehicle data; an access control device (60) mounted on the vehicle that communicates with the server; An access management method by an access management system comprising: the server stores a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; transmitting the stored first manifest and the stored second manifest to the vehicle; The access management device acquiring the first manifest and the second manifest from the server through communication and storing them; managing access by the user to the in-vehicle device using the application program based on the stored first manifest and second manifest; Access control methods.
Claims
1. An in-vehicle access management device (60) that manages vehicle data acquired from a plurality of vehicles (50) and communicates with a server (10, 30) that provides services related to the vehicles based on the vehicle data, a storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access an in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the storage unit; a manifest management unit (74, S33, S41) configured to store at least one of the first manifest and the second manifest acquired from the server through communication in the device storage unit; An access control device comprising:
2. 2. The access management device according to claim 1, The user authority indicates at least one of the in-vehicle devices that the user can access among the in-vehicle devices that the application program can access, the data that the user can access among the data related to the in-vehicle devices, and the operations that the user is permitted to perform on the in-vehicle devices that the user can access. Access control devices.
3. 2. The access management device according to claim 1, the manifest management unit is configured, when acquiring the application program from the server through communication, to acquire the first manifest corresponding to the application program from the server through communication and store the first manifest in the storage unit; Access control devices.
4. 2. The access management device according to claim 1, the manifest management unit is configured to store the second manifest acquired from the server through communication in the storage unit based on the information of the user. Access control devices.
5. An in-vehicle access management device (60) that manages vehicle data acquired from a plurality of vehicles (50) and communicates with a server (10, 30) that provides services related to the vehicles based on the vehicle data, a storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access an in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the storage unit; Equipped with the access management unit is configured to, when the user uses the application program to access the in-vehicle device requiring access authority, acquire a validity period of the access authority from the server through communication, and permit the user to access the in-vehicle device requiring access authority using the application program during the acquired validity period. Access control devices.
6. 6. The access management device according to claim 5, the access management unit is configured to provide, when accessing the in-vehicle device, a first API that requires the access authority to the in-vehicle device and a second API that does not require the access authority to the in-vehicle device. Access control devices.
7. An in-vehicle access management device (60) that manages vehicle data acquired from a plurality of vehicles (50) and communicates with a server (10, 30) that provides services related to the vehicles based on the vehicle data, a storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access an in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the storage unit; Equipped with The first manifest specifies a correspondence between the application programs installed in the access management device and an in-vehicle electronic control device (52) other than the access management device, and the program authority for the application programs to access the in-vehicle devices. Access control devices.
8. a server (10, 30) that manages vehicle data acquired from a plurality of vehicles (50) and provides services related to the vehicles based on the vehicle data; an access control device (60) mounted on the vehicle that communicates with the server; An access control system (2) comprising: The access management device a device storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the device storage unit; a first management unit (74, S33, 341) configured to manage storage of data received from the server; Equipped with The server a communication unit (12, 32) configured to communicate with the vehicle; A server storage unit (14, 34); a second management unit (20, 40, S13, S21) configured to store the first manifest and the second manifest in the server storage unit; Equipped with the second management unit is configured to transmit the first manifest and the second manifest stored in the server storage unit from the communication unit to the vehicle, the first management unit is configured to store the first manifest and the second manifest acquired from the server through communication in the device storage unit; Access control system.
9. 9. The access control system of claim 8, the second management unit is configured to transmit the first manifest stored in the server storage unit in association with the application program to the vehicle when transmitting the application program from the communication unit to the vehicle, the first management unit is configured, when acquiring the application program from the server through communication, to acquire the first manifest corresponding to the application program from the server through communication and store the first manifest in the device storage unit; Access control system.
10. 10. The access control system according to claim 8 or 9, The server The system comprises a management server (10) and a service server (30), The management server As the communication unit, a first communication unit (12) that communicates with the vehicle; a first server storage unit (14) configured to store the first manifest in the server storage unit; a third management unit (20, S13) of the second management unit configured to store the first manifest in the first server storage unit; Equipped with The service server As the communication unit, a second communication unit (32) that communicates with the vehicle; a second server storage unit (34) configured to store the second manifest in the server storage unit; a fourth management unit (40, S21) of the second management unit configured to store the second manifest in the second server storage unit; Equipped with the third management unit is configured to transmit the first manifest stored in the first server storage unit from the first communication unit to the vehicle; the fourth management unit is configured to transmit the second manifest stored in the second server storage unit from the second communication unit to the vehicle, the first management unit is configured to store the first manifest acquired from the management server through communication in the device storage unit, and to store the second manifest acquired from the service server through communication in the device storage unit; Access control system.
11. An access management program installed in an in-vehicle access management device (60) that manages vehicle data acquired from a plurality of vehicles (50) and causes a computer to function to communicate with a server (10, 30) that provides services related to the vehicles based on the vehicle data, comprising: a storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the storage unit; a manifest management unit (74, S33, S41) configured to store at least one of the first manifest and the second manifest acquired from the server through communication in the device storage unit; An access control program that allows a computer to function as a
12. a server (10, 30) that manages vehicle data acquired from a plurality of vehicles (50) and provides services related to the vehicles based on the vehicle data; an access control device (60) mounted on the vehicle that communicates with the server; An access management method by an access management system comprising: the server stores a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; transmitting the stored first manifest and the stored second manifest to the vehicle; The access management device acquiring the first manifest and the second manifest from the server through communication and storing them; managing access by the user to the in-vehicle device using the application program based on the stored first manifest and second manifest; Access control methods.
Citation Information
Patent Citations
On-vehicle gateway device, accumulation control method, and program
JP2017174111A
Authentication management method, authentication management program and user authentication management device
JP2022057228A
Computer, method for controlling access to compute resource, and access control program
WO2006114878A1