Vehicle communication control system and vehicle communication control method
The vehicle communication control system facilitates decryption of encrypted vehicle information for aftermarket devices by using a relay device and external communication to provide decryption keys, addressing the challenge of inferior functionality and maintaining key confidentiality.
Patent Information
- Application Number
- JP2022076889
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-05-09
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2042-05-09
AI Technical Summary
Existing vehicle communication systems face challenges in enabling aftermarket devices to decrypt encrypted vehicle information without disclosing decryption keys to third-party manufacturers, leading to inferior functionality compared to genuine products.
A vehicle communication control system and method that utilizes an onboard device, a relay device, and an external communication device to perform a predetermined process based on device identification information, allowing the relay device to transmit a decryption key to the onboard device for decrypting encrypted vehicle information without pre-setting the decryption key in the onboard device.
Enables aftermarket devices to decrypt encrypted vehicle information, ensuring equivalent functionality with genuine products, while maintaining confidentiality of decryption keys and allowing retrofitting of devices post-sale.
Smart Images

Figure 0007794685000001 
Figure 0007794685000002
Abstract
Description
[Technical Field]
[0001] The present invention relates to a vehicle communication control system and a vehicle communication control method that utilizes an external device (external communication device) such as a data center. [Background technology]
[0002] BACKGROUND ART Conventionally, there is a vehicle communication control system that performs communication between a communication device mounted on a vehicle and a data center (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2019-144655 Summary of the Invention [Problem to be solved by the invention]
[0004] Vehicles are equipped with an in-vehicle local area network (LAN) including a controller area network (CAN). In the in-vehicle LAN, information and communication devices such as a display audio (D / A) and a navigation system, as well as an electronic control unit (ECU), are each connected to a gateway, and the information and communication devices communicate with the ECU via the gateway. In this case, to protect vehicle information (e.g., vehicle speed, intake air volume, etc.), when the ECU transmits vehicle information to the information and communication devices via the gateway, the gateway may encrypt the vehicle information using an encryption key and transmit the encrypted vehicle information (hereinafter, appropriately referred to as "encrypted vehicle information") to the information and communication devices. The information and communication devices may then decrypt the encrypted vehicle information using a decryption key corresponding to the encryption key used by the gateway to obtain the vehicle information. In this case, the decryption key corresponding to the encryption key used by the gateway must be pre-set in the information and communication devices.
[0005] Information and communication devices such as display audio (D / A) and navigation systems include genuine information and communication devices developed by vehicle manufacturers who disclose to parts manufacturers the decryption key that corresponds to the encryption key used by the gateway when encrypting vehicle information, as well as information and communication devices (third-party products (aftermarket products)) that users add to their vehicles after the sale, and many users choose to add aftermarket products.As a result, there is a growing need to minimize the impact of differences between information and communication devices (genuine products, aftermarket products, etc.) and achieve equivalent functionality in vehicles.
[0006] However, since it is possible to preset a decryption key corresponding to the encryption key used by the gateway when encrypting vehicle information in genuine products, the genuine products can, for example, decrypt encrypted vehicle information encrypted by the gateway using the encryption key to obtain the vehicle information. On the other hand, since there is a desire to minimize the provision of highly confidential vehicle information to third-party product manufacturers that develop third-party products and not disclose the decryption key for the encryption key to the third-party manufacturers, it may not be possible to preset a decryption key corresponding to the encryption key used by the gateway when encrypting the vehicle information in genuine products. Therefore, the third-party products cannot decrypt encrypted vehicle information encrypted by the gateway using the encryption key, for example, and cannot obtain the vehicle information, resulting in inferior functionality compared to genuine products.
[0007] The object of the present invention is to provide a vehicle communication control system and a vehicle communication control method that enable an on-board device installed in a vehicle to decrypt encrypted vehicle information encrypted by a relay device using an encryption key and obtain vehicle information, even if a decryption key corresponding to the encryption key used by the relay device to encrypt the vehicle information is not disclosed. [Means for solving the problem]
[0008] In order to achieve the above-mentioned object, the vehicle communication control system of the present invention is a vehicle communication control system comprising an onboard device mounted on a vehicle, a relay device mounted on the vehicle and communicatively connected to the onboard device, and an onboard communication device mounted on the vehicle and communicatively connected to the relay device, and capable of communicating with an exterior communication device installed outside the vehicle, wherein the onboard device transmits onboard device identification information for identifying the onboard device to the exterior communication device via the relay device and the onboard communication device, the relay device receives the result of a predetermined processing performed by the exterior communication device based on the onboard device identification information from the exterior communication device via the onboard communication device, the relay device transmits a decryption key corresponding to an encryption key used to encrypt the vehicle information to be relayed to the onboard device based on the result of the predetermined processing, the relay device encrypts the vehicle information to be relayed using the encryption key and relays the encrypted vehicle information to the onboard device, and the onboard device decrypts the encrypted vehicle information from the relay device using the decryption key received from the relay device.
[0009] According to this configuration, the exterior communication device performs a predetermined process based on the in-vehicle device identification information and transmits the results of the predetermined process to the relay device via the in-vehicle communication device. The relay device then transmits a decryption key corresponding to the encryption key used to encrypt the relayed vehicle information to the in-vehicle device based on the results of the predetermined process. Therefore, by performing a predetermined process by the exterior communication device to determine whether the in-vehicle device is capable of acquiring vehicle information, the in-vehicle device can decrypt the encrypted vehicle information, which was encrypted using the encryption key sent from the relay device, using the decryption key corresponding to the encryption key, and acquire the vehicle information, without disclosing information about the decryption key corresponding to the encryption key to the manufacturer of the in-vehicle device or without presetting the encryption key in the relay device or the decryption key in the in-vehicle device. Furthermore, by performing a predetermined process by the exterior communication device to determine whether the in-vehicle device is capable of acquiring vehicle information, the in-vehicle device can acquire vehicle information from a device connected to the relay device, even if the in-vehicle device is developed after the vehicle has been sold or after the vehicle's development has been completed.
[0010] The in-vehicle device may be capable of being retrofitted to the vehicle.
[0011] According to this configuration, even if the on-board device is retrofitted to the vehicle, the on-board device can obtain the vehicle information by decrypting the encrypted vehicle information, which has been encrypted using an encryption key sent from the relay device, using a decryption key corresponding to the encryption key.
[0012] Further, a vehicle communication control method according to the present invention is a vehicle communication control method carried out in a vehicle communication control system including an on-board device mounted on a vehicle, a relay device mounted on the vehicle and communicably connected to the on-board device, and an on-board communication device mounted on the vehicle and communicably connected to the relay device and capable of communicating with an exterior communication device installed outside the vehicle, wherein the on-board device transmits on-board device identification information for identifying the on-board device to the exterior communication device via the relay device and the on-board communication device, and the relay device transmits on-board device identification information for identifying the on-board device to the exterior communication device via the relay device and the on-board communication device, and The relay device receives a result of a predetermined process based on the vehicle-mounted device identification information from the exterior communication device via the vehicle-mounted communication device, and based on the result of the predetermined process, the relay device transmits a decryption key corresponding to an encryption key used to encrypt the vehicle information to be relayed to the vehicle-mounted device, the relay device encrypts the vehicle information to be relayed using the encryption key and relays the encrypted vehicle information to the vehicle-mounted device, and the vehicle-mounted device decrypts the encrypted vehicle information from the relay device using the decryption key received from the relay device.
[0013] According to this configuration, the exterior communication device performs a predetermined process based on the in-vehicle device identification information and transmits the results of the predetermined process to the relay device via the in-vehicle communication device. The relay device then transmits a decryption key corresponding to the encryption key used to encrypt the relayed vehicle information to the in-vehicle device based on the results of the predetermined process. Therefore, by performing a predetermined process by the exterior communication device to determine whether the in-vehicle device is capable of acquiring vehicle information, the in-vehicle device can decrypt the encrypted vehicle information, which was encrypted using the encryption key sent from the relay device, using the decryption key corresponding to the encryption key, and acquire the vehicle information, without disclosing information about the decryption key corresponding to the encryption key to the manufacturer of the in-vehicle device or without presetting the encryption key in the relay device or the decryption key in the in-vehicle device. Furthermore, by performing a predetermined process by the exterior communication device to determine whether the in-vehicle device is capable of acquiring vehicle information, the in-vehicle device can acquire vehicle information from a device connected to the relay device, even if the in-vehicle device is developed after the vehicle has been sold or after the vehicle's development has been completed. [Effects of the Invention]
[0014] According to the present invention, the exterior communication device performs a predetermined process based on the in-vehicle device identification information and transmits the result of the predetermined process to the relay device via the in-vehicle communication device. The relay device then transmits a decryption key corresponding to the encryption key used to encrypt the relayed vehicle information to the in-vehicle device based on the result of the predetermined process. Therefore, by performing the predetermined process by the exterior communication device regarding whether the in-vehicle device is capable of acquiring vehicle information, the in-vehicle device can decrypt the encrypted vehicle information, which was encrypted using the encryption key sent from the relay device, using the decryption key corresponding to the encryption key, and acquire the vehicle information, without disclosing information about the decryption key corresponding to the encryption key to the manufacturer of the in-vehicle device and without presetting the encryption key in the relay device or the decryption key in the in-vehicle device in memory. Furthermore, by performing the predetermined process by the exterior communication device regarding whether the in-vehicle device is capable of acquiring vehicle information, the in-vehicle device can acquire vehicle information from a device connected to the relay device, even if the in-vehicle device is developed after the vehicle has been sold or after the vehicle's development has been completed. [Brief explanation of the drawings]
[0015] [Figure 1] 1 is a system configuration diagram showing the configuration of a vehicle communication control system according to an embodiment of the present invention; [Figure 2] 2 is a sequence diagram showing a communication sequence performed in the vehicle communication control system of FIG. 1, in which an information communication device acquires information from an ECU. DETAILED DESCRIPTION OF THE INVENTION
[0016] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings.
[0017] 1. System configuration of vehicle communication control system The system configuration of a vehicle communication control system S according to one embodiment of the present invention will be described with reference to FIG.
[0018] An in-vehicle LAN including a CAN and the like is configured in a vehicle M. The vehicle communication control system S shown in FIG. 1 is a system mounted on the vehicle M, and includes a gateway 1, an in-vehicle communication device 2, an ECU 3, and an information communication device 4, which are included in the in-vehicle LAN including a CAN and the like. In this embodiment, the information communication device 4 is an aftermarket product, as will be described later, and the information communication device 4 and the gateway 1 are connected by an information bus B that connects the aftermarket products. Also, the data center 5 shown in FIG. 1 is a device installed outside the vehicle M, and is capable of communicating with the in-vehicle communication device 2 included in the vehicle communication control system S, for example, via wireless communication. Note that the gateway 1 corresponds to the "relay device" of the present invention, the in-vehicle communication device 2 corresponds to the "in-vehicle communication device" of the present invention, the information communication device 4 corresponds to the "in-vehicle device" of the present invention, and the data center 5 corresponds to the "external vehicle communication device" of the present invention.
[0019] The gateway 1 has a function of relaying communications between networks with different communication protocols. In this embodiment, the gateway 1 is connected to an in-vehicle communication device 2, an ECU 3, and an information communication device 4. In this embodiment, the gateway 1 encrypts the vehicle information transmitted from the ECU 3 using an encryption key, and outputs the encrypted vehicle information (encrypted vehicle information) to the information bus B to transmit it to the information communication device 4.
[0020] The gateway 1 also receives a vehicle information list, which will be described later, from the data center 5 via the in-vehicle communication device 2. The gateway 1 then checks whether the vehicle information list includes the vehicle information transmitted from the ECU 3, and if it checks that the vehicle information list includes the vehicle information transmitted from the ECU 3, it outputs a decryption key corresponding to the encryption key used to encrypt the vehicle information transmitted from the ECU 3 to the information bus B and transmits it to the information communication device 4.
[0021] The in-vehicle communication device 2 is constructed, for example, using a DCM (Data Communication Module), which is a communication device dedicated to the vehicle, and is connected to the gateway 1 and communicates with a data center 5 installed outside the vehicle M.
[0022] The ECU 3 is, for example, a body ECU, a VSC (Vehicle Stability Control) ECU, a meter ECU, a stereo camera ECU, or an EFI (Electronic Fuel Injection) ECU, and is connected to the gateway 1. In this embodiment, the ECU 3 transmits vehicle information to the gateway 1 during periodic processing performed at a predetermined cycle (for example, every 10 ms). The vehicle information transmitted by the ECU 3 during periodic processing is encrypted by the gateway 1 using an encryption key, and the encrypted vehicle information is output to the information bus B and transmitted to the information communication device 4. Therefore, in order for the information communication device 4 to obtain the vehicle information transmitted by the ECU 3 during periodic processing, the gateway 1 needs a decryption key corresponding to the encryption key used to encrypt the vehicle information. The body ECU, VSC ECU, meter ECU, stereo camera ECU, and EFI ECU are common devices, and detailed description thereof will be omitted.
[0023] The information communication device 4 is, for example, an in-vehicle device such as a display audio (D / A) or a navigation system, and is connected to the gateway 1. The information communication device 4 in this embodiment is an aftermarket device (an aftermarket product) that is attached by a user to the vehicle M after it has been sold.
[0024] At the time when the information communication device 4 is retrofitted to the vehicle M, the information communication device 4 is not set with a decryption key corresponding to the encryption key used to encrypt the vehicle information that is transmitted by the ECU 3 and received by the gateway 1 during periodic processing. Therefore, at the time when the information communication device 4 is retrofitted to the vehicle M, the information communication device 4 is unable to decrypt the vehicle information that is transmitted by the ECU 3 and encrypted by the gateway 1 using the encryption key during periodic processing (encrypted vehicle information), and is therefore unable to obtain the vehicle information.
[0025] In this embodiment, the following processing is performed so that the information communication device 4 can decrypt the vehicle information (encrypted vehicle information) sent by the ECU 3 during periodic processing and encrypted by the gateway 1 using an encryption key.
[0026] After the information communication device 4 is retrofitted to the vehicle M, when the information communication device 4 detects, for example, an operation of a pairing switch (an operation requesting the data center 5 to perform a match using a database related to the information communication device 4 and the vehicle M), the information communication device 4 transmits a pairing request (a request for authentication from the data center 5) and an information communication device ID to the data center 5 via the gateway 1 and the in-vehicle communication device 2. When the pairing request and the information communication device ID are transmitted from the information communication device 4 to the data center 5 via the gateway 1 and the in-vehicle communication device 2, the in-vehicle communication device 2 transmits the vehicle ID to the data center 5. As a result, the data center 5 receives the pairing request, the information communication device ID, and the vehicle ID. Here, the information communication device ID is an ID for identifying the information communication device 4 and corresponds to the "in-vehicle device identification information" of the present invention. The vehicle ID is the VIN (Vehicle Identification Number) of the vehicle M.
[0027] Although the information communication device 4 is supposed to send a pairing request and an information communication device ID to the data center 5 based on the detection of the operation of the pairing switch, this is not limited to this, and for example, the information communication device 4 may send a pairing request and an information communication device ID to the data center 5 based on the failure to decrypt encrypted vehicle information.
[0028] As will be described later, the data center 5 stores a database in a memory (not shown) provided in the data center 5, in which vehicle IDs, information communication device IDs, and a vehicle information list (a list of vehicle information that is permitted to be disclosed to information communication devices of the information communication device ID installed in the vehicle of the vehicle ID) are associated with each other. When the data center 5 receives a pairing request, an information communication device ID, and a vehicle ID, the data center 5 reads out the vehicle information list that associates the received information communication device ID with the received vehicle ID from the database in response to the pairing request, and transmits the read vehicle information list to the gateway 1 via the in-vehicle communication device 2. The process of reading out the vehicle information list that associates the information communication device ID with the vehicle ID from the database in response to the pairing request corresponds to the "predetermined process" of the present invention.
[0029] Although the data center 5 stores in a memory (not shown) a database associating vehicle IDs, information and communication device IDs, and a vehicle information list, the present invention is not limited to this, and for example, a database associating vehicle IDs with information and communication device IDs may be stored in a memory (not shown). In this case, in response to a pairing request, the data center 5 checks whether the information and communication device IDs and vehicle IDs are stored in association with each other in the database, and if it is confirmed that the information and communication device IDs and vehicle IDs are stored in association with each other in the database, it transmits the vehicle information list to the gateway 1 via the in-vehicle communication device 2.
[0030] The gateway 1 receives the vehicle information list from the data center 5 via the in-vehicle communication device 2 .
[0031] The gateway 1 checks whether the vehicle information list contains the vehicle information transmitted and received from the ECU 3 during the periodic processing. If the gateway 1 checks that the vehicle information list contains the vehicle information transmitted and received from the ECU 3 during the periodic processing, the gateway 1 outputs a decryption key corresponding to the encryption key used to encrypt the vehicle information to the information bus B and transmits it to the information communication device 4.
[0032] The information communication device 4 receives the decryption key output from the gateway 1 to the information bus B and transmitted to the information communication device 4 .
[0033] The above is a series of processes involved in the information communication device 4 obtaining the decryption key corresponding to the encryption key, which enables the information communication device 4 to decrypt the vehicle information (encrypted vehicle information) sent by the ECU 3 during periodic processing and encrypted by the gateway 1 using the encryption key.
[0034] When acquiring vehicle information transmitted by the ECU 3 during periodic processing, the information communication device 4 performs the following processing. The vehicle information transmitted by the ECU 3 during periodic processing is encrypted by the gateway 1 using an encryption key, and the information communication device 4 receives the encrypted vehicle information (encrypted vehicle information). The information communication device 4 decrypts the encrypted vehicle information using a decryption key acquired from the gateway 1 in response to the pairing request, and acquires the vehicle information.
[0035] As described above, the data center 5 is a device installed outside the vehicle M. In this embodiment, a memory (not shown) provided in the data center 5 stores in advance a vehicle information list that lists vehicle information to be made public to information communication devices such as the information communication device 4 mounted on vehicles such as the vehicle M. Specifically, a database that associates vehicle IDs, information communication device IDs, and vehicle information lists is stored in the memory (not shown) provided in the data center 5.
[0036] The data center 5 receives the vehicle ID, the information and communication device ID, and the pairing request, and in response to the received pairing request, reads out a vehicle information list corresponding to the received vehicle ID and information and communication device ID from the database, and transmits the read vehicle information list to the gateway 1 via the in-vehicle communication device 2.
[0037] If the information communication device 4 is an information communication device whose information communication device ID does not exist in the database of the data center 5, the data center 5 transmits a vehicle information list indicating authentication failure or not listing vehicle information that is permitted to be disclosed to the gateway 1 via the in-vehicle communication device 2. The gateway 1 receives the vehicle information list indicating authentication failure or not listing vehicle information that is permitted to be disclosed, and in this case outputs a decryption key corresponding to the encryption key used to encrypt the vehicle information from the ECU 3 to the information bus B and does not transmit it to the information communication device 4. As a result, the information communication device 4 is unable to decrypt the vehicle information that was transmitted by the ECU 3 and encrypted by the gateway 1 using the encryption key (encrypted vehicle information), and is therefore unable to obtain the vehicle information.
[0038] 2. Communication sequence of vehicle communication control system A communication sequence in which the information communication device 4 acquires information from the ECU 3 in the vehicle communication control system S of FIG. 1 will be described with reference to FIG.
[0039] At the time when the communication sequence of FIG. 2 is started, the information communication device 4 does not have set therein a decryption key corresponding to the encryption key used by the gateway 1 to encrypt the vehicle information from the ECU 3.
[0040] In the periodic processing, the ECU 3 transmits vehicle information to the gateway 1, and the gateway 1 receives the vehicle information from the ECU 3 (step S1). The gateway 1 encrypts the received vehicle information using an encryption key (step S2). The gateway 1 outputs the encrypted vehicle information (encrypted vehicle information) to the information bus B (step S3), and the encrypted vehicle information is input from the information bus B to the information communication device 4 (step S4). The information communication device 4 does not have a decryption key corresponding to the encryption key used by the gateway 1 to encrypt the vehicle information, so it cannot decrypt the encrypted vehicle information and cannot obtain the vehicle information (step S5).
[0041] The information communication device 4 transmits a pairing request and an information communication device ID for identifying the information communication device 4 to the data center 5. The pairing request and the information communication device ID are output from the information communication device 4 to the information bus B (step S6), input from the information bus B to the gateway 1 (step S7), transmitted from the gateway 1 to the in-vehicle communication device 2, and received by the in-vehicle communication device 2 (step S8).
[0042] The in-vehicle communication device 2 that has received the pairing request and the information communication device ID from the gateway 1 transmits the pairing request and the information communication device ID, as well as a vehicle ID for identifying the vehicle M, to the data center 5. The pairing request, vehicle ID, and information communication device ID are transmitted from the in-vehicle communication device 2 to the data center 5 and received by the data center 5 (step S9).
[0043] In step S9, the data center 5 receives the vehicle ID, the information and communication device ID, and the pairing request, and in response to the received pairing request, reads out a vehicle information list (a list of vehicle information that is permitted to be disclosed to the information and communication device of the information and communication device ID installed in the vehicle of the vehicle ID) that corresponds to the received vehicle ID and information and communication device ID from the database (step S10).
[0044] The data center 5 transmits the vehicle information list read from the database in step S10 to the gateway 1 via the in-vehicle communication device 2. The vehicle information list is transmitted from the data center 5 to the in-vehicle communication device 2 and received by the in-vehicle communication device 2 (step S11), and is transmitted from the in-vehicle communication device 2 to the gateway 1 and received by the gateway 1 (step S12).
[0045] The gateway 1 checks whether the vehicle information list received in step S12 includes the vehicle information from the ECU 3 (step S13). In the communication sequence of Fig. 2, it checks whether the vehicle information list received in step S12 includes the vehicle information from the ECU 3.
[0046] If the gateway 1 confirms that the vehicle information list includes the vehicle information from the ECU 3, it outputs a decryption key corresponding to the encryption key used to encrypt the vehicle information from the ECU 3 to the information bus B (step S14), and the decryption key is input from the information bus B to the information communication device 4 (step S15). As a result, the information communication device 4 becomes able to decrypt the vehicle information sent from the ECU 3 and encrypted by the gateway 1 using the encryption key (encrypted vehicle information) using the decryption key corresponding to the encryption key, and acquire the vehicle information.
[0047] In the periodic processing, the ECU 3 transmits the vehicle information to the gateway 1, and the gateway 1 receives the vehicle information from the ECU 3 (step S16). The gateway 1 encrypts the received vehicle information using an encryption key (step S17). The gateway 1 outputs the encrypted vehicle information (encrypted vehicle information) to the information bus B (step S18), and the encrypted vehicle information is input from the information bus B to the information communication device 4 (step S19). The information communication device 4 has a decryption key corresponding to the encryption key used by the gateway 1 to encrypt the vehicle information, and therefore decrypts the encrypted vehicle information using the decryption key corresponding to the encryption key used by the gateway 1 to encrypt the vehicle information, thereby acquiring the vehicle information (step S20).
[0048] 3.Effects According to the above-described embodiment, the information communication device 4 transmits a pairing request and an information communication device ID to the data center 5 via the gateway 1 and the in-vehicle communication device 2, and at this time, the in-vehicle communication device 2 transmits the vehicle ID to the data center 5. The data center 5 reads out a vehicle information list associated with the vehicle ID and the information communication device ID from the database, and transmits the read vehicle information list to the gateway 1 via the in-vehicle communication device 2. If the vehicle information from the ECU 3 is included in the vehicle information list, the gateway 1 transmits a decryption key corresponding to the encryption key used to encrypt the vehicle information from the ECU 3 to the information communication device 4 via the information bus B, and the information communication device 4 receives the decryption key corresponding to the encryption key used to encrypt the vehicle information from the ECU 3. As a result, the information communication device 4 can decrypt the vehicle information transmitted by the ECU 3 and encrypted by the gateway 1 using the encryption key (encrypted vehicle information) using the decryption key corresponding to the encryption key, and thereby obtain the vehicle information.
[0049] Furthermore, even if the information and communication device 4 is an aftermarket product that can be installed on the vehicle M, such as an aftermarket product, the information and communication device 4 can decrypt the vehicle information (encrypted vehicle information) sent by the ECU 3 and encrypted by the gateway 1 using an encryption key using a decryption key corresponding to the encryption key, and thereby obtain the vehicle information.
[0050] Furthermore, if an information communication device does not have an information communication device ID in the database of the data center 5, the information communication device cannot receive from the gateway 1 the decryption key corresponding to the encryption key used to encrypt the information from the ECU 3, and therefore cannot decrypt the vehicle information (encrypted vehicle information) that was sent by the ECU 3 and encrypted by the gateway 1 using the encryption key, and therefore cannot obtain the vehicle information. In this way, an information communication device whose information communication device ID does not exist in the database of the data center 5 (for example, an information communication device that is not certified by the vehicle manufacturer of vehicle M) cannot obtain the vehicle information, and the vehicle information is protected.
[0051] Furthermore, even if the information and communication device 4 is an aftermarket information and communication device developed after the sale of vehicle M or after the completion of development of vehicle M, by storing the vehicle ID, information and communication device ID, and vehicle information list in association with each other in the database of data center 5, the information and communication device 4 can obtain a decryption key for decrypting the vehicle information (encrypted vehicle information) sent by ECU 3 and encrypted by gateway 1 using the encryption key, and thereby obtain the vehicle information.
[0052] Furthermore, the ECU 3 transmits vehicle information in periodic processing that is performed at predetermined intervals, allowing the information communication device 4 and the like to use more real-time vehicle information.
[0053] Furthermore, since the information communication device 4 does not transmit information when acquiring vehicle information from the ECU 3, the occupation of communication buses such as the information bus B by the information communication device 4 can be alleviated.
[0054] Furthermore, vehicle information can be provided to information communication devices 4 such as aftermarket products while minimizing disclosure of information to the manufacturer that developed the information communication devices 4.
[0055] In addition, it is possible to increase the number of aftermarket information and communication devices 4 that can achieve the same functions as the genuine products, thereby improving the appeal of the vehicle M itself that is equipped with the vehicle communication control system S.
[0056] In addition, various design modifications can be made to the above-described configuration within the scope of the claims.
[0057] For example, in the above embodiment, the gateway 1 may periodically change the encryption key used to encrypt the vehicle information from the ECU 3, and the information communication device 4 that has been the subject of the processing from step S6 to step S14 in FIG. 2 may again be the subject of the processing from step S6 to step S14 in FIG. 2.
[0058] In the above embodiment, the gateway 1 may set the encryption key and the decryption key for each vehicle information unit, for each ECU that provides the information, for each information communication device that receives the information, or for each vehicle. For example, if the encryption key and the decryption key are set for each vehicle, it becomes possible to prevent the decryption key obtained in one vehicle from being reused in another vehicle.
[0059] Furthermore, the contents described in the above embodiment and the contents described in the above modified examples may be combined as appropriate.
[0060] The present invention is widely applicable to a vehicle communication control system and a vehicle communication control method that utilizes an external device (external communication device) such as a data center. [Explanation of symbols]
[0061] S: Vehicle communication control system M: Vehicle 1: Gateway 2: In-vehicle communication device 3: ECU 4: Information and communication equipment 5: Data Center
Claims
1. an on-board device mounted in a vehicle; a relay device mounted on the vehicle and communicably connected to the in-vehicle device; an in-vehicle communication device that is mounted on the vehicle, is communicably connected to the relay device, and is capable of communicating with an exterior communication device installed outside the vehicle; A vehicle communication control system comprising: the in-vehicle device transmits in-vehicle device identification information for identifying the in-vehicle device to the exterior communication device via the relay device and the in-vehicle communication device; the relay device receives a result of a predetermined process performed by the exterior communication device based on the in-vehicle device identification information from the exterior communication device via the in-vehicle communication device; the relay device transmits, to the in-vehicle device, a decryption key corresponding to an encryption key used to encrypt the vehicle information to be relayed based on a result of the predetermined processing; the relay device encrypts the vehicle information to be relayed using the encryption key, and relays the encrypted vehicle information to the in-vehicle device; The vehicle-mounted device decrypts the encrypted vehicle information from the relay device using the decryption key received from the relay device. A vehicle communication control system comprising:
2. 2. The vehicle communication control system according to claim 1, wherein the in-vehicle device can be retrofitted to the vehicle.
3. an on-board device mounted in a vehicle; a relay device mounted on the vehicle and communicably connected to the in-vehicle device; an in-vehicle communication device that is mounted on the vehicle, is communicably connected to the relay device, and is capable of communicating with an exterior communication device installed outside the vehicle; A vehicle communication control method performed in a vehicle communication control system comprising: the in-vehicle device transmits in-vehicle device identification information for identifying the in-vehicle device to the exterior communication device via the relay device and the in-vehicle communication device; the relay device receives a result of a predetermined process performed by the exterior communication device based on the in-vehicle device identification information from the exterior communication device via the in-vehicle communication device; the relay device transmits, to the in-vehicle device, a decryption key corresponding to an encryption key used to encrypt the vehicle information to be relayed based on a result of the predetermined processing; the relay device encrypts the vehicle information to be relayed using the encryption key, and relays the encrypted vehicle information to the in-vehicle device; The vehicle-mounted device decrypts the encrypted vehicle information from the relay device using the decryption key received from the relay device. A vehicle communication control method comprising:
Citation Information
Patent Citations
Communication system
JP2017059894A
On-vehicle device and probe data transmission method
JP2019144655A
Vehicle-oriented service provision system, on-vehicle device, and command transmission method
JP2019192953A
On-vehicle authentication system, communication device, on-vehicle authentication device, communication device authentication method and communication device manufacturing method
US20200153636A1