Server device, data modification method, program, and data modification system

The system securely updates vehicle data by assigning electronic signatures and using a relay device for direct connection when network connectivity is absent, ensuring secure data changes in vehicles.

JP7831144B2Active Publication Date: 2026-03-17DAI NIPPON PRINTING CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-08
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Vehicles and similar mobile devices often cannot communicate in real-time, making it difficult to securely update data without real-time communication.

Method used

A system that assigns an electronic signature to data changes in electronic devices, determines network connectivity, and transmits signed data to a relay device for direct connection when network connectivity is unavailable, using a data management server, vehicle server, and diagnostic device.

Benefits of technology

Ensures secure data updates in vehicles by verifying electronic signatures even when real-time communication is not possible, allowing data changes through a relay device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007831144000001
    Figure 0007831144000001
  • Figure 0007831144000002
    Figure 0007831144000002
  • Figure 0007831144000003
    Figure 0007831144000003
Patent Text Reader

Abstract

To provide a server device and the like that can securely change data even when real-time communication is not possible.SOLUTION: When changing data of an electronic device 20 installed in a mobile body, a server device 10 adds an electronic signature to change data that is for changing the data (S3), and determines whether the electronic device 20 can connect to a network 3 (S4). When the electronic device 20 cannot connect to the network 3, the server device transmits the change data with the electronic signature added to a diagnostic device 40, which is a relay device capable of directly connecting to the electronic device 20 (S6).SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of server devices, data change methods, programs, and data change systems.

Background Art

[0002] When a vehicle has a function to authenticate with the outside, such as a digital key that unlocks / locks the vehicle door and starts the engine using a contactless IC card, smartphone, etc., the data of the key and certificate is stored in the ECU (Electronic Control Unit) inside the vehicle. When updating these data later, in order to prevent unauthorized writing, it is necessary to confirm that the data is from a party with the correct authority using authentication and secure messages. For example, in Patent Document 1, in response to an access request to a target site, a computing device receives the current digital certificate from the target site, and based on the previously received digital certificate regarding the target site, the confirmation certificate received from the certificate review service, and the digital certificate and / or additional characteristics of the target site, it discloses an automatic detection of an illegal digital certificate to determine whether the current digital certificate is genuine or fraudulent.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the conventional method, it is assumed that the device is connected to the network. However, vehicles and the like are not always able to communicate in real time. In situations where real-time communication is not possible, authentication for mutual data exchange cannot be performed, and it is difficult to securely update data.

[0005] Therefore, the present invention has been made in view of the above problems, and aims to provide a server device, a data modification method, a program, and a data modification system that can securely modify data even when real-time communication is not possible. [Means for solving the problem]

[0006] To solve the above problems, the invention described in claim 1 provides an assignment means for assigning an electronic signature to change data when changing data in an electronic device installed on a mobile body, and the electronic device is connectable to a network. It has the following functions Determine whether it is true or false. connection A determination means, and the electronic device is connectable to the network. It does not have that function. In this case, the system includes a transmission means for transmitting the modified data to which the electronic signature has been applied to a relay device that can be directly connected to the electronic device. The modified data is a command executed in the electronic device, and includes a command for modifying the data. It is characterized by the following:

[0007] The invention described in claim 2 determines whether or not to change the data of the electronic device in the server device described in claim 1. change The system is further characterized by comprising a determination means.

[0008] The invention described in claim 3 is, The connection determination means determines whether the electronic device has the function to connect to the network by referring to a storage means that stores information on whether the electronic device has the function to connect to the network. It is characterized by the following:

[0009] The invention described in claim 4 is characterized in that, in the server device described in claim 1 or claim 2, the electronic signature is used to verify the modified data in the electronic device.

[0010] The invention described in claim 5 is an invention that, when the granting means modifies the data of an electronic device installed on a mobile body, grants an electronic signature to the modified data for modifying the data, connection The determination means determines that the electronic device can connect to a network. It has the following functions Determine whether or not connection A determination step and a transmission means, the electronic device connecting to the network. It does not have that function. In this case, the process includes a transmission step of transmitting the modified data to which the electronic signature has been added to a relay device that can be directly connected to the electronic device. Furthermore, the modified data includes a command executed in the electronic device, which is a command for modifying the data. It is characterized by [something].

[0011] Furthermore, the invention described in claim 6 provides a means for assigning an electronic signature to modified data when a computer modifies data in an electronic device installed on a mobile device, and the electronic device is connectable to a network. It has the following functions Determine whether or not connection The determination means and the electronic device are connected to the network. It does not have that function. In this case, the modified data to which the electronic signature has been attached is to function as a transmission means for transmitting it to a relay device that can be directly connected to the electronic device. The modified data is a command executed in the electronic device, and includes a command for modifying the data. It is characterized by the following:

[0012] Furthermore, the invention described in claim 7 is a data modification system comprising an electronic device installed on a mobile body, a server device for managing changes to the data of the electronic device, and a relay device directly connectable to the electronic device, wherein when the server device modifies the data of the electronic device, the system includes a means for attaching an electronic signature to the modification data for modifying the data, and the electronic device is connectable to a network. It has the following functions Determine whether or not connection The determination means and the electronic device are connected to the network. It does not have that function. In this case, the system includes a transmission means for transmitting the modified data to which the electronic signature has been attached to the relay device. Furthermore, the modified data is a command executed in the electronic device, and includes a command for modifying the data. It is characterized by the following: [Effects of the Invention]

[0013] According to the present invention, when changing data of an electronic device installed in a moving body, an electronic signature is attached to change data for changing the data, it is determined whether the electronic device can be connected to a network, and when the electronic device cannot be connected to the network, the change data with the attached electronic signature is directly transmitted to a relay device that can be connected to the electronic device. Therefore, even when real-time communication is not possible, the change data with the attached electronic signature is transmitted from the relay device directly connected to the electronic device, and after verifying the electronic signature, the data in the electronic device can be securely changed based on the change data.

Brief Description of the Drawings

[0014] [Figure 1] It is a diagram showing a schematic configuration example of a data change system according to this embodiment. [Figure 2] It is a diagram showing a schematic configuration example of the data management server device in FIG. 1. [Figure 3] It is a diagram showing an example of a database of the data management server device in FIG. 2. [Figure 4] It is a diagram showing a schematic configuration example of an electronic device. [Figure 5] It is a diagram showing a schematic configuration example of a vehicle server device. [Figure 6] It is a diagram showing a schematic configuration example of a diagnostic device. [Figure 7] It is a flowchart showing an example of the operation of the data management server device. [Figure 8] It is a schematic diagram showing an example of the flow of a change data set in a data change system. [Figure 9] It is a flowchart showing an example of the operation of a vehicle server device or a diagnostic device. [Figure 10] It is a flowchart showing an example of the operation of an electronic device.

Embodiments for Carrying Out the Invention

[0015] Embodiments of the present invention will now be described in detail with reference to the drawings. The embodiments described below are examples of the application of the present invention to a data modification system that modifies data in an electronic device installed inside a vehicle. The vehicle is an example of a mobile vehicle, such as a two-wheeled vehicle, a four-wheeled vehicle, or a bicycle.

[0016] [1. Overview of the Data Change System S] First, the general configuration of the data modification system S according to this embodiment will be described with reference to Figure 1, etc. Figure 1 is a diagram showing an example of the general configuration of the data modification system S according to this embodiment.

[0017] As shown in Figure 1, the data change system S comprises a data management server device 10, an electronic device 20 mounted on a vehicle C, a vehicle server device 30 that communicates with the electronic device 20 via a network 3, and a diagnostic device 40 that is directly connected to the vehicle C to diagnose various electronic systems of the vehicle C. Vehicle C is an example of a mobile vehicle, such as a two-wheeled vehicle, a four-wheeled vehicle, or a bicycle. Vehicle C may or may not have wireless communication capabilities via the network 3.

[0018] The data management server device 10, the electronic device 20, and the vehicle server device 30 are connected to a network 3, which is comprised of, for example, the Internet. The data management server device 10 and the vehicle server device 30 can communicate with each other via network 3. The vehicle server device 30 and the electronic device 20 can communicate wirelessly via network 3 and a wireless base station 5. The electronic device 20 may communicate directly with the data management server device 10 via network 3 without going through the vehicle server device 30. Network 3 is connected to a public key infrastructure (PKI).

[0019] Furthermore, certain vehicles C may not have wireless communication capabilities with the outside world, and the electronic device 20 of this vehicle C may not be able to connect to the network 3. Also, even if vehicle C has wireless communication capabilities via the network 3, the electronic device 20 may not be able to communicate with the outside world in real time depending on the communication environment.

[0020] The data management server device 10 is a server for managing specific applications, data, etc., that can be provided to specific devices, such as an electronic device 20 installed in vehicle C.

[0021] The electronic device 20 is, for example, a control device such as an ECU (Electronic Control Unit) installed in vehicle C, or a device having an eSE (embedded Secure Element). The electronic device 20 may also be an electronic device such as a navigation system or drive recorder installed in vehicle C, or a device that provides various services such as payment services. The electronic device 20 may also be a digital key for vehicle C.

[0022] Here, examples of data that the data management server device 10 provides to the electronic device 20 include key data such as encryption keys stored in the ECU, digital certificate data, navigation map data, control data for the ECU, and data for updating these. In addition, examples of applications (electronic device data) that the data management server device 10 provides to the electronic device 20 include control programs for the ECU, navigation programs, and software required to use various services such as payment services.

[0023] The vehicle server device 30 is, for example, a server that connects to the electronic device 20 via the network 3 and provides data to be modified in the electronic device 20.

[0024] The diagnostic device 40 is a portable computer used, for example, to diagnose the electronic system of vehicle C during inspection or vehicle inspection. The diagnostic device 40 can be directly connected to the electronic device 20 of vehicle C via a vehicle diagnostic port (e.g., OBD (On Board Diagnostics)-II). This is an example of a relay device that can be directly connected to the electronic device 20. The connection between the diagnostic device 40 and the electronic device 20 may be made by wire or by direct short-range wireless communication. Short-range wireless communication technologies such as NFC (Near Field Communication), Bluetooth (registered trademark), or UWB (Ultra Wide Band) can be used.

[0025] The data management server device 10 and the diagnostic device 40 are connected via a local area network or the like. Alternatively, the diagnostic device 40 may be connected to network 3 to send and receive data with the data management server device 10. The diagnostic device 40 may be provided for each business location that inspects vehicle C, or for each repair technician.

[0026] Next, we will describe an example of the data management server device 10's configuration. Figure 2 shows an example of the data management server device 10's configuration. Figure 3 shows an example of the database of the data management server device 10.

[0027] As shown in Figure 2, the data management server device 10 comprises a communication unit 11, a storage unit 12, a display unit 13, an operation unit 14, a system control unit 15, and an input / output interface unit 16. The system control unit 15 and the input / output interface unit 16 are connected via a system bus 17.

[0028] The communication unit 11 connects to the network 3 to control the communication status with the vehicle server device 30, etc., and connects to the local area network to send and receive data with the diagnostic device 40, etc.

[0029] The storage unit 12 is composed of, for example, a hard disk drive, a solid-state drive, etc. As shown in Figure 3, the storage unit 12 has a database in which the vehicle ID assigned to each vehicle C, the certificate ID of the electronic certificate, and the expiration date of the electronic certificate are associated. The digital certificate, which is an electronic certificate, includes the public key, the identification name of the owner of the private key corresponding to the public key, and information of the certification authority. The vehicle ID may also be the electronic device ID assigned to the electronic device 20. Furthermore, the vehicle ID and the electronic device ID are stored in association in the storage unit 12.

[0030] Furthermore, the storage unit 12 stores data IDs that identify data and applications that need updating, version information of data and applications contained in the electronic device 20, the latest version information, and is associated with the electronic device ID or vehicle ID. The storage unit 12 also stores information (private key, public key, etc.) of the digital signature to be attached to the data to be changed. In addition, the storage unit 12 stores information regarding commands that can be executed in each electronic device 20, associated with the electronic device ID or vehicle ID.

[0031] The storage unit 12 stores the operating system and applications. The applications include mutual authentication processing programs, etc. The storage unit 12 also stores authentication data (for example, a key set including a secure channel encryption key, a secure channel MAC key, and a data encryption key) used for mutual authentication processing to establish a secure channel with the vehicle server device 30, the diagnostic device 40, etc.

[0032] The storage unit 12 stores information associated with the vehicle ID or electronic device ID, indicating whether the electronic device 20 of vehicle C has the function to connect to network 3. The storage unit 12 also stores the network address of the electronic device 20 for connection via network 3, associated with the vehicle ID or electronic device ID.

[0033] The display unit 13 is composed of, for example, a liquid crystal display element or an organic EL (Electro-Luminescence) element. The operation unit 14 is composed of, for example, a keyboard and a mouse.

[0034] The system control unit 15 includes, for example, a CPU (Central Processing Unit), RAM (Random Access Memory), and ROM (Read Only Memory). The system control unit 15's CPU reads and executes various programs stored in the ROM, RAM, and storage unit 12. For example, the system control unit 15 performs mutual authentication processing to establish a secure session between the electronic device 20 and the vehicle server device 30 according to the mutual authentication processing program. After authentication, the system control unit 15 transmits change data, etc., to the electronic device 20 or the vehicle server device 30. The data management server device 10 functions as a computer, and the system control unit 15 performs various calculations and processing according to the program.

[0035] The input / output interface unit 16 is the interface between the communication unit 11 and the storage unit 12, etc., and the system control unit 15.

[0036] Next, an example of the general configuration of the electronic device 20 will be described. Figure 4 is a diagram showing an example of the general configuration of the electronic device 20. As shown in Figure 4, the electronic device 20 is configured to include a communication unit 21, a storage unit 22, a control unit 23, and the like.

[0037] The communication unit 21 communicates with the vehicle server device 30 via the wireless base station 5 and the network 3. The communication unit 21 may have an antenna for communicating with the wireless base station 5, or it may communicate with the wireless base station 5 via equipment capable of wireless communication with the wireless base station 5.

[0038] The storage unit 22 is, for example, nonvolatile memory (NVM). The storage unit 12 stores data such as digital certificates and control data for the ECU. The storage unit 12 also stores the operating system (OS) and applications. The applications include mutual authentication processing programs, etc.

[0039] Furthermore, the storage unit 22 stores authentication data used for mutual authentication processing to establish a secure channel, associated with the key device. This authentication data is, for example, a key set including a secure channel encryption key, a secure channel MAC (Message Authentication Code) key, and a data encryption key. The storage unit 22 also stores information (public key, private key, etc.) of the digital signature attached to the data to be modified.

[0040] The control unit 23 is comprised of a CPU, RAM, ROM, etc. The control unit 23 performs authentication with the vehicle server device 30, the diagnostic device 40, etc., according to the mutual authentication processing program. After authentication, the control unit 23 receives and executes data update commands to update data such as electronic certificates.

[0041] Next, we will describe an example of the vehicle server device 30's configuration. Figure 5 shows an example of the vehicle server device 30's configuration.

[0042] As shown in Figure 5, the vehicle server device 30, an example of a computer, comprises a communication unit 31, a storage unit 32, a display unit 33, an operation unit 34, a system control unit 35, and an input / output interface unit 36. The system control unit 35 and the input / output interface unit 36 ​​are connected via a system bus 37. Note that these configurations are almost the same as those of the communication unit 11, storage unit 12, etc. in the data management server device 10, so their explanation is omitted. The same applies to the example of the general configuration of the diagnostic device 40 described below.

[0043] The system control unit 35 performs authentication with the electronic device 20 according to the mutual authentication processing program stored in the storage unit 32. After authenticating the electronic device 20, it sends data update commands, etc., to the electronic device 20.

[0044] Next, we will describe an example of the general configuration of the diagnostic device 40. Figure 6 is a diagram showing an example of the general configuration of the diagnostic device 40.

[0045] As shown in Figure 6, a diagnostic device 40, an example of a computer, comprises a communication unit 41, a storage unit 42, a display unit 43, an operation unit 44, a system control unit 45, and an input / output interface unit 46. The system control unit 45 and the input / output interface unit 46 are connected via a system bus 47.

[0046] The communication unit 41 connects to a local area network or the like to control the communication status with the data management server device 10, etc. The communication unit 41 also connects to the vehicle diagnostic port of vehicle C to control the communication status of the electronic devices 20 of vehicle C. The communication unit 41 may also have short-range wireless communication capabilities to control the communication status of the electronic devices 20 of vehicle C.

[0047] The memory unit 42 stores data update commands and the like for the electronic device 20. The system control unit 45 authenticates with the electronic device 20 according to the mutual authentication processing program stored in the memory unit 42. After authenticating the electronic device 20, it sends data update commands and the like to the electronic device 20.

[0048] [2. Operation of Data Change System S] Next, the operation of the data modification system S will be explained using diagrams. The operation of the data modification system S will be explained using the updating of an electronic certificate, which is an example of data to be modified in the electronic device 20, as an example.

[0049] (2.1 Operation of the data management server device 10) First, the operation of the data management server device 10 will be explained. Figure 7 is a flowchart showing an example of the operation of the data management server device 10. Figure 8 is a schematic diagram showing an example of the flow of a data set for modification in the data modification system S.

[0050] As shown in Figure 7, the data management server device 10 determines whether or not the electronic certificate has expired (step S1). Specifically, the system control unit 15 refers to the database in the storage unit 12 and compares the expiration information of the electronic certificates for each electronic device 20 of each vehicle C with the current date to determine whether or not the electronic certificate has expired or is about to expire. The system control unit 15 extracts the electronic device ID or vehicle ID of the electronic device 20 whose electronic certificate has expired or is about to expire. In this way, the data management server device 10 functions as an example of a determination means for determining whether or not to change the data of an electronic device.

[0051] If the digital certificate has not expired (Step S1: NO), the data management server device 10 terminates the process.

[0052] If the digital certificate has expired (Step S1: YES), the data management server device 10 generates a change dataset (Step S2). Specifically, the system control unit 15 extracts the certificate ID by referring to the database in the storage unit 12 based on the electronic device ID or vehicle ID. Based on the extracted certificate ID, the system control unit 15 extracts the corresponding digital certificate information and generates a change dataset to update the digital certificate information. The change dataset is an example of change data for modifying data. The generated change dataset may consist only of change data, only of data modification commands executed by the electronic device 20, or a combination of these data modification commands and change data. The command executed by the electronic device 20, which is an example of a command for modifying data, may be a single command or a command set consisting of multiple commands.

[0053] Next, the data management server device 10 signs the change dataset (step S3). Specifically, the system control unit 15 obtains the private key for the digital signature by referring to the database in the storage unit 12. The system control unit 15 applies the private key to the hash value of the change dataset using a predetermined hash function to generate a digital signature, attaches it to the change dataset, and generates a change dataset with a digital signature. This digital signature is created using the private key of the Certification Authority (CA) corresponding to the public key of the Certification Authority installed in the electronic device 20 of vehicle C. Note that this CA key set does not have to be dedicated to data modification; for example, one used for network communication authentication with the data management server device 10 may be reused. Also, the digital signature may be generated and attached for each command. This makes it possible to verify on a command-by-command basis.

[0054] Thus, the data management server device 10 functions as an example of a means for attaching an electronic signature to modified data when modifying data in an electronic device installed on a mobile device.

[0055] Next, the data management server device 10 determines whether network communication is possible (step S4). Specifically, the system control unit 15, based on the vehicle ID, refers to the storage unit 12 to determine whether vehicle C has the function to connect to network 3. The system control unit 15 may also determine whether communication with vehicle C corresponding to the vehicle ID is currently possible via the vehicle server device 30. In this way, the data management server device 10 functions as an example of a determination means for determining whether an electronic device can connect to a network.

[0056] If network communication is possible (Step S4: YES), the data management server device 10 sends the change dataset to the vehicle server device 30 (Step S5). After mutual authentication with the vehicle server device 30 and establishing a secure channel, the system control unit 15 sends the change dataset, with an electronic signature attached, along with the electronic device ID or vehicle ID to identify the target electronic device 20, to the vehicle server device 30, as shown in Figure 8. The system control unit 15 also sends to the vehicle server device 30 information for establishing a secure channel with the target electronic device 20, the network address of the electronic device 20, etc.

[0057] Furthermore, after the vehicle server device 30 receives the update data for a specific electronic device 20, it may determine whether or not it can be transmitted to the electronic device 20. The vehicle server device 30 determines whether or not network communication is possible, and if it is possible, it sends the change data set with an electronic signature attached to the electronic device 20; otherwise, it notifies the data management server device 10 that it is not possible. Alternatively, the data management server device 10 may send the change data set with the signature attached to the electronic device 20 to the electronic device 20 without going through the vehicle server device 30.

[0058] If network communication is not possible (Step S4: NO), the data management server device 10 sends the change dataset to the diagnostic device 40 (Step S6). After mutual authentication with the diagnostic device 40 and establishing a secure channel, the system control unit 15 sends the signed change dataset, along with the electronic device ID or vehicle ID to identify the target electronic device 20, to the diagnostic device 40, as shown in Figure 8. The system control unit 15 also sends information to the diagnostic device 40 for establishing a secure channel with the target electronic device 20, as well as expiration information. In this way, the data management server device 10 functions as an example of a transmission means that sends the electronically signed change data to a relay device that can directly connect to the electronic device when the electronic device cannot connect to the network.

[0059] (2.2 Operation of the vehicle server device 30 or the diagnostic device 40) Next, we will describe the operation of the vehicle server device 30 or the diagnostic device 40 in sending a change data set to the target electronic device 20. Figure 9 is a flowchart showing an example of the operation of the vehicle server device 30 or the diagnostic device 40. Note that the operation of sending a change data set to the target electronic device 20 is basically the same for both the vehicle server device 30 and the diagnostic device 40, so we will mainly describe the diagnostic device 40 here.

[0060] First, the diagnostic device 40 connects to a local area network or the like in order to connect with the data management server device 10.

[0061] As shown in Figure 9, the diagnostic device 40 determines whether or not it has received a change data set (step S10). Specifically, in step S6, the system control unit 45 performs mutual authentication with the data management server device 10 and establishes a secure channel, and then determines whether or not it has received a change data set from the data management server device 10.

[0062] Next, the system control unit 45 stores in the storage unit 42 a modified dataset with an attached digital signature, associated with the electronic device ID or vehicle ID of the target electronic device 20, and information on the key for establishing a secure channel with the target electronic device 20. In the case of a vehicle server device 30, the system control unit 35 stores in the storage unit 32 a modified dataset with an attached signature, associated with the electronic device ID or vehicle ID of the target electronic device 20, information on the key for establishing a secure channel with the target electronic device 20, and the network address of the electronic device 20.

[0063] If the change dataset has not been received (step S10: NO), the diagnostic device 40 terminates the process.

[0064] Next, the diagnostic device 40 determines whether or not it has connected to the electronic device 20 (step S11). The diagnostic device 40 is directly connected to the vehicle diagnostic port of vehicle C, which has been brought in for inspection such as a vehicle inspection. The system control unit 45 determines whether or not communication has been established with the electronic device 20 of vehicle C. Note that the diagnostic device 40 and the electronic device 20 may be directly connected by wire or by short-range wireless communication. In the case of the vehicle server device 30, the system control unit 35 attempts to connect via the network 3 and determines whether or not communication has been established with the electronic device 20 of vehicle C.

[0065] If not connected (Step S11: NO), the diagnostic device 40 waits for a connection to the electronic device 20.

[0066] If a connection is established (Step S11: YES), the diagnostic device 40 transmits the change dataset to the electronic device 20 of the target vehicle C (Step S12). Specifically, the system control unit 45 performs mutual authentication with the electronic device 20 of vehicle C, establishes a secure channel, and then transmits the change dataset with an attached electronic signature to the diagnostic device 40, as shown in Figure 8. In the case of a connection in a location with little risk of information leakage, the mutual authentication process may be omitted. In the case of the vehicle server device 30, the system control unit 35 transmits the change dataset to the electronic device 20 of the target vehicle C via the network 3.

[0067] (2.3 Operation of Electronic Device 20) Next, we will explain the operation of updating data in the electronic device 20. Figure 10 is a flowchart showing an example of the operation of the electronic device 20. Note that the operation of updating data in the electronic device 20 is basically the same when a change data set is received from the vehicle server device 30 or the diagnostic device 40, so we will mainly explain the case when a change data set is received from the diagnostic device 40.

[0068] As shown in Figure 10, the electronic device 20 determines whether or not it has received the change data set (step S20). Specifically, in step S12, the control unit 23 performs mutual authentication with the diagnostic device 40 and establishes a secure channel, and then determines whether or not it has received the change data set with an electronic signature attached from the data management server device 10.

[0069] If the change data set is not received (step S20: NO), the electronic device 20 terminates processing. For example, in this case, the electronic device 20 may send information to the diagnostic device 40 indicating that the change data set was not received, and the diagnostic device 40 may display this information on the display unit 43.

[0070] If the modification dataset is received (step S20: YES), the electronic device 20 determines whether the signature verification was successful (step S21). Specifically, the control unit 23 separates the digital signature from the modification dataset. The control unit 23 decrypts the digital signature using a CA public key that it has previously held. The control unit 23 compares the hash value of the modification dataset with the decrypted digital signature, and if they match, it determines that the signature verification was successful.

[0071] If signature verification fails (step S21: NO), the electronic device 20 terminates the process. For example, in this case, the electronic device 20 may send information to the diagnostic device 40 indicating that signature verification failed, and the diagnostic device 40 may display this information on the display unit 43.

[0072] If signature verification is successful (step S21: YES), the electronic device 20 executes a command to update the electronic certificate and updates the electronic certificate (step S22). Specifically, the control unit 23 executes a command to update the electronic certificate in the modification dataset and updates the data of the electronic certificate stored in the storage unit 22. By executing the command set, the control unit 23 modifies the key information contained in the electronic certificate. Note that the update command itself may contain information such as the key of the electronic certificate to be updated, or it may be included separately in the modification dataset.

[0073] If the data change involves updating a program or application, the change dataset may include the latest version of the program, etc., and a command set to initiate the program update process. If the data change involves a large amount of data, such as map data, the change dataset may consist only of a command set to initiate the map data update process, and the map data may be downloaded separately from the diagnostic device 40.

[0074] As described above, according to the above embodiment, when changing data such as an electronic certificate in the electronic device 20 installed in vehicle C, an electronic signature is attached to the change data for changing the data, it is determined whether the electronic device 20 can connect to the network 3, and if the electronic device 20 cannot connect to the network 3, the electronically signed change data is sent to the diagnostic device 40 which can be directly connected to the electronic device 20. Therefore, even if real-time communication is not possible, the diagnostic device 40 directly connected to the electronic device 20 can send the electronically signed change data, and after verifying the electronic signature, the data in the electronic device 20 can be securely changed based on the change data.

[0075] If the system also includes a determination means for determining whether or not to change the data of an electronic device, it is possible to identify only the electronic devices 20 that need to be changed and centrally manage data changes such as updating electronic certificates for each electronic device 20.

[0076] If the data to be modified is a command executed in an electronic device and includes a command to modify the data, the data in the electronic device 20 can be securely modified based on the command to modify the data after the electronic signature has been verified.

[0077] When an electronic signature is used to verify the changed data in the electronic device 20, unauthorized data tampering can be prevented in the electronic device 20. [Explanation of Symbols]

[0078] 3 Network 10. Data management server device (server device) 20 Electronic equipment 40 Diagnostic equipment (relay device)

Claims

1. When modifying data in an electronic device installed on a mobile device, a means for attaching an electronic signature to the modified data used to modify the data, Connection determination means for determining whether the electronic device has the function to connect to a network, If the electronic device does not have the ability to connect to the network, a transmission means for transmitting the modified data to which the electronic signature has been attached to a relay device that can be directly connected to the electronic device, Equipped with, A server device characterized in that the modified data is a command executed in the electronic device, and includes a command for modifying the data.

2. In the server device described in claim 1, A server device further comprising a change determination means for determining whether or not to change the data of the aforementioned electronic device.

3. In the server device according to claim 1 or claim 2, A server device characterized in that the connection determination means determines whether or not the electronic device has the function to connect to the network by referring to a storage means that stores information on whether or not the electronic device has the function to connect to the network.

4. In the server device according to claim 1 or claim 2, A server device characterized in that the electronic signature is used to verify the modified data in the electronic device.

5. The granting means, when modifying data of an electronic device installed on a mobile body, includes a granting step of granting an electronic signature to the modified data for modifying the data, Connection determination means includes a connection determination step of determining whether the electronic device has the function to connect to a network, If the electronic device does not have a function to connect to the network, the transmission means includes a transmission step of transmitting the modified data to a relay device that can be directly connected to the electronic device, with the electronic signature attached. Includes, A data modification method characterized in that the modified data is a command executed in the electronic device, and includes a command for modifying the data.

6. Computers, When modifying data in an electronic device installed on a mobile device, a means for attaching an electronic signature to the modified data used to modify the data, Connection determination means for determining whether the electronic device has the function to connect to a network, and If the electronic device does not have a function to connect to the network, it will function as a transmission means to transmit the modified data to which the electronic signature has been attached to a relay device that can be directly connected to the electronic device. A program characterized in that the modified data is a command executed in the electronic device, and includes a command for modifying the data.

7. A data modification system comprising an electronic device installed on a mobile body, a server device that manages changes to the data of the electronic device, and a relay device that can be directly connected to the electronic device, The aforementioned server device When modifying the data of the aforementioned electronic device, the means for attaching an electronic signature to the modified data for modifying the aforementioned data, Connection determination means for determining whether the electronic device has the function to connect to a network, If the electronic device does not have a function to connect to the network, a transmission means for transmitting the modified data to the relay device with the electronic signature attached, It has, A data modification system characterized in that the modified data is a command executed in the electronic device, and includes a command for modifying the data.

Citation Information

Patent Citations

  • Communication system

    JP2009075703A

  • Communication control method, communication controller, communication control program and terminal device

    JP2010287934A

  • Automatic fraudulent digital certificate detection

    JP2019013009A

  • Program and communication system

    JP2019185524A

  • Authentication system

    JP2021050556A