Data storage system, mobile object, and data storage program

The data storage system encrypts and decrypts data using a secure key to authenticate data transmission and verify device states, addressing fraudulent data transmission and ensuring data integrity in vehicle backup systems.

JP7810540B2Active Publication Date: 2026-02-03DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2021174822
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-10-26
Publication Date
2026-02-03
Estimated Expiration
2041-10-26

AI Technical Summary

Technical Problem

Existing data storage systems for vehicles do not verify the authenticity of data transmitted to backup servers, nor ensure that the transmitting and receiving devices are in an appropriate state, making them vulnerable to fraudulent data transmission.

Method used

A data storage system that encrypts data using an encryption key stored in a secure, restricted-access area of the vehicle's ECU, and decrypts it using the same key at the backup server, ensuring only legitimate data is transmitted and received, with additional verification through hash value checks.

Benefits of technology

Ensures the authenticity of data transmitted to backup servers and verifies the integrity of both the transmitting and receiving devices, preventing fraudulent data transmission and ensuring appropriate device states.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007810540000001
    Figure 0007810540000001
  • Figure 0007810540000002
    Figure 0007810540000002
  • Figure 0007810540000003
    Figure 0007810540000003
Patent Text Reader

Abstract

To provide a data storage system, a mobile body, and a data storage program that determine whether data to be backed up and an apparatus that transmits or receives the data are suitable.SOLUTION: In a data storage system 10, when data is transmitted from an on-vehicle ECU 14 to a backup server 16, the data is encrypted using an encryption key, and the encrypted data received by the backup server 16 is decrypted with the encryption key. Since the on-vehicle ECU 14 stores the encryption key in an area where access is restricted, a so-called secure world SW, the data cannot be encrypted using the encryption key from the outside of the on-vehicle ECU 14. For this reason, the data received by the backup server 16 and can be decrypted using the encryption key is data appropriately transmitted from the on-vehicle ECU 14.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a data storage system, a mobile object, and a data storage program. [Background technology]

[0002] In recent years, the importance of data acquired by moving objects such as vehicles has increased. Therefore, there is a demand for a device that can store data acquired by moving objects such as vehicles while ensuring reliability.

[0003] Patent Document 1 describes a data storage device in which an on-board ECU uses a blockchain to store data acquired in a vehicle. The data storage device described in Patent Document 1 backs up data to a backup server, and if an abnormality occurs in the data stored in the on-board ECU, the data is restored using the backup data. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent Publication No. 2021-13122 Summary of the Invention [Problem to be solved by the invention]

[0005] The data storage device described in Patent Document 1 does not verify that data transmitted to the backup server is not fraudulently transmitted data. Therefore, the data storage device described in Patent Document 1 cannot detect, for example, a case where an on-board ECU is manipulated by a malicious third party to fraudulently transmit data to the backup server. Furthermore, Patent Document 1 cannot detect whether an on-board ECU in an appropriate state transmitted the data or whether a backup server in an appropriate state received the data. In other words, it is required that the data transmitted to the backup server is not fraudulent data, and that devices such as the device transmitting the data and the backup server are in an appropriate state.

[0006] In view of the above background, an object of the present invention is to provide a data storage system, a mobile object, and a data storage program that can determine whether the data to be backed up and the device that transmits or receives the data are appropriate. [Means for solving the problem]

[0007] The present invention employs the following technical solutions to solve the above problems. The reference symbols in parentheses in the claims and this section are merely examples showing the correspondence with the specific solutions described in the embodiments below as one aspect, and do not limit the technical scope of the present invention.

[0008] A data storage system (10) according to one embodiment of the present invention is a data storage system that stores data transmitted from an information processing device (14) in a backup server (16), wherein the information processing device includes an encryption unit (64) that encrypts the data using an encryption key stored in a storage area (TS) with restricted access to generate encrypted data, and a transmission unit (48) that transmits the encrypted data to the backup server, and the backup server includes a decryption unit (70) that decrypts the encrypted data received from the information processing device using the encryption key.

[0009] According to this configuration, when data is sent from an information processing device to a backup server, the data is encrypted using an encryption key, and the backup server decrypts the received encrypted data using the encryption key. Because the information processing device stores the encryption key in a storage area with restricted access, data cannot be encrypted using the encryption key from outside the information processing device. Therefore, data received by the backup server that can be decrypted using the encryption key is data that was properly transmitted from the information processing device. On the other hand, data received by the backup server that cannot be decrypted using the encryption key is data that was improperly transmitted from the information processing device or data that was not transmitted from the information processing device. Furthermore, the fact that the backup server can decrypt data using the encryption key indicates that not only the information processing device but also the backup server is in an appropriate state. Therefore, this configuration can determine whether the data to be backed up and the device transmitting or receiving the data are appropriate.

[0010] A mobile object (12) according to one aspect of the present invention includes a mobile object (12) equipped with the information processing device described above.

[0011] A data storage program according to one embodiment of the present invention is a data storage program for storing data transmitted from an information processing device in a backup server, and causes a computer provided by the information processing device to function as an encryption unit that encrypts the data using an encryption key stored in an area with restricted access to generate encrypted data, and a transmission unit that transmits the encrypted data to the backup server, and causes a computer provided by the backup server to function as a decryption unit that decrypts the encrypted data received from the information processing device using the encryption key. [Effects of the Invention]

[0012] According to the present invention, it is possible to determine whether the data to be backed up and the device that transmits or receives the data are appropriate. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 2 is a functional block diagram showing the electrical configuration of the data storage system according to the embodiment. [Figure 2] 4 is a flowchart showing the flow of a data transmission process executed by an on-board ECU according to the embodiment. [Figure 3] 10 is a flowchart illustrating the flow of a received data verification process executed by the backup server of the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. Note that the embodiment described below shows an example of how the present invention can be implemented, and the present invention is not limited to the specific configuration described below. When implementing the present invention, a specific configuration corresponding to the embodiment may be appropriately adopted.

[0015] 1 is a functional block diagram showing the electrical configuration of a data storage system 10 according to this embodiment. The data storage system 10 is made up of an on-board ECU (Electronic Control Unit) 14 provided in a vehicle 12 and a backup server 16.

[0016] The on-vehicle ECU 14 is one of a plurality of electronic control units mounted on the vehicle 12. The on-vehicle ECU 14 may be, for example, an integrated ECU for a body system, or an autonomous driving ECU for autonomous driving or advanced driving assistance. Furthermore, the on-vehicle ECU 14 may be a dedicated ECU for storing acquired data. The on-vehicle ECU 14 is electrically connected directly or indirectly to a DCM (Data Communication Module) 20, a V2X (Vehicle to Everything) communicator 22, a plurality of on-vehicle sensors 24, and the like.

[0017] The DCM 20 is a communication module mounted on the vehicle 12 and transmits and receives data to and from information processing devices such as the backup server 16. For example, the DCM 20 transmits data stored in the on-board ECU 14 to the backup server 16 for backup purposes, and receives backup data from the backup server 16.

[0018] The V2X communicator 22 is an in-vehicle communication device that realizes vehicle-to-vehicle communication, roadside-to-vehicle communication, and pedestrian-to-vehicle communication. When an in-vehicle device mounted on another vehicle, a roadside device installed on a road, a mobile terminal carried by a pedestrian, etc. is within its communication range, the V2X communicator 22 is capable of bidirectional communication with these communication devices. The V2X communicator 22 transmits communication data acquired through communication to the in-vehicle ECU 14, for example, via a communication bus of an in-vehicle communication network.

[0019] The on-vehicle sensors 24 include multiple types of sensors mounted on the vehicle 12. The on-vehicle sensors 24 include a vehicle speed sensor and an inertial sensor that detect the driving state of the vehicle 12, an in-vehicle camera that detects the driver's state and driving operation, a pedal sensor, and a steering sensor. The on-vehicle sensors 24 also include an outside camera, millimeter-wave radar, and lidar that are used for driving assistance or autonomous driving. Each on-vehicle sensor 24 transmits detected data to the on-vehicle ECU 14, for example, via a communication bus of an on-vehicle communication network.

[0020] The on-board ECU 14 is an on-board computer that functions as a data storage device that acquires data generated in the vehicle 12 and stores the acquired data in a state that makes it difficult to tamper with. The on-board ECU 14 is equipped with a control circuit that includes a processor 26, a storage unit 28, an input / output interface 30, and a RAM (Random Access Memory) 32.

[0021] The processor 26 is hardware for arithmetic processing coupled to the RAM 32, and executes various programs by accessing the RAM 32. The storage unit 28 includes a non-volatile storage medium, and stores various programs executed by the processor 26. The storage unit 28 stores at least a data deletion program related to the accumulation, provision, and monitoring of data generated in the vehicle 12.

[0022] The in-vehicle ECU 14 defines at least two different processing domains within the system: a normal world network and a secure world software. The normal world network and the secure world software may be physically separated on the hardware, or may be virtually separated by cooperation between hardware and software. For example, the in-vehicle ECU 14 uses a function such as a context switch to temporally separate resources required for application execution into the normal world network and the secure world software.

[0023] The normal world network is a normal area where the operating system and applications are executed. The normal world network is provided with a normal storage US as a storage area (untrusted storage) for storing data.

[0024] The secure world SW is an area isolated from the normal world NW. In the secure world SW, a secure operating system and applications for processes requiring security are executed. Access from the normal world NW to the secure world SW is restricted by the functions of the processor 26. Therefore, the existence of the secure world SW cannot be recognized from the normal world NW, ensuring the safety of processes executed in the secure world SW and information stored in the secure world SW. The secure world SW is provided with a secure storage TS, which is a storage area (Trusted Storage) for storing data and is a memory area with restricted access that cannot be directly accessed from the normal world NW. The capacity of the secure storage TS may be smaller than the capacity of the normal storage US.

[0025] The in-vehicle ECU 14 of this embodiment stores the acquired data using a blockchain. Furthermore, the in-vehicle ECU 14 of this embodiment appropriately transmits the acquired data to the backup server 16 for backup storage.

[0026] The configuration of the in-vehicle ECU 14 for transmitting data to the backup server 16 will be described below with reference to FIG.

[0027] The normal world NW includes a data acquisition unit 40, a block generation unit 42, an encryption request unit 44, a program hash value calculation unit 46, a backup transmission unit 48, and a data restoration unit 50.

[0028] The data acquisition unit 40 is electrically connected to, for example, a communication bus of an in-vehicle communication network, and acquires various data generated in the vehicle 12, such as communication data and detection data, via the communication bus. The data acquisition unit 40 extracts preset data from the data sequentially output to the communication bus by the in-vehicle sensors 24 and the V2X communicator 22, selectively acquires the data as acquired data to be saved, and stores the data in the normal storage US.

[0029] The block generation unit 42 has a function of calculating hash values ​​using a hash function such as SH-256. The block generation unit 42 converts the data acquired and stored by the data acquisition unit 40, which is to be included in the blockchain, into a hash chain-like data structure and stores it as a secure data file in the normal storage US. The block generation unit 42 creates one block, for example, based on a predetermined number or capacity of data. The block generation unit 42 generates a blockchain consisting of multiple blocks linked in a linear chain by including the hash value (block hash value) of the data of one block in the next block. In this embodiment, the data to be sent to the backup server 16 is, for example, a block to be linked to the blockchain.

[0030] The encryption request unit 44 requests the encryption unit 64 of the secure world SW to encrypt data acquired by the on-board ECU 14 in order to transmit the data to the backup server 16. Details of the encryption unit 64 will be described later. The data to be transmitted to the backup server 16 are, for example, blocks that constitute a blockchain, and the data to be transmitted to the backup server 16 will also be referred to as a message in the following description. Furthermore, the encryption request unit 44 transmits the data to be transmitted to the backup server 16 to the secure world SW and requests the encryption unit 64 to encrypt the data, for example, at a predetermined timing such as a predetermined time, every time the size of the data acquired by the data acquisition unit 40 reaches a predetermined size, or every time the size of a block not yet transmitted to the backup server 16 reaches a predetermined size.

[0031] The program hash value calculation unit 46 encrypts data (message) and calculates a program unique value, which is a unique value of a program related to transmission to the backup server 16. Note that this unique value is, for example, a hash value, and in the following description, the unique value is referred to as a calculated program hash value. The calculated program hash value is transmitted to the encryption unit 64 along with the message. Note that, for example, the program for which the hash value is calculated is a program (encryption request program) that functions as the encryption request unit 44. However, the program is not limited to this as long as it is related to encrypting data and transmitting it to the backup server 16, and may also be, for example, a program that functions as the backup transmission unit 48.

[0032] The backup transmission unit 48 transmits data to be stored in the backup server 16 to the backup server 16 via the DCM 20.

[0033] The data restoration unit 50 restores data using backup data stored in the backup server 16 when an abnormality such as tampering or loss occurs in the blockchain.

[0034] The secure world SW comprises a program hash value determination unit 60, a transmission message hash value calculation unit 62, and an encryption unit 64. The secure storage TS provided in the secure world SW stores a stored program hash value and an encryption key. The stored program hash value is a hash value of a program related to encrypting a message and transmitting it to the backup server 16, which in this embodiment is the encryption request program, and is calculated in advance. The encryption key is a secret key used to encrypt the message, and the same key is also stored in the backup server 16 and used for decryption. By storing the stored program hash value and the encryption key in the secure storage TS, they cannot be obtained from the normal world NW, and therefore tampering is prevented.

[0035] In this embodiment, as described above, the same key (common key) is used as the encryption key for encryption and decryption, but this is not limited to this, and different keys (public key and private key) may be used for encryption and decryption.

[0036] The program hash value determination unit 60 determines whether the calculated program hash value calculated by the program hash value calculation unit 46 matches a stored program hash value that has been calculated and stored in advance. If the calculated program hash value and the stored program hash value differ, the program hash value determination unit 60 determines that there is a possibility that the encrypted request program has been tampered with.

[0037] The transmission message hash value calculation unit 62 calculates a transmission message hash value, which is a hash value of a message received from the normal world NW and to be transmitted to the backup server 16.

[0038] The encryption unit 64 encrypts the data transmitted from the normal world NW using the encryption key stored in the secure storage TS to generate encrypted data. The encrypted data generated by the encryption unit 64 in this embodiment is obtained by encrypting the transmission message hash value calculated by the transmission message hash value calculation unit 62.

[0039] The encrypted data is used as a digital signature for the message to be sent to the backup server 16. Therefore, the encrypted data is sent from the secure world SW to the normal world NW. The backup sending unit 48 adds the encrypted data to the message as a digital signature and sends it to the backup server 16.

[0040] The backup server 16 includes a decryption unit 70, a received message hash value calculation unit 72, a message hash value determination unit 74, a block hash value determination unit 75, and a storage unit 76.

[0041] The decryption unit 70 decrypts the encrypted data received from the in-vehicle ECU 14 using the encryption key. As described above, the encrypted data in this embodiment is added as a digital signature to the message transmitted from the in-vehicle ECU 14. The encryption key is stored in the storage unit 76.

[0042] The received message hash value calculation unit 72 calculates a received message hash value, which is a hash value of a message received from the in-vehicle ECU 14 .

[0043] The message hash value determination unit 74 determines whether the transmitted message hash value obtained by decryption by the decryption unit 70 matches the received message hash value. If the transmitted message hash value and the received message hash value differ, the message hash value determination unit 74 determines that the message (data) sent to the backup server 16 is invalid data.

[0044] The block hash value determination unit 75 determines whether the hash value of the previous block included in the block received from the vehicle ECU 14 (hereinafter referred to as the "previous block hash value") matches the hash value of the last block stored in the backup server 16 (hereinafter referred to as the "last block hash value").

[0045] The storage unit 76 is a large-capacity storage medium such as a hard disk drive, and stores data transmitted as a message from the in-vehicle ECU 14 for backup purposes, by linking it to, for example, ID information of the in-vehicle ECU 14. Note that the data transmitted from the in-vehicle ECU 14 for backup purposes is a block linked to a blockchain, and therefore the storage unit 76 stores the data as a blockchain.

[0046] 2 is a flowchart showing the flow of the data transmission process executed by the in-vehicle ECU 14. As described above, the data transmission process starts at a predetermined timing such as a predetermined time, when the size of data acquired by the data acquisition unit 40 reaches a predetermined size, or when the size of a block that has not been transmitted to the backup server 16 reaches a predetermined size. In the data transmission process of this embodiment, as an example, when the size of an untransmitted block reaches a predetermined size, the block is transmitted from the in-vehicle ECU 14 to the backup server 16. Note that an encryption key and a stored program hash value are stored in advance in the secure storage TS.

[0047] First, in step S100, the encryption request unit 44 transmits data to be sent to the backup server 16 as a message to the secure world SW. At this time, the encryption request unit 44 transmits the calculated program hash value calculated by the program hash value calculation unit 46 together with the message.

[0048] In the next step S102, the message and the calculated program hash value are received in the secure world SW.

[0049] In the next step S104, the program hash value determination unit 60 determines whether the received calculated program hash value matches the stored saved program hash value, and if the determination is positive, proceeds to step S106, and if the determination is negative, proceeds to step S114.

[0050] In step S106, the transmitted message hash value calculation unit 62 calculates the hash value of the received message.

[0051] In the next step S108, the encryption unit 64 encrypts the calculated message hash value using the encryption key to generate encrypted data.

[0052] In the next step S110, the encrypted data is transmitted to the normal world NW.

[0053] In this way, the encryption unit 64 and the program hash value determination unit 60 execute processing in the secure world SW, and therefore, the stored program hash value and encryption key stored in the in-vehicle ECU 14 can be prevented from being tampered with.

[0054] In the next step S112, the encrypted data received from the secure world SW is added to the message as a digital signature, and the backup transmission unit 48 transmits the message to the backup server 16, thereby carrying out the data transmission process. In the data transmission process of this embodiment, the encrypted data is added to the message as a digital signature, so that the transmission of the message to the backup server 16 can be carried out in the same manner as in the conventional case.

[0055] If the determination in step S104 is negative, the process proceeds to step S114, where it is determined that an unintended data transmission request has been made due to tampering with the encrypted request program or the like because the program hash values ​​do not match, and the in-vehicle ECU 14 is rebooted and the process proceeds to secure boot, where tampering with the encrypted request program or the like is detected.

[0056] 3 is a flowchart showing the flow of the received data verification process executed by the backup server 16. The received data verification process is executed when the backup server 16 receives a message transmitted from the in-vehicle ECU 14. Note that an encryption key is stored in advance in the storage unit 76 provided in the backup server 16.

[0057] First, in step S200, the received message hash value calculation unit 72 calculates a received message hash value, which is a hash value of a received message.

[0058] In the next step S202, the decryption unit 70 decrypts the digital signature added to the received message using the encryption key.

[0059] In the next step S204, the decryption unit 70 determines whether the decryption was successful, and if the determination is affirmative, the process proceeds to step S206, and if the determination is negative, the process proceeds to step S210. If the determination is affirmative, the backup server 16 acquires the transmitted message hash value. On the other hand, if the determination is negative, the received message may have been transmitted to the backup server 16 fraudulently, so the message is discarded in step S210 without being stored in the storage unit 76.

[0060] In step S206, the message hash value determination unit 74 determines whether the transmitted message hash value acquired by decryption matches the received message hash value calculated by the received message hash value calculation unit 72, and if the determination is affirmative, the process proceeds to step S207. On the other hand, if the determination is negative, the received message may have been sent to the backup server 16 fraudulently, so the process proceeds to step S210, where the message is discarded without being stored in the storage unit 76.

[0061] In the next step S207, the block hash value determination unit 75 determines whether the previous block hash value included in the block received as a message matches the last block hash value stored in the backup server 16, and if the determination is affirmative, the process proceeds to step S208. On the other hand, if the determination is negative, there is a possibility that the received block has been tampered with, so the process proceeds to step S210, and the message is discarded without being stored in the storage unit 76. In this way, by checking the hash value before the backup server 16 stores the block, it is possible to detect whether the block has been tampered with.

[0062] In step S208, the storage unit 76 stores the data that is the received message, and the received data verification process ends. Note that the data received as a message in this embodiment is a block, and is therefore stored by being linked to the final block of the blockchain that has already been stored in the storage unit 76. A digital signature may also be stored in the storage unit 76 together with the message.

[0063] As described above, the data storage system 10 of this embodiment encrypts data using an encryption key when transmitting data from the vehicle ECU 14 to the backup server 16, and the backup server 16 decrypts the received encrypted data using the encryption key. Because the vehicle ECU 14 stores the encryption key in an area with restricted access, known as a secure world SW, data cannot be encrypted using the encryption key from outside the vehicle ECU 14. Therefore, data received by the backup server 16 that can be decrypted using the encryption key is data that was properly transmitted from the vehicle ECU 14. On the other hand, data received by the backup server 16 that cannot be decrypted using the encryption key is data that was improperly transmitted from the vehicle ECU 14 or data that was not transmitted from the vehicle ECU 14. Furthermore, the fact that the backup server 16 can decrypt data using the encryption key indicates that not only the vehicle ECU 14 but also the backup server 16 are in an appropriate state. Therefore, the data storage system 10 of this embodiment can determine whether the data to be backed up and the devices transmitting or receiving the data are appropriate.

[0064] In addition, the data storage system 10 of this embodiment double-verifies the data received by the backup server 16 from the vehicle ECU 14 by encryption and hash value determination, making it possible to more reliably determine that the data sent to the backup server 16 was sent appropriately.

[0065] Although the present invention has been described above using the above-mentioned embodiment, the technical scope of the present invention is not limited to the scope described in the above-mentioned embodiment. Various changes or improvements can be made to the above-mentioned embodiment without departing from the gist of the invention, and such changes or improvements are also included in the technical scope of the present invention.

[0066] In the above embodiment, the data storage system 10 encrypts the hashed message, which is a transmitted message hash value, and attaches it to the message as an electronic signature before transmitting it to the backup server 16. However, this is not limited to this, and the encrypted transmitted message hash value may be transmitted in a form other than an electronic signature as long as the message is associated with the encrypted transmitted message hash value and transmitted to the backup server 16.

[0067] The data storage system 10 of the above embodiment may be configured to encrypt messages without hashing them and transmit them to the backup server 16. In this configuration, the message hash value is not calculated, and the backup server 16 determines whether the data transmission is appropriate based on whether it can be decrypted using the encryption key.

[0068] The hash function used in the data storage system 10 of the above embodiment is a cryptographic hash function. A cryptographic hash function has the property that it never outputs the same hash value from different inputs, and that it is virtually impossible to guess the input from the output hash value. Instead of the above-mentioned SHA-256, which is one of SHA-2, the SHA-1, SHA-2, and SHA-3 algorithms may be used as appropriate depending on the required output length (number of bits). Furthermore, an irreversible value that is unique to data or a program may be used instead of the hash value.

[0069] The vehicle 12 equipped with the on-board ECU 14 may be a private car that is privately owned by a specific owner and is intended for use by that owner, etc. When applied to private cars, data indicating the user's driving history, which is stored in a state protected from fraud, becomes highly valuable to service providers that set insurance premiums according to driving conditions, for example.

[0070] The vehicle 12 equipped with the on-board ECU 14 may be a rental car vehicle, a manned taxi vehicle, a ride-sharing vehicle, a freight vehicle, a bus, etc. Furthermore, the on-board ECU 14 may be installed in a driverless vehicle used for a mobility service. As mobility services become more widespread in the future, it is expected that the importance of data accumulated in the on-board ECU 14 will become even greater.

[0071] In the above embodiment, each function provided by the in-vehicle ECU 14 can be provided by software and hardware that executes the software, software alone, hardware alone, or a combination of these. When such a function is provided by electronic circuits as hardware, each function can also be provided by digital circuits including multiple logic circuits or analog circuits.

[0072] Each processor in the above embodiments may include at least one arithmetic core such as a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit).Furthermore, the processor may further include an FPGA (Field-Programmable Gate Array) and an IP core with other dedicated functions.

[0073] The form of the storage medium storing the programs related to the data transmission process and the received data verification process of the above embodiment may be changed as appropriate. For example, the storage medium is not limited to a configuration mounted on a circuit board, but may be provided in the form of a memory card or the like, inserted into a slot, and electrically connected to a computer bus. Furthermore, the storage medium may be an optical disk or a hard disk drive, etc., from which the programs are copied to the computer.

[0074] The control unit and the method of the present embodiment may be implemented by a special-purpose computer having a processor programmed to execute one or more functions embodied in a computer program. Alternatively, the apparatus and the method described in the present embodiment may be implemented by a special-purpose hardware logic circuit. Alternatively, the apparatus and the method described in the present embodiment may be implemented by one or more special-purpose computers configured by a combination of a processor that executes a computer program and one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory tangible storage medium.

[0075] Furthermore, ECUs with data transmission processing functions can be installed in moving objects other than vehicles, such as heavy machinery used at work sites, driving toys arranged in amusement facilities, railroad cars, trams, and airplanes.

[0076] Furthermore, the processing flow described in the above embodiment is also an example, and unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged within the scope of the present invention. [Explanation of symbols]

[0077] 10. Data storage system, 12. Vehicle, 14. In-vehicle ECU, 16...backup server, 46...program hash value calculation unit, 48: Backup transmission unit; 60: Program hash value determination unit; 62: Transmission message hash value calculation unit; 64: Encryption unit; 70: Decryption unit; 72...Received message hash value calculation unit, TS...Secure storage

Claims

1. A data storage system (10) that stores data transmitted from an information processing device (14) in a backup server (16), The information processing device includes: a first data unique value calculation unit (62) that calculates a first data unique value that is a unique value of the data to be transmitted to the backup server; an encryption unit (64) that encrypts the first data unique value using an encryption key stored in a storage area (TS) whose access is restricted to generate encrypted data; a transmission unit (48) that adds the encrypted data to the data and transmits the data to the backup server, The backup server a decryption unit (70) that decrypts the encrypted data received from the information processing device using the encryption key; a second data eigenvalue calculation unit (72) that calculates a second data eigenvalue that is an eigenvalue of the data received from the information processing device; a data unique value determination unit (74) that determines whether or not the first data unique value obtained by decoding by the decoding unit matches the second data unique value, When the first data unique value and the second data unique value match, the backup server stores the data received from the information processing device. Data storage system.

2. The data storage system according to claim 1 , wherein the encrypted data is added as a digital signature of data transmitted to the backup server.

3. The information processing device includes: a program unique value calculation unit that encrypts the data and calculates a first program unique value that is a unique value of a program related to transmission to the backup server; a program unique value determination unit that determines whether or not the first program unique value calculated by the program unique value calculation unit matches a second program unique value that is a unique value of the program and that is calculated and stored in advance; 3. The data storage system according to claim 1, comprising:

4. The data storage system according to claim 3 , wherein the encryption unit and the program unique value determination unit execute processes in an area where access is restricted.

5. The data is a block linked to a blockchain; A data storage system as described in any one of claims 1 to 4, wherein the backup server is provided with a block unique value determination unit that determines whether the unique value of the previous block included in the block received from the information processing device matches the unique value of the final block stored in the backup server.

6. A mobile object (12) comprising the information processing device according to any one of claims 1 to 4.

7. A data storage program for storing data transmitted from an information processing device in a backup server, The computer included in the information processing device a first data unique value calculation unit that calculates a first data unique value that is a unique value of the data to be transmitted to the backup server; an encryption unit that encrypts the first data unique value with an encryption key stored in an area to which access is restricted to generate encrypted data; a transmitting unit that adds the encrypted data to the data and transmits the data to the backup server; and make it work, A computer included in the backup server, a decryption unit that decrypts the encrypted data received from the information processing device using the encryption key; a second data eigenvalue calculation unit (72) that calculates a second data eigenvalue that is an eigenvalue of the data received from the information processing device; a data unique value determination unit (74) that determines whether the first data unique value obtained by decoding by the decoding unit matches the second data unique value; and make it work, When the first data unique value and the second data unique value match, the backup server stores the data received from the information processing device. Data storage program.

Citation Information

Patent Citations

  • Data storage device and data storage program

    JP2021013122A