Relay device, vehicle communication method, and vehicle communication program
The relay device and communication method improve in-vehicle network security by dynamically updating authentication information and prioritizing secure communication, addressing challenges with new units and environmental interference.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- SUMITOMO ELECTRIC INDUSTRIES LTD
- Filing Date
- 2025-03-03
- Publication Date
- 2026-04-21
AI Technical Summary
Existing in-vehicle network systems lack effective security measures to ensure reliable communication and authentication of new functional units added to the network, especially in challenging driving environments where communication with external devices is poor.
A relay device and communication method that acquires and updates authentication information for functional units from external devices, performs authentication processing, and relays information based on authentication results, with the ability to extend authentication validity and prioritize secure communication based on functional unit type and information importance.
Enhances security and stability of in-vehicle networks by ensuring secure communication with new units and maintaining network integrity even in poor communication environments, preventing authentication errors during vehicle operation.
Smart Images

Figure 0007848911000001 
Figure 0007848911000002 
Figure 0007848911000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a relay device and a vehicle communication method. This application claims priority based on Japanese Patent Application No. 2019-126255 filed on Jul. 5, 2019, and incorporates all of the disclosure thereof herein.
Background Art
[0002] Patent Document 1 (Japanese Patent Application Laid-Open No. 2013-193598) discloses a vehicle authentication device as follows. That is, the vehicle authentication device is mounted on a vehicle and is a vehicle authentication device (11) provided in an electronic control device (1) connected via an in-vehicle network to an in-vehicle communication device (2) that can communicate at least wirelessly with an external device (3) outside the vehicle using the Internet protocol. When information including identification information for identifying the external device is transmitted from the external device to the communication device, identification information acquisition means (11, S1) for acquiring the identification information; state determination means (11, S5) for determining whether or not the state of the vehicle corresponds to a security ensured state indicating that a regular user permitted to operate the vehicle has operated or has operated on the vehicle; registration means (11, S7) for registering the identification information acquired by the identification information acquisition means in a storage device (12) mounted on the vehicle when it is determined by the state determination means that the security ensured state is satisfied, and not registering the identification information in the storage device when it is determined that the security ensured state is not satisfied; registration determination means (11, S2) for determining whether or not the identification information is registered in the storage device when the identification information acquisition means acquires the identification information; and authentication means (11, S3, S6) for permitting information exchange between the external device specified by the identification information and the electronic control device when it is determined by the registration determination means that the identification information is registered in the storage device, and prohibiting information exchange between the external device specified by the identification information and the electronic control device based on the determination by the registration determination means that the identification information is not registered in the storage device.
Prior Art Documents
[0003] [Patent Document 1] Japanese Patent Publication No. 2013-193598 [Overview of the project]
[0004] The relay device of this disclosure is a relay device mounted on a vehicle having a plurality of functional units, comprising: an authentication processing unit that acquires authentication information for the functional units from an external device outside the vehicle and performs authentication processing for the functional units using the acquired authentication information; and a relay processing unit that relays information between the functional unit and other functional units based on the result of the authentication processing by the authentication processing unit, wherein the authentication processing unit acquires new authentication information from the external device when the validity period of the authentication information expires.
[0005] The vehicle communication method of this disclosure is a vehicle communication method in a relay device mounted on a vehicle having a plurality of functional units, and includes the steps of: obtaining authentication information for the functional units from an external device outside the vehicle; performing authentication processing for the functional units using the obtained authentication information; relaying information between the functional unit and other functional units based on the result of the authentication processing; and obtaining new authentication information from the external device when the validity period of the authentication information has expired.
[0006] One aspect of this disclosure may be implemented as a semiconductor integrated circuit that implements part or all of a relay device, or as a system including a relay device. Another aspect of this disclosure may be implemented as a program that causes a computer to execute processing steps in the relay device. [Brief explanation of the drawing]
[0007] [Figure 1] Figure 1 is a diagram showing the configuration of a communication system according to an embodiment of the present disclosure. [Figure 2] Figure 2 shows the configuration of an in-vehicle communication system according to an embodiment of the present invention. [Figure 3] Figure 3 is a diagram showing the configuration of an in-vehicle ECU according to an embodiment of the present disclosure. [Figure 4] Figure 4 is a diagram showing the configuration of a relay device according to an embodiment of the present disclosure. [Figure 5] Figure 5 is a flowchart that defines the operating procedure of a relay device in a communication system according to an embodiment of the present disclosure when relaying information between in-vehicle ECUs based on the results of an authentication process. [Figure 6] Figure 6 shows an example of the sequence of external authentication processing in a communication system according to an embodiment of the present disclosure. [Figure 7] Figure 7 shows an example of the sequences of external and internal authentication processing in a communication system according to an embodiment of the present disclosure. [Figure 8] Figure 8 shows an example of the sequence of in-vehicle authentication processing in a communication system according to an embodiment of the present disclosure. [Figure 9] Figure 9 shows another example of the sequences of external and internal authentication processing in a communication system according to an embodiment of the present disclosure. [Modes for carrying out the invention]
[0008] Conventionally, in-vehicle network systems have been developed to improve security in in-vehicle networks.
[0009] [Issues this disclosure aims to address] Beyond the technology described in Patent Document 1, there is a need for technology that can improve security in in-vehicle networks.
[0010] This disclosure was made to solve the aforementioned problems, and its purpose is to provide a relay device and a vehicle communication method that can improve security in an in-vehicle network.
[0011] [Effects of this disclosure] According to this disclosure, security in in-vehicle networks can be improved.
[0012] [Description of Embodiments in this Disclosure] First, the embodiments of this disclosure will be listed and explained.
[0013] (1) The relay device according to the embodiment of the present disclosure is a relay device mounted on a vehicle having a plurality of functional units, comprising: an authentication processing unit that acquires authentication information for the functional units from an external device outside the vehicle and performs authentication processing for the functional units using the acquired authentication information; and a relay processing unit that relays information between the functional unit and other functional units based on the result of the authentication processing by the authentication processing unit, wherein the authentication processing unit acquires new authentication information from the external device when the validity period of the authentication information expires.
[0014] In this configuration, authentication information for functional units is obtained from an external device outside the vehicle. This ensures that authentication information for a new, unknown functional unit can be obtained even when it is added to the in-vehicle network. Furthermore, by obtaining new authentication information when the previous information expires, performing authentication processing for the functional unit using the obtained authentication information, and relaying information between functional units based on the results of the authentication processing, the security of the in-vehicle network can be guaranteed. Moreover, even in situations where the communication environment between the relay device and the external device is poor due to the vehicle's driving environment, making it difficult to obtain new authentication information from the external device, authentication processing for the functional unit can continue using the authentication information. Therefore, security in the in-vehicle network can be improved.
[0015] (2) Preferably, if the validity period of the authentication information has expired and the relay device is unable to communicate with the external device, the authentication processing unit performs an extension process to maintain the validity of the authentication information, and uses the extended authentication information, which is the authentication information whose validity has been maintained, to perform the authentication processing of the functional unit corresponding to the authentication information.
[0016] With such a configuration, when the expiration date of the authentication information has passed and the communication environment between the relay device and the external device is poor due to the driving environment of the vehicle and it is impossible to obtain new authentication information, authentication processing can be performed and the relay of information between functional units based on the authentication result can be continued. Thereby, for example, in a configuration in which security is improved by updating the content of the authentication information outside the vehicle, stable communication in the in-vehicle network can be managed regardless of the driving environment of the vehicle.
[0017] (3) Preferably, when the authentication process using the extended authentication information by the authentication processing unit is successful, the relay processing unit determines the content of the information to be relayed according to the type of the functional unit.
[0018] With such a configuration, since a part of the information to be relayed when the extension process is performed can be restricted according to the type of the functional unit, for example, while continuing the relay of information between functional units that affect the driving of the vehicle, by stopping the relay of information between functional units that do not affect the driving of the vehicle, it is possible to suppress a decrease in security in the in-vehicle network while maintaining good driving of the vehicle.
[0019] (4) Preferably, when the authentication process using the extended authentication information by the authentication processing unit is successful, the relay processing unit determines whether to perform relay according to the type of the information received from the functional unit.
[0020] With such a configuration, since a part of the information to be relayed when the extension process is performed can be restricted according to the type of the information received from the functional unit, for example, while continuing the relay of information that affects the driving of the vehicle, by stopping the relay of information that does not affect the driving of the vehicle, it is possible to suppress a decrease in security in the in-vehicle network while maintaining good driving of the vehicle.
[0021] (5) Preferably, the authentication processing unit obtains the authentication information having different contents from the external device each time the authentication information is obtained.
[0022] This configuration allows for the acquisition of new authentication information each time the previous one expires, and enables the authentication process of the functional unit to be performed using this new authentication information, thereby further improving security in the in-vehicle network.
[0023] (6) Preferably, if the vehicle is in motion and communication between the relay device and the external device is possible and the validity period of the authentication information has expired, the authentication processing unit performs an extension process to maintain the validity of the authentication information without acquiring new authentication information from the external device.
[0024] This configuration prevents, for example, authentication errors caused by using new authentication information during the authentication process, which could interrupt the relay of some or all of the information between functional parts while the vehicle is in motion, thus maintaining the smooth operation of the vehicle.
[0025] (7) A vehicle communication method according to an embodiment of the present disclosure is a vehicle communication method in a relay device mounted on a vehicle having a plurality of functional units, comprising the steps of: obtaining authentication information for the functional units from an external device outside the vehicle; performing authentication processing for the functional units using the acquired authentication information; relaying information between the functional unit and other functional units based on the result of the authentication processing; and obtaining new authentication information from the external device when the validity period of the authentication information has expired.
[0026] In this way, by obtaining authentication information for a functional unit from an external device outside the vehicle, authentication information for a new, unknown functional unit can be obtained even when it is added to the in-vehicle network. Furthermore, by obtaining new authentication information when the previous information expires, performing authentication processing for the functional unit using the obtained authentication information, and relaying information between functional units based on the results of the authentication processing, the security of the in-vehicle network can be guaranteed. Moreover, even in situations where the communication environment between the relay device and the external device is poor due to the vehicle's driving environment, making it difficult to obtain new authentication information from the external device, authentication processing for the functional unit can continue using the authentication information. Therefore, security in the in-vehicle network can be improved.
[0027] Embodiments of this disclosure will be described below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals, and their descriptions will not be repeated. Furthermore, at least some of the embodiments described below may be combined in any way.
[0028] [Communication System] Figure 1 is a diagram showing the configuration of a communication system according to an embodiment of the present disclosure.
[0029] Referring to Figure 1, the communication system 401 comprises a server 181 and an in-vehicle communication system 301. The in-vehicle communication system 301 is mounted on vehicle 1.
[0030] Figure 2 shows the configuration of an in-vehicle communication system according to an embodiment of the present invention.
[0031] Referring to Figure 2, the in-vehicle communication system 301 comprises in-vehicle ECUs (Electronic Control Units) 200A to 200D and a relay device 100.
[0032] Hereinafter, each of the in-vehicle ECUs 200A to 200D will also be referred to as in-vehicle ECU 200. The in-vehicle ECU 200 and relay device 100 are examples of in-vehicle equipment.
[0033] Furthermore, the in-vehicle communication system 301 is not limited to a configuration with four in-vehicle ECUs 200, but may also be configured with three or fewer, or five or more, in-vehicle ECUs 200. Also, the in-vehicle communication system 301 is not limited to a configuration with one relay device 100, but may also be configured with two or more relay devices 100.
[0034] The in-vehicle ECU 200 and relay device 100 constitute the in-vehicle network 12. The in-vehicle ECU 200 is an example of a functional unit in the in-vehicle network 12.
[0035] In the in-vehicle network 12, the in-vehicle ECU 200 is connected to a relay device 100, for example, via an Ethernet® cable 13.
[0036] The relay device 100 is, for example, a switch device capable of relaying information between multiple in-vehicle ECUs 200 connected to it. More specifically, the relay device 100 can perform relay processing according to, for example, Layer 2 and Layer 3, which is higher than Layer 2.
[0037] The in-vehicle ECU200A is, for example, a TCU (Telematics Communication Unit). Hereafter, the in-vehicle ECU200A will also be referred to as TCU200A.
[0038] Vehicle ECUs 200B to 200D include, for example, autonomous driving ECUs (Electronic Control Units), sensors, navigation systems, accelerator control ECUs, brake control ECUs, steering control ECUs, and human-machine interfaces.
[0039] For example, the in-vehicle ECU 200D is not connected to the relay device 100 in its initial state. The in-vehicle ECU 200D is installed in vehicle 1 at, for example, the manufacturing plant of vehicle 1, the dealer of vehicle 1, or the aftermarket parts store for vehicle 1, and is connected to the relay device 100 via an Ethernet cable.
[0040] The relay device 100 performs relay processing of Ethernet frames in accordance with the Ethernet communication standard. Specifically, the relay device 100 relays, for example, Ethernet frames exchanged between in-vehicle ECUs 200. The Ethernet frame contains IP packets.
[0041] Furthermore, the in-vehicle communication system 301 is not limited to a configuration in which Ethernet frames are relayed according to the Ethernet communication standard, but may also be configured in which data is relayed according to communication standards such as CAN (Controller Area Network) (registered trademark), FlexRay (registered trademark), MOST (Media Oriented Systems Transport) (registered trademark), and LIN (Local Interconnect Network).
[0042] Referring to Figures 1 and 2, the TCU200A can communicate with a server 181 located outside of vehicle 1. More specifically, the TCU200A can communicate with the server 181 via a wireless base station device 161 using IP packets, for example.
[0043] More specifically, the TCU200A can communicate wirelessly with a wireless base station device 161 outside the vehicle 1, for example, in accordance with communication standards such as LTE (Long Term Evolution) or 3G.
[0044] Specifically, when the wireless base station device 161 receives an IP packet from a server 181 outside the vehicle 1 via the external network 11, it includes the received IP packet in a wireless signal and transmits it to the TCU 200A.
[0045] For example, when the TCU200A receives a radio signal containing an IP packet from server 181 via radio base station equipment 161, it retrieves the IP packet from the received radio signal, stores the retrieved IP packet in an Ethernet frame, and transmits it to relay equipment 100.
[0046] Furthermore, when the TCU200A receives an Ethernet frame from the relay device 100, it obtains an IP packet from the received Ethernet frame, includes the obtained IP packet in the wireless signal, and transmits it to the wireless base station device 161.
[0047] When the wireless base station device 161 receives a wireless signal from the TCU200A, it obtains an IP packet from the received wireless signal and transmits the obtained IP packet to the server 181 via the external network 11.
[0048] [In-vehicle ECU] Figure 3 is a diagram showing the configuration of an in-vehicle ECU according to an embodiment of the present disclosure.
[0049] Referring to Figure 3, the in-vehicle ECU 200 comprises a communication unit 210, a processing unit 220, an authentication request unit 230, and a storage unit 240. The storage unit 240 is, for example, flash memory.
[0050] When the communication unit 210 receives an Ethernet frame from the relay device 100 via the corresponding Ethernet cable 13, it outputs the received Ethernet frame to the processing unit 220.
[0051] The processing unit 220 acquires information contained in the Ethernet frame received from the communication unit 210 and performs predetermined processing using the acquired information.
[0052] Furthermore, the processing unit 220 generates an Ethernet frame destined for another in-vehicle ECU 200 and outputs the generated Ethernet frame to the communication unit 210.
[0053] When the communication unit 210 receives an Ethernet frame from the processing unit 220, it transmits the received Ethernet frame to the relay device 100 via the corresponding Ethernet cable 13.
[0054] Furthermore, when the processing unit 220 obtains a common key (described later) from the Ethernet frame received from the communication unit 210, it outputs the obtained common key to the authentication request unit 230.
[0055] When the authentication request unit 230 receives a common key from the processing unit 220, it stores the received common key in the storage unit 240.
[0056] Furthermore, when its own in-vehicle ECU 200 is connected to the relay device 100 via the Ethernet cable 13, the authentication request unit 230 generates an Ethernet frame containing authentication request information, including its own ID, such as its MAC address, and transmits the generated Ethernet frame to the relay device 100 via the communication unit 210.
[0057] [Relay device] Figure 4 is a diagram showing the configuration of a relay device according to an embodiment of the present disclosure.
[0058] Referring to Figure 4, the relay device 100 includes communication ports 52A, 52B, 52C, and 52D, a communication unit 110, a relay processing unit 120, a detection unit 130, an authentication processing unit 140, a storage unit 150, and a timer 160. The storage unit 150 is, for example, flash memory.
[0059] For example, the relay device 100 is equipped with a number of timers 160 corresponding to the communication ports 52A, 52B, 52C, and 52D. Specifically, the relay device 100 is equipped with timers 160A, 160B, 160C, and 160D as timers 160.
[0060] Hereinafter, communication ports 52A, 52B, 52C, and 52D will also be referred to as communication port 52. Communication port 52 is, for example, a terminal to which an Ethernet cable can be connected.
[0061] In this example, communication ports 52A, 52B, and 52C are connected to TCU200A, in-vehicle ECU200B, and in-vehicle ECU200C, respectively.
[0062] When the communication unit 110 receives an Ethernet frame from a certain in-vehicle ECU 200 via the corresponding communication port 52, it outputs the received Ethernet frame to the relay processing unit 120.
[0063] Furthermore, when the communication unit 110 receives an Ethernet frame destined for a certain in-vehicle ECU 200 from the relay processing unit 120, it transmits the received Ethernet frame to the in-vehicle ECU 200 via the corresponding communication port 52.
[0064] The relay processing unit 120 performs relay processing of Ethernet frames between the in-vehicle ECUs 200. Specifically, when the relay processing unit 120 receives an Ethernet frame from the communication unit 110, for example, it performs Layer 2 relay processing and Layer 3 relay processing on the received Ethernet frame.
[0065] Furthermore, when the relay processing unit 120 receives an Ethernet frame containing authentication request information from the in-vehicle ECU 200 newly added to the in-vehicle network 12, it obtains the authentication request information from the received Ethernet frame and outputs the obtained authentication request information to the detection unit 130.
[0066] [Detection unit] The detection unit 130 detects newly added functional units to the in-vehicle network 12. For example, the detection unit 130 detects the in-vehicle ECU 200D, which has been newly added to the in-vehicle network 12, as a new functional unit.
[0067] Referring to Figures 2 and 4, the in-vehicle ECU 200D is connected to the communication port 52D of the relay device 100 via the Ethernet cable 13.
[0068] The detection unit 130 in the relay device 100 detects the addition of the in-vehicle ECU 200D to the in-vehicle network 12 by receiving authentication request information from the in-vehicle ECU 200D via the relay processing unit 120.
[0069] The detection unit 130 outputs the authentication request information received from the relay processing unit 120 to the authentication processing unit 140.
[0070] [Authentication Processing] The authentication processing unit 140 obtains authentication information for the in-vehicle ECU 200 from an external device located outside the vehicle 1.
[0071] More specifically, when the authentication processing unit 140 receives authentication request information from the detection unit 130, it obtains authentication information for the in-vehicle ECU 200D, which is the new functional unit indicated by the authentication request information, from the server 181, for example, in accordance with the procedure of IEEE802.1X.
[0072] Server 181 generates authentication information for the in-vehicle ECU 200 by performing authentication processing on the in-vehicle ECU 200 using an authentication protocol, for example, in accordance with the IEEE 802.1X procedure. Hereinafter, the authentication processing of the in-vehicle ECU 200 by Server 181 will also be referred to as the external authentication processing.
[0073] Here, the authentication methods used in the external authentication process by server 181 include, depending on the authentication protocol used for the authentication process, EAP (Extended Authentication Protocol)-MD (Message Digest algorithm) 5, EAP-TLS (Transport Layer Security), PEAP (Protected EAP), LEAP (Lightweight EAP), and EAP-TTLS (EAP-Tunneled Transport Layer Security).
[0074] For example, the storage unit 150 stores the authentication method used in the external authentication process performed by the server 181.
[0075] When the authentication processing unit 140 receives authentication request information from the detection unit 130, it obtains the authentication method for the external authentication processing performed by the server 181 from the storage unit 150, and transmits the authentication method information indicating the obtained authentication method to the in-vehicle ECU 200D, which is a new functional unit indicated by the authentication request information, via the relay processing unit 120 and the communication unit 110.
[0076] The in-vehicle ECU 200D and server 181 exchange EAP messages containing information necessary for external authentication processing via the relay device 100.
[0077] The authentication processing unit 140 in the relay device 100 relays EAP messages and the like exchanged between the server 181 and the in-vehicle ECU 200D.
[0078] More specifically, when the authentication processing unit 140 receives an Ethernet frame containing an EAP message from the in-vehicle ECU 200D via the communication unit 110 and the relay processing unit 120, it converts the received Ethernet frame into a RADIUS (Remote Authentication Dial In User Service) frame and sends the converted RADIUS frame to the server 181 via the communication unit 110 and the TCU 200A.
[0079] Furthermore, when the authentication processing unit 140 receives a RADIUS frame from the server 181 via the TCU 200A, the communication unit 110, and the relay processing unit 120, it converts the received RADIUS frame into an Ethernet frame and transmits the converted Ethernet frame to the in-vehicle ECU 200D via the communication unit 110.
[0080] Server 181 performs external authentication processing for the in-vehicle ECU 200D using EAP messages received from the in-vehicle ECU 200 via the relay device 100. When Server 181 successfully authenticates the in-vehicle ECU 200D through the external authentication processing, it generates authentication information indicating successful authentication and transmits the generated authentication information to the relay device 100 via the wireless base station device 161 and TCU 200A.
[0081] On the other hand, if the server 181 fails to authenticate the in-vehicle ECU 200D, it generates authentication information indicating the authentication failure and transmits the generated authentication information to the relay device 100 via the wireless base station device 161 and TCU 200A.
[0082] When the authentication processing unit 140 receives authentication information indicating successful authentication from the server 181 via the TCU 200A, communication unit 110, and relay processing unit 120, it generates external authentication success information indicating that the external authentication process was successful, and outputs the generated external authentication success information to the relay processing unit 120.
[0083] When the relay processing unit 120 receives external authentication success information from the authentication processing unit 140, it transmits the received external authentication success information to the in-vehicle ECU 200D via the communication unit 110.
[0084] Here, when the authentication processing unit 140 receives authentication information indicating successful authentication from the server 181 via the communication unit 110 and the relay processing unit 120, it sets the validity period of the authentication information in the timer 160 for each in-vehicle ECU 200.
[0085] For example, the authentication processing unit 140 sets the validity period of the authentication information of the TCU200A connected to communication port 52A in timer 160A, the validity period of the authentication information of the in-vehicle ECU200B connected to communication port 52A in timer 160B, the validity period of the authentication information of the in-vehicle ECU200C connected to communication port 52C in timer 160C, and the validity period of the authentication information of the in-vehicle ECU200D connected to communication port 52D in timer 160D.
[0086] On the other hand, when the authentication processing unit 140 receives authentication information indicating authentication failure from the server 181 via the TCU200A, communication unit 110, and relay processing unit 120, it outputs connection denied information to the relay processing unit 120.
[0087] When the relay processing unit 120 receives connection denial information from the authentication processing unit 140, it transmits the received connection denial information to the in-vehicle ECU 200D via the communication unit 110.
[0088] The authentication processing unit 140 performs authentication processing on the in-vehicle ECU 200 using authentication information indicating successful authentication obtained from the server 181. Hereinafter, the authentication processing of the in-vehicle ECU 200 by the authentication processing unit 140 will also be referred to as in-vehicle authentication processing.
[0089] The relay processing unit 120 relays information between the in-vehicle ECUs 200 based on the results of the in-vehicle authentication processing performed by the authentication processing unit 140.
[0090] (Authentication Example 1) For example, the authentication information that the authentication processing unit 140 receives from the server 181, indicating successful authentication, includes a shared key.
[0091] When the authentication processing unit 140 receives authentication information for the in-vehicle ECU 200 from the server 181 via the TCU 200A, communication unit 110, and relay processing unit 120, it sets a predetermined validity period for the received authentication information in the corresponding timer 160.
[0092] The authentication processing unit 140 then obtains a common key from the received authentication information and stores the obtained common key in the storage unit 150, associating it with the in-vehicle ECU 200. For example, the authentication processing unit 140 stores the obtained common key in the storage unit 150, associating it with the communication port 52.
[0093] Furthermore, the authentication processing unit 140 generates external authentication success information including the common key, and transmits the generated external authentication success information to the corresponding in-vehicle ECU 200 via the communication unit 110.
[0094] Referring again to Figure 3, when the authentication request unit 230 in the in-vehicle ECU 200 receives external authentication success information from the authentication processing unit 140 in the relay device 100 via the communication unit 210, it obtains a common key from the received external authentication success information and stores the obtained common key in the storage unit 240.
[0095] The authentication processing unit 140 in the relay device 100 performs in-vehicle authentication processing for each vehicle-mounted ECU 200, for example, periodically or irregularly, using a common key in the storage unit 150.
[0096] Specifically, the authentication processing unit 140 generates a random number, for example, and transmits the generated random number to the corresponding in-vehicle ECU 200 via the communication unit 110. The authentication processing unit 140 also generates encrypted data by encrypting the generated random number using a shared key.
[0097] When the authentication request unit 230 in the in-vehicle ECU 200 receives the random number, it generates encrypted data by encrypting the received random number using a common key in the storage unit 240. The in-vehicle ECU 200 then transmits the generated encrypted data to the relay device 100.
[0098] When the authentication processing unit 140 in the relay device 100 receives encrypted data from the in-vehicle ECU 200 via the communication unit 110, it compares the received encrypted data with the encrypted data it generated itself.
[0099] The authentication processing unit 140 determines that the in-vehicle authentication process of the in-vehicle ECU 200 has been successful if the encrypted data received from the in-vehicle ECU 200 matches the encrypted data it has generated. The authentication processing unit 140 then outputs in-vehicle authentication success information to the relay processing unit 120, indicating that the authentication of the in-vehicle ECU 200 has been successful.
[0100] When the relay processing unit 120 receives information indicating successful in-vehicle authentication from the authentication processing unit 140, it starts or continues relaying information between the in-vehicle ECU 200 and other in-vehicle ECUs 200.
[0101] More specifically, when the relay processing unit 120 receives successful in-vehicle authentication information from the authentication processing unit 140, it starts or continues relaying Ethernet frames between the in-vehicle ECU 200 and other in-vehicle ECUs 200.
[0102] On the other hand, if the authentication processing unit 140 finds that the encrypted data received from the in-vehicle ECU 200 does not match the encrypted data it has generated, it determines that the in-vehicle authentication process of the in-vehicle ECU 200 has failed. The authentication processing unit 140 then outputs in-vehicle authentication failure information to the relay processing unit 120, indicating that the authentication of the in-vehicle ECU 200 has failed.
[0103] When the relay processing unit 120 receives in-vehicle authentication failure information from the authentication processing unit 140, it stops relaying information between the in-vehicle ECU 200 and other in-vehicle ECUs 200.
[0104] More specifically, when the relay processing unit 120 receives in-vehicle authentication failure information from the authentication processing unit 140, it begins discarding Ethernet frames received from the in-vehicle ECU 200, as well as Ethernet frames addressed to the same in-vehicle ECU 200 that have been received from other in-vehicle ECUs 200.
[0105] Furthermore, if the in-vehicle authentication process for the vehicle-mounted ECU 200 fails, the authentication processing unit 140 obtains new authentication information for the vehicle-mounted ECU 200 from the server 181, for example, using a procedure that conforms to IEEE802.1X.
[0106] When the authentication processing unit 140 receives authentication information indicating successful authentication from the server 181 as new authentication information, it stores the common key included in the received authentication information in the storage unit 150 and sets a predetermined validity period for the new authentication information in the timer 160. The authentication processing unit 140 also transmits the common key to the in-vehicle ECU 200 via the relay processing unit 120 and the communication unit 110.
[0107] The authentication processing unit 140 then uses the shared key to perform the in-vehicle authentication process of the in-vehicle ECU 200 again. Specifically, the authentication processing unit 140 generates random numbers and encrypted data, transmits the generated encrypted data to the in-vehicle ECU 200, and compares the encrypted data received from the in-vehicle ECU 200 with the encrypted data it generated.
[0108] On the other hand, when the authentication processing unit 140 receives authentication information indicating authentication failure from the server 181 as new authentication information, it outputs connection denied information to the relay processing unit 120.
[0109] (Authentication Example 2) For example, the authentication information received by the authentication processing unit 140 from the server 181 includes the MAC address of the vehicle-mounted ECU 200 that has been authenticated by the server 181. Hereinafter, the MAC address of the authenticated vehicle-mounted ECU 200 will also be referred to as the authenticated MAC address.
[0110] When the authentication processing unit 140 receives authentication information for the in-vehicle ECU 200 from the server 181 via the TCU 200A, communication unit 110, and relay processing unit 120, it sets a predetermined validity period for the received authentication information in the corresponding timer 160.
[0111] The authentication processing unit 140 then obtains the authenticated MAC address from the received authentication information and stores the obtained authenticated MAC address in the storage unit 150, associating it with the in-vehicle ECU 200. For example, the authentication processing unit 140 stores the obtained authenticated MAC address in the storage unit 150, associating it with the communication port 52.
[0112] Furthermore, the authentication processing unit 140 transmits the successful external authentication information to the corresponding in-vehicle ECU 200 via the communication unit 110.
[0113] The authentication processing unit 140 performs authentication processing for each in-vehicle ECU 200, for example, periodically or irregularly, using the authenticated MAC addresses in the storage unit 150.
[0114] For example, the authentication processing unit 140 obtains the source MAC address included in the Ethernet frame received by the communication unit 110 from the corresponding in-vehicle ECU 200 via the communication port 52, and compares the obtained source MAC address with the authenticated MAC address associated with the communication port 52.
[0115] If the authentication processing unit 140 finds that the acquired source MAC address matches the authenticated MAC address, it outputs in-vehicle authentication success information to the relay processing unit 120, indicating that the authentication of the in-vehicle ECU 200 was successful.
[0116] When the relay processing unit 120 receives information indicating successful in-vehicle authentication from the authentication processing unit 140, it starts or continues relaying information between the in-vehicle ECU 200 and other in-vehicle ECUs 200.
[0117] On the other hand, if the acquired source MAC address does not match the authenticated MAC address, the authentication processing unit 140 outputs in-vehicle authentication failure information to the relay processing unit 120, indicating that authentication of the in-vehicle ECU 200 has failed.
[0118] When the relay processing unit 120 receives in-vehicle authentication failure information from the authentication processing unit 140, it starts discarding Ethernet frames received from the in-vehicle ECU 200, and Ethernet frames addressed to the same in-vehicle ECU 200 that have been received from other in-vehicle ECUs 200.
[0119] Furthermore, if the in-vehicle authentication process for the in-vehicle ECU 200 fails, the authentication processing unit 140 obtains new authentication information for the in-vehicle ECU 200 connected to the communication port 52 from the server 181, for example, using a procedure that conforms to IEEE802.1X.
[0120] When the authentication processing unit 140 receives authentication information indicating successful authentication from the server 181 as new authentication information, it stores the authenticated MAC address included in the received authentication information in the storage unit 150 and sets a predetermined validity period for the new authentication information in the timer 160.
[0121] Then, the authentication processing unit 140 performs the authentication process of the in-vehicle ECU 200 again using the authenticated MAC address. Specifically, the authentication processing unit 140 obtains the source MAC address included in the Ethernet frame received by the communication unit 110 via the communication port 52, and compares the obtained source MAC address with the authenticated MAC address associated with the communication port 52.
[0122] On the other hand, when the authentication processing unit 140 receives authentication information indicating authentication failure from the server 181 as new authentication information, it outputs connection denied information to the relay processing unit 120.
[0123] [Update authentication information] If the authentication information for a certain in-vehicle ECU 200 expires, the authentication processing unit 140 obtains new authentication information for that in-vehicle ECU 200 from the server 181.
[0124] More specifically, when the timer 160 of the corresponding in-vehicle ECU 200 expires, the authentication processing unit 140 discards the common key or authenticated MAC address in the storage unit 150.
[0125] The authentication processing unit 140 then obtains new authentication information for the in-vehicle ECU 200 from the server 181, for example, using a procedure that conforms to IEEE802.1X.
[0126] For example, each time server 181 performs an external authentication process and successfully authenticates, it generates authentication information with different content. More specifically, each time server 181 performs an external authentication process and successfully authenticates, it generates authentication information containing a different shared key.
[0127] In other words, the authentication processing unit 140 obtains authentication information from the server 181, which will have different content each time it is obtained. More specifically, the authentication processing unit 140 obtains authentication information from the server 181, the shared key of which is updated each time it is obtained.
[0128] When the authentication processing unit 140 receives new authentication information from the server 181, it stores the common key included in the received authentication information in the storage unit 150 and sets a predetermined validity period for the authentication information in the timer 160. The authentication processing unit 140 also transmits the common key to the in-vehicle ECU 200 via the relay processing unit 120 and the communication unit 110.
[0129] [Extension Processing] The authentication processing unit 140 performs an extension process to maintain the validity of the authentication information if the validity period of the authentication information has expired and the relay device 100 is unable to communicate with the server 181.
[0130] For example, when the timer 160 expires, the authentication processing unit 140 sends a communication confirmation request to the server 181 via the communication unit 110 and TCU200A to check whether or not communication with the server 181 is possible.
[0131] When server 181 receives the communication confirmation request, it sends communication availability information to relay device 100 via wireless base station device 161 and TCU200A as a response to the communication confirmation request.
[0132] When the authentication processing unit 140 receives communication-enabled information from the server 181 via the communication unit 110 and the relay processing unit 120, it deletes the corresponding common key or authenticated MAC address of the in-vehicle ECU 200 in the storage unit 150.
[0133] The authentication processing unit 140 then obtains new authentication information for the in-vehicle ECU 200 from the server 181, for example, using a procedure that conforms to IEEE802.1X.
[0134] On the other hand, if the authentication processing unit 140 fails to receive communication availability information within a predetermined period after sending a communication confirmation request, it determines that communication between the relay device 100 and the server 181 is not possible and performs extension processing to maintain the validity of the authentication information.
[0135] More specifically, the authentication processing unit 140 sets a predetermined extension time for the authentication information in the timer 160 without discarding the common key or authenticated MAC address of the corresponding in-vehicle ECU 200 in the storage unit 150.
[0136] Alternatively, if, for example, the authentication processing unit 140 is able to communicate with the relay device 100 and the server 181, and the vehicle 1 is in motion while the authentication information has expired, the authentication processing unit 140 will perform extension processing without obtaining new authentication information from the server 181.
[0137] For example, the authentication processing unit 140 obtains information from an in-vehicle ECU 200, such as an autonomous driving ECU, via the communication unit 110 and the relay processing unit 120, indicating whether or not vehicle 1 is in motion.
[0138] Even if the authentication processing unit 140 receives communication-enabled information from the server 181 via the communication unit 110 and the relay processing unit 120, if the vehicle 1 is in motion, it sets a predetermined extension time for the authentication information in the timer 160 without discarding the common key or authenticated MAC address of the corresponding in-vehicle ECU 200 in the storage unit 150.
[0139] The authentication processing unit 140 performs in-vehicle authentication processing on the corresponding in-vehicle ECU 200 using the extended authentication information, which is authentication information that has maintained its validity after the extension processing. Specifically, it performs authentication processing on the in-vehicle ECU 200 using the common key or authenticated MAC address in the storage unit 150 that corresponds to the extended authentication information.
[0140] The authentication processing unit 140 performs authentication processing of the in-vehicle ECU 200 using the extended authentication information. If the authentication of the in-vehicle ECU 200 is successful, it outputs the extended authentication success information to the relay processing unit 120.
[0141] When the relay processing unit 120 receives the extended authentication success information from the authentication processing unit 140, it continues to relay information between the in-vehicle ECU 200 and other in-vehicle ECUs 200.
[0142] After performing the extension process, the authentication processing unit 140 periodically or irregularly sends a communication confirmation request to the server 181 to attempt to obtain new authentication information.
[0143] The authentication processing unit 140 performs authentication processing of the in-vehicle ECU 200 using the extended authentication information until new authentication information is obtained.
[0144] [Relay processing based on extended authentication information] The relay processing unit 120 determines the content of the information to be relayed when the authentication process using the extended authentication information by the authentication processing unit 140 is successful, according to the type of in-vehicle ECU 200.
[0145] Alternatively, the relay processing unit 120 decides whether or not to perform relaying if the authentication process using the extended authentication information by the authentication processing unit 140 is successful, depending on the type of information received from the in-vehicle ECU 200.
[0146] The relay processing unit 120 determines the content of the information to be relayed from the information received from the in-vehicle ECU 200 and the information destined for the in-vehicle ECU 200 when it receives extended authentication success information from the authentication processing unit 140.
[0147] For example, the authentication information received by the authentication processing unit 140 from the server 181 includes the MAC address, IP address, and port number of the corresponding in-vehicle ECU 200 that is the communication target, as well as the port number of the corresponding in-vehicle ECU 200.
[0148] When the authentication processing unit 140 obtains this information from the authentication information, it outputs the obtained information to the relay processing unit 120.
[0149] Based on the information received from the authentication processing unit 140, the relay processing unit 120 determines the content of the information to be relayed when it receives extended authentication success information from the authentication processing unit 140.
[0150] For example, the relay processing unit 120 relays all information between the in-vehicle ECU 200 and other in-vehicle ECUs that affect the driving status of vehicle 1, such as the autonomous driving ECU. On the other hand, the relay processing unit 120 stops relaying information between the in-vehicle ECU 200 and other in-vehicle ECUs that do not affect the driving status of vehicle 1.
[0151] Furthermore, for example, the relay processing unit 120 determines information that affects the driving status of vehicle 1 based on the port number of information from the corresponding in-vehicle ECU 200 and the port number of information from the in-vehicle ECU 200 that is the communication target of the corresponding in-vehicle ECU 200, and relays all information between the in-vehicle ECU 200 and other in-vehicle ECUs that affects the driving status of vehicle 1.
[0152] Furthermore, the relay processing unit 120 may be configured to determine whether or not to relay some or all of the information when the authentication processing using the extended authentication information by the authentication processing unit 140 is successful, depending on both the type of in-vehicle ECU 200 and the type of information received from the in-vehicle ECU 200.
[0153] [Operation Flow] In the embodiments of this disclosure, each device in the communication system includes a computer with memory, and the arithmetic processing unit such as the CPU in the computer reads and executes a program from the memory that includes some or all of the steps in the following flowchart and sequence. The programs for each of these devices can be installed externally. The programs for each of these devices are distributed in a state where they are stored on a recording medium.
[0154] Figure 5 is a flowchart that defines the operating procedure of a relay device in a communication system according to an embodiment of the present disclosure when relaying information between in-vehicle ECUs based on the results of an authentication process.
[0155] Referring to Figure 5, first, the relay device 100 waits for the addition of a new functional unit to the in-vehicle network 12 (NO in step S102), and when it detects the addition of an in-vehicle ECU 200D to the in-vehicle network 12 (YES in step S102), it obtains authentication information for the detected in-vehicle ECU 200D from the server 181 (step S104).
[0156] Next, when the relay device 100 obtains authentication information indicating authentication failure from the server 181 (NO in step S106), it sends connection denial information to the in-vehicle ECU 200D (step S108).
[0157] Next, the relay device 100 awaits the addition of a new functional unit to the in-vehicle network 12 (NO in step S102).
[0158] Meanwhile, when the relay device 100 obtains authentication information indicating successful authentication from the server 181 (YES in step S106), it transmits the successful external authentication information to the corresponding in-vehicle ECU 200D (step S110).
[0159] Next, the relay device 100 performs in-vehicle authentication processing on the in-vehicle ECU 200D using the authentication information obtained from the server 181 (step S112).
[0160] Next, if the relay device 100 fails to perform the in-vehicle authentication process of the in-vehicle ECU 200D (YES in step S114), it stops relaying information between the in-vehicle ECU 200D and other in-vehicle ECUs 200 (step S116).
[0161] Next, the relay device 100 obtains new authentication information for the in-vehicle ECU 200D from the server 181 (step S104).
[0162] On the other hand, if the relay device 100 succeeds in the in-vehicle authentication process of the in-vehicle ECU 200D (NO in step S114), it starts or continues relaying information between the in-vehicle ECU 200D and other in-vehicle ECUs 200 (step S118).
[0163] Next, if the authentication information of the in-vehicle ECU 200D has not expired (NO in step S120), the relay device 100 uses the authentication information to perform in-vehicle authentication processing on the in-vehicle ECU 200D at the timing of the next in-vehicle authentication processing (step S112).
[0164] Meanwhile, when the authentication information of the in-vehicle ECU 200D expires (YES in step S120), the relay device 100 checks whether it is possible to communicate with the server 181 (step S122).
[0165] Next, if the relay device 100 is able to communicate with the server 181 (YES in step S122) and the vehicle 1 is not in motion (YES in step S124), it obtains new authentication information for the on-board ECU 200D from the server 181 (step S104).
[0166] On the other hand, if the relay device 100 is not in a position to communicate with the server 181 (NO in step S122), or if it is in a position to communicate with the server 181 (YES in step S122) and the vehicle 1 is in motion (NO in step S124), it performs extension processing (step S126).
[0167] Next, at the timing of the next in-vehicle authentication process, the relay device 100 performs the in-vehicle authentication process of the in-vehicle ECU 200D using the extended authentication information, which is authentication information whose validity has been maintained by the extension process (step S112).
[0168] Figure 6 shows an example of the sequence of external authentication processing in a communication system according to an embodiment of the present disclosure.
[0169] Referring to Figure 6, first, when the in-vehicle ECU 200D, a new functional unit newly added to the in-vehicle network 12, is connected to the relay device 100, it transmits authentication request information, including its own MAC address, to the relay device 100 (step S202).
[0170] Next, when the relay device 100 receives authentication request information from the in-vehicle ECU 200D, it transmits authentication method information indicating the authentication method for the external authentication process to the in-vehicle ECU 200D (step S204).
[0171] Next, the in-vehicle ECU 200D and the server 181 exchange EAP messages containing information necessary for external authentication processing via the relay device 100 (step S206).
[0172] Next, the server 181 performs external authentication processing for the in-vehicle ECU 200D using the EAP message received from the in-vehicle ECU 200 via the relay device 100 (step S208).
[0173] Next, when the server 181 successfully authenticates the in-vehicle ECU 200D through the external authentication process, it generates authentication information indicating successful authentication and transmits the generated authentication information to the relay device 100 (step S210).
[0174] Next, when the relay device 100 receives authentication information from the server 181, it transmits the successful external authentication information to the in-vehicle ECU 200D (step S212).
[0175] Figure 7 shows an example of the sequences of external and internal authentication processing in a communication system according to an embodiment of the present disclosure.
[0176] Referring to Figure 7, first, the relay device 100 relays information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the results of the in-vehicle authentication process using a common key. That is, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the results of the in-vehicle authentication process performed by the relay device 100 (step S302).
[0177] Next, when the authentication information of the in-vehicle ECU 200D expires, the relay device 100 sends a communication confirmation request to the server 181 (step S304).
[0178] Next, if the relay device 100 fails to receive communication availability information from the server 181 within a predetermined time after sending a communication confirmation request, it determines that communication between the relay device 100 and the server 181 is not possible and performs extension processing to maintain the validity of the authentication information including the shared key (step S306).
[0179] Next, the relay device 100 continues to relay information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the results of the in-vehicle authentication process using a common key. Then, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the results of the in-vehicle authentication process by the relay device 100 (step S308).
[0180] Next, the relay device 100 sends another communication confirmation request to the server 181 (step S310).
[0181] Next, when server 181 receives a communication confirmation request, it sends communication availability information to relay device 100 as a response to the communication confirmation request (step S312).
[0182] Next, the in-vehicle ECU 200D and the server 181 exchange EAP messages containing information necessary for the external authentication process via the relay device 100. Then, the server 181 uses the EAP message received from the in-vehicle ECU 200 via the relay device 100 to perform the external authentication process on the in-vehicle ECU 200D (step S314).
[0183] Next, when the server 181 successfully authenticates the in-vehicle ECU 200D through the external authentication process, it generates authentication information including a new common key and transmits the generated authentication information to the relay device 100 (step S316).
[0184] Next, when the relay device 100 receives authentication information including a new shared key from the server 181, it transmits external authentication success information including the new shared key to the in-vehicle ECU 200D (step S318).
[0185] Next, the relay device 100 starts relaying information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the results of the in-vehicle authentication process using the new common key. Then, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the results of the in-vehicle authentication process by the relay device 100 (step S320).
[0186] Figure 8 shows an example of the sequence of in-vehicle authentication processing in a communication system according to an embodiment of the present disclosure. Figure 8 shows the details of the processing in steps S302, S308, and S320 in Figure 7.
[0187] Referring to Figure 8, first, the relay device 100 generates random numbers (step S402).
[0188] Next, the relay device 100 transmits the generated random number to the in-vehicle ECU 200D, which is the target of the in-vehicle authentication process (step S404).
[0189] Next, the relay device 100 generates encrypted data by encrypting the generated random numbers using a shared key (step S406).
[0190] Furthermore, the in-vehicle ECU 200D generates encrypted data by encrypting the random numbers received from the relay device 100 using a common key (step S408).
[0191] Next, the in-vehicle ECU 200D transmits the generated encrypted data to the relay device 100 (step S410).
[0192] When the relay device 100 receives encrypted data from the in-vehicle ECU 200D, it compares the received encrypted data with the encrypted data it generated itself (step S412).
[0193] Next, if the relay device 100 finds that the encrypted data received from the in-vehicle ECU 200D matches the encrypted data it generated, it determines that the in-vehicle authentication process of the in-vehicle ECU 200D has been successful, and starts or continues relaying information between the in-vehicle ECU 200D and other in-vehicle ECUs 200 (step S414).
[0194] Figure 9 shows another example of the sequences of external and internal authentication processing in a communication system according to an embodiment of the present disclosure.
[0195] Referring to Figure 9, first, the relay device 100 relays information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the results of the in-vehicle authentication process using the authenticated MAC address. That is, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the results of the in-vehicle authentication process performed by the relay device 100 (step S502).
[0196] Next, when the authentication information of the in-vehicle ECU 200D expires, the relay device 100 sends a communication confirmation request to the server 181 (step S504).
[0197] Next, if the relay device 100 fails to receive communication availability information from the server 181 within a predetermined time after sending a communication confirmation request, it determines that communication between the relay device 100 and the server 181 is not possible and performs extension processing to maintain the validity of the authentication information, including the authenticated MAC address (step S506).
[0198] Next, the relay device 100 continues to relay information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the results of the in-vehicle authentication process using the authenticated MAC address. Then, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the results of the in-vehicle authentication process by the relay device 100 (step S508).
[0199] Next, the relay device 100 sends another communication confirmation request to the server 181 (step S510).
[0200] Next, when server 181 receives a communication confirmation request, it sends communication availability information to relay device 100 as a response to the communication confirmation request (step S512).
[0201] Next, the in-vehicle ECU 200D and the server 181 exchange EAP messages containing information necessary for the external authentication process via the relay device 100. Then, the server 181 uses the EAP message received from the in-vehicle ECU 200 via the relay device 100 to perform the external authentication process on the in-vehicle ECU 200D (step S514).
[0202] Next, if the server 181 successfully authenticates the in-vehicle ECU 200D through the external authentication process, it sends new authentication information, including the authenticated MAC address, to the relay device 100 (step S516).
[0203] Next, when the relay device 100 receives new authentication information from the server 181, it sends external authentication success information, including the authenticated MAC address corresponding to the received authentication information, to the in-vehicle ECU 200D (step S518).
[0204] Next, the relay device 100 starts relaying information between the in-vehicle ECU 200C and the in-vehicle ECU 200D based on the results of the in-vehicle authentication process using the newly authenticated MAC address. Then, the in-vehicle ECU 200C and the in-vehicle ECU 200D communicate via the relay device 100 based on the results of the in-vehicle authentication process by the relay device 100 (step S520).
[0205] In the embodiment of the present disclosure, the authentication processing unit 140 is configured to perform an extension process to maintain the validity of the authentication information when the validity period of the authentication information has expired and the relay device 100 cannot communicate with the server 181, and to perform in-vehicle authentication processing of the corresponding in-vehicle ECU 200 using the extended authentication information, which is the authentication information whose validity has been maintained. However, the invention is not limited to this configuration. The authentication processing unit 140 may also be configured to stop in-vehicle authentication processing until new authentication information is obtained, without performing an extension process, when the validity period of the authentication information has expired and the relay device 100 cannot communicate with the server 181. Furthermore, the relay processing unit 120 may be configured to stop relaying information between in-vehicle ECUs 200 until the authentication processing unit 140 obtains new authentication information and performs in-vehicle authentication processing using the newly obtained authentication information.
[0206] Furthermore, in the relay device 100 according to the embodiment of this disclosure, the relay processing unit 120 is configured to determine the content of the information to be relayed when the authentication processing using extended authentication information by the authentication processing unit 140 is successful, depending on the type of in-vehicle ECU 200, but it is not limited to this. The relay processing unit 120 may be configured to relay all information, including various contents between the in-vehicle ECU 200 and other in-vehicle ECUs 200, when the authentication processing using extended authentication information by the authentication processing unit 140 is successful, regardless of the type of in-vehicle ECU 200.
[0207] Furthermore, in the relay device 100 according to the embodiment of this disclosure, the relay processing unit 120 is configured to decide whether or not to perform relaying when the authentication processing using extended authentication information by the authentication processing unit 140 is successful, depending on the type of information received from the in-vehicle ECU 200, but it is not limited to this. The relay processing unit 120 may be configured to relay all information received from the in-vehicle ECU 200 destined for other in-vehicle ECUs 200 when the authentication processing using extended authentication information by the authentication processing unit 140 is successful, regardless of the type of information received from the in-vehicle ECU 200.
[0208] Furthermore, in the relay device 100 according to the embodiment of this disclosure, the authentication processing unit 140 is configured to obtain authentication information from the server 181, the common key of which is updated each time it is obtained, but the invention is not limited to this configuration. The server 181 may also be configured to generate authentication information containing the same corresponding common key each time it performs an external authentication process and successfully authenticates, and to transmit the generated authentication information to the relay device 100.
[0209] Furthermore, in the relay device 100 according to the embodiment of this disclosure, the authentication processing unit 140 is configured to perform extension processing to maintain the validity of the authentication information without acquiring new authentication information from the server 181 if communication between the relay device 100 and the server 181 is possible and the validity period of the authentication information has expired, while the vehicle 1 is in motion. However, the invention is not limited to this configuration. The authentication processing unit 140 may also be configured to acquire new authentication information from the server 181 regardless of whether the vehicle 1 is in motion or not, while communication between the relay device 100 and the server 181 is possible and the validity period of the authentication information has expired.
[0210] By the way, there is a need for technologies that can improve security in in-vehicle networks.
[0211] Specifically, for example, when configuring a new in-vehicle network by installing a new in-vehicle ECU into an existing in-vehicle network, there is a need for technology that can improve the security of the new in-vehicle network.
[0212] In contrast, the relay device 100 according to the embodiment of this disclosure is installed in a vehicle 1 equipped with a plurality of in-vehicle ECUs 200. The authentication processing unit 140 obtains authentication information for the in-vehicle ECUs 200 from a server 181 located outside the vehicle 1 and performs authentication processing for the in-vehicle ECUs 200 using the obtained authentication information. The relay processing unit 120 relays information between the in-vehicle ECUs 200 and other in-vehicle ECUs 200 based on the results of the authentication processing by the authentication processing unit 140. If the authentication information expires, the authentication processing unit 140 obtains new authentication information from the server 181.
[0213] In this configuration, the authentication information for the in-vehicle ECU 200 is obtained from the server 181 located outside the vehicle 1. This ensures that even if a new, unknown in-vehicle ECU 200 is added to the in-vehicle network, the authentication information for that ECU can be obtained. Furthermore, by obtaining new authentication information when the previous information expires, using the obtained authentication information to perform authentication processing on the in-vehicle ECU 200, and relaying information between the in-vehicle ECU 200 and other in-vehicle ECUs 200 based on the results of the authentication processing, the security of the in-vehicle network can be guaranteed. Moreover, even in situations where it is difficult to obtain new authentication information from the server 181 due to the driving environment of the vehicle 1, the authentication processing for the in-vehicle ECU 200 can continue using the authentication information.
[0214] Therefore, the relay device 100 according to the embodiment of this disclosure can improve security in the in-vehicle network.
[0215] Furthermore, in the relay device 100 according to the embodiment of this disclosure, if the validity period of the authentication information expires and the relay device 100 cannot communicate with the server 181, the authentication processing unit 140 performs an extension process to maintain the validity of the authentication information, and uses the extended authentication information, which is the authentication information whose validity has been maintained, to perform the authentication process of the in-vehicle ECU 200 corresponding to the said authentication information.
[0216] With this configuration, even if the communication environment between the relay device 100 and the server 181 is poor due to the driving environment of vehicle 1 when the authentication information expires, making it impossible to obtain new authentication information, the authentication process can still be performed, and the relay of information between the in-vehicle ECUs 200 based on the authentication result can continue. This allows for stable communication in the in-vehicle network, regardless of the driving environment of vehicle 1, in a configuration that improves security by updating the content of authentication information outside of vehicle 1.
[0217] Furthermore, in the relay device 100 according to the embodiment of this disclosure, the relay processing unit 120 determines the content of the information to be relayed when the authentication processing using the extended authentication information by the authentication processing unit 140 is successful, according to the type of in-vehicle ECU 200.
[0218] With this configuration, it is possible to restrict some of the information relayed when extension processing is performed, depending on the type of in-vehicle ECU 200. For example, by continuing to relay information between in-vehicle ECUs 200 that affect the driving of vehicle 1, while stopping the relay of information between in-vehicle ECUs 200 that do not affect the driving of vehicle 1, it is possible to maintain smooth driving of vehicle 1 while suppressing a decrease in security in the in-vehicle network.
[0219] Furthermore, in the relay device 100 according to the embodiment of this disclosure, the relay processing unit 120 determines whether or not to perform relaying when the authentication processing using extended authentication information by the authentication processing unit 140 is successful, depending on the type of information received from the in-vehicle ECU 200.
[0220] With this configuration, it is possible to restrict some of the information relayed when extension processing is performed, depending on the type of information received from the in-vehicle ECU 200. For example, by continuing to relay information that affects the driving of vehicle 1 while stopping the relay of information that does not affect the driving of vehicle 1, it is possible to maintain the smooth operation of vehicle 1 while suppressing a decrease in security in the in-vehicle network.
[0221] Furthermore, in the relay device 100 according to the embodiment of this disclosure, the authentication processing unit 140 obtains authentication information from the server 181, which has different content each time authentication information is obtained.
[0222] This configuration allows for the acquisition of new authentication information each time the previous one expires, and enables the authentication process of the in-vehicle ECU200 to be performed using this new authentication information, thereby further improving security in the in-vehicle network.
[0223] Furthermore, in the relay device 100 according to the embodiment of this disclosure, if communication between the relay device 100 and the server 181 is possible and the validity period of the authentication information has expired, and the vehicle 1 is in motion, the authentication processing unit 140 performs extension processing to maintain the validity of the authentication information without obtaining new authentication information from the server 181.
[0224] This configuration prevents, for example, authentication errors that occur when authentication processing is performed using new authentication information, which could cause the relay of some or all of the information between the on-board ECUs 200 to stop while the vehicle 1 is running, thereby maintaining the smooth operation of the vehicle 1.
[0225] Furthermore, the vehicle communication method according to the embodiment of this disclosure is a vehicle communication method in a relay device 100 mounted on a vehicle 1 equipped with a plurality of on-board ECUs 200. In this vehicle communication method, first, authentication information for the on-board ECUs 200 is obtained from an external device outside the vehicle 1. Next, authentication processing for the on-board ECUs 200 is performed using the acquired authentication information. Next, information of the on-board ECUs 200 and other on-board ECUs 200 is relayed based on the results of the authentication processing. Next, if the validity period of the authentication information expires, new authentication information is obtained from the server 181.
[0226] In this way, by obtaining authentication information for the in-vehicle ECU 200 from the server 181 located outside the vehicle 1, authentication information for a new, unknown in-vehicle ECU 200 can be obtained even when it is added to the in-vehicle network. Furthermore, by obtaining new authentication information when the previous information expires, performing authentication processing for the in-vehicle ECU 200 using the obtained authentication information, and relaying information between the in-vehicle ECU 200 and other in-vehicle ECUs 200 based on the results of the authentication processing, the security of the in-vehicle network can be guaranteed. In addition, even in situations where it is difficult to obtain new authentication information from the server 181 due to the driving environment of the vehicle 1, authentication processing for the in-vehicle ECU 200 can be continued using the authentication information.
[0227] Therefore, the vehicle communication method according to the embodiment of this disclosure can improve security in the in-vehicle network.
[0228] The embodiments described above should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than the above description, and all modifications within the meaning and scope of the claims are intended to be included.
[0229] The above description includes the following features. [Note 1] A relay device mounted on a vehicle equipped with multiple functional units, An authentication processing unit that obtains authentication information for the functional unit from an external device outside the vehicle and performs authentication processing for the functional unit using the obtained authentication information, The system includes a relay processing unit that relays information between the functional unit and other functional units based on the results of the authentication process performed by the authentication processing unit, The authentication processing unit, when the validity period of the authentication information expires, obtains new authentication information from the external device. The authentication processing unit is a relay device that obtains authentication information, which includes a different common key each time it is obtained, from the external device, and performs authentication processing on the functional unit using the common key included in the obtained authentication information. [Explanation of Symbols]
[0230] 1 vehicle 11 External Network 12. In-vehicle network 13 Ethernet cable 52 communication ports 100 relay devices 110 Communications Department 120 Relay Processing Unit 130 Detection unit 140 Authentication Processing Unit 150 Storage section 160 timer 161 Wireless base station equipment 181 Servers 200 Automotive ECU 210 Communications Department 220 processing units 230 Authentication Request Section 240 Storage section 301 In-vehicle communication system 401 Communication Systems
Claims
1. A relay device mounted on a vehicle equipped with multiple functional units, An authentication processing unit that obtains authentication information for the functional unit from an external device outside the vehicle and performs in-vehicle authentication processing, which is the authentication process for the functional unit, using the obtained authentication information. The system includes a relay processing unit that relays information between the functional unit and other functional units based on the results of the in-vehicle authentication process, The authentication processing unit, when the validity period of the authentication information expires, obtains new authentication information from the external device. The relay device further includes a storage unit that stores the authentication method in the external authentication process, which is the authentication process of the functional unit by the external device, and notifies the functional unit of the authentication method. The relay device relays information used in the external authentication process, which is exchanged between the external device and the functional unit that has been notified of the authentication method. The authentication processing unit is a relay device that, when the external device succeeds in the external authentication process, performs the in-vehicle authentication process using the authentication information.
2. The relay device according to claim 1, wherein the authentication processing unit obtains authentication information from the external device, the authentication information having different content each time it is obtained.
3. A vehicle communication method in a relay device mounted on a vehicle equipped with multiple functional units, The steps include obtaining authentication information for the functional unit from an external device located outside the vehicle, The steps include: performing an in-vehicle authentication process, which is the authentication process of the functional unit, using the acquired authentication information; The steps include relaying information between the functional unit and other functional units based on the results of the in-vehicle authentication process, The step of obtaining new authentication information from the external device if the authentication information has expired includes the step of The aforementioned vehicle communication method further includes, The steps include notifying the function unit of the authentication method in the external authentication process, which is the authentication process of the function unit by the external device, The process includes a step of relaying information used in the external authentication process, which is exchanged between the external device and the functional unit that has been notified of the authentication method, A vehicle communication method in which, in the step of performing the in-vehicle authentication process, if the external device succeeds in the external authentication process, the authentication information is used to perform the in-vehicle authentication process.
4. A vehicle communication program for a relay device installed in a vehicle equipped with multiple functional units, On the computer, The steps include obtaining authentication information for the functional unit from an external device located outside the vehicle, The steps include: performing an in-vehicle authentication process, which is the authentication process of the functional unit, using the acquired authentication information; The steps include relaying information between the functional unit and other functional units based on the results of the in-vehicle authentication process, This program causes the execution of the step of obtaining new authentication information from the external device when the expiration date of the aforementioned authentication information has expired. The aforementioned vehicle communication program further, To the aforementioned computer, The steps include notifying the function unit of the authentication method in the external authentication process, which is the authentication process of the function unit by the external device, A program for causing the execution of a step of relaying information used in the external authentication process, which is information exchanged between the external device and the functional unit that has been notified of the authentication method, In the step of performing the in-vehicle authentication process, if the external device succeeds in the external authentication process, the vehicle communication program performs the in-vehicle authentication process using the authentication information.
Citation Information
Patent Citations
Authentication system, wireless communication terminal, authentication server, authentication method and program
JP2010134493A
Vehicle authentication device, and vehicle authentication system
JP2013193598A
Hybrid authentication of vehicle devices and / or mobile user devices
US20190159026A1
Network system, communication control method, and storage medium
WO2015194323A1
Key management method, vehicle-mounted network system and key management device
WO2016075869A1