vehicle-mounted device
The in-vehicle device manages security function transitions using activation flags to prevent insecure communication services during abnormal transitions, ensuring secure communication.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- DENSO CORP
- Filing Date
- 2022-12-16
- Publication Date
- 2026-05-26
AI Technical Summary
Existing in-vehicle devices may experience abnormality during security function transition, leading to incomplete function transitions and potential execution of communication services vulnerable to security risks.
An in-vehicle device with a security function unit, security method identification unit, and communication service management unit that manages security function activation flags to ensure complete and secure function transitions, preventing communication services from being executed in abnormal states.
Ensures secure communication services by preventing execution in abnormal states and avoiding security vulnerabilities during incomplete function transitions.
Smart Images

Figure 0007865190000001 
Figure 0007865190000002 
Figure 0007865190000003
Abstract
Description
Technical Field
[0001] The disclosure according to this specification relates to the transition of security methods in communication between an in-vehicle device and a communication target.
Background Art
[0002] In an ETC (registered trademark) system, technologies corresponding to smooth transition of security methods have been proposed. In Patent Document 1, a plurality of security functions individually corresponding to a plurality of security methods that may be used in the future are pre-installed in an in-vehicle device. And it is disclosed that by connecting a setup card to the in-vehicle device, a new security method and its function can be enabled.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, some abnormality may occur during the function transition process of the security function in setup, and the function transition process may not complete normally. In this case, if the in-vehicle device communicates with the communication target, there is a possibility that the old security method is not invalidated and a communication service vulnerable to security is executed.
[0005] One of the purposes according to the disclosure of this specification is to provide an in-vehicle device that can avoid executing a communication service vulnerable to security even when the function transition process does not complete normally.
Means for Solving the Problems
[0006] One aspect disclosed herein is an in-vehicle device used for a communication service with a communication target (60), A security function unit (25) having multiple security functions that individually correspond to multiple security methods used in communication services, A security method identification unit (21) identifies the target security method to be enabled from among multiple security methods in response to external setup request information, A security function activation unit (23) executes a function migration process to activate security functions corresponding to the security method of the destination, A communication service management unit configured to perform communication services with a communication target based on any of multiple security functions, and comprising a communication service management unit (26) that refers to a security function activation flag (102) and, if the security function activation flag is a value indicating that the service is unavailable, puts the communication service with the communication target into an unavailable state, The security function activation unit, in the function migration process, sets the security function activation flag to a value indicating service unavailable before activating the security function of the destination, and sets the security function activation flag to a value indicating service available once the activation of the security function of the destination is complete.
[0007] In this configuration, if the function migration process to the target security function does not complete successfully after the process has started, the security function activation flag will hold a value indicating that the service is unavailable. In this state, by referring to the security function activation flag, it is possible to know in advance that the service is unavailable. Therefore, the communication service between the in-vehicle device and the communication target will ultimately fail. Thus, it is possible to avoid the in-vehicle device executing a communication service with security vulnerabilities while in an abnormal state if the function migration process does not complete successfully.
[0008] The symbols in parentheses included in the claims, etc., are illustrative examples illustrating the correspondence with the embodiments described later, and are not intended to limit the technical scope. [Brief explanation of the drawing]
[0009] [Figure 1] This is a schematic diagram of the in-vehicle unit and setup card configuration. [Figure 2] This is a functional configuration diagram of the in-vehicle device. [Figure 3] This figure shows an example of a unique ID for an in-vehicle device. [Figure 4] This flowchart shows an example of the setup process. [Figure 5] This flowchart shows an example of the process at the start of communication. [Figure 6] This flowchart shows an example of the setup process. [Figure 7] This flowchart shows an example of the setup process. [Figure 8] This flowchart shows an example of the setup process. [Modes for carrying out the invention]
[0010] Several embodiments will be described below with reference to the drawings. In each embodiment, the same reference numerals are used for corresponding components, and redundant explanations may be omitted. If only a part of the configuration is described in each embodiment, the configuration of other embodiments described earlier can be applied to the other parts of that configuration. Furthermore, in addition to the combinations of configurations explicitly stated in the description of each embodiment, configurations from multiple embodiments can be partially combined even if not explicitly stated, as long as there are no particular problems with the combination.
[0011] (First Embodiment) As shown in Figure 1, the on-board unit 10 of the first embodiment is used in an ETC (Electronic Toll Collection) system. The on-board unit 10 is mounted in a vehicle. The on-board unit 10 communicates with roadside units 60, which are installed on the road and act as communication targets for collecting tolls on toll roads as a communication service. The on-board unit 10 consists of a computer 11, a power supply circuit 15, a communication circuit 17, a card I / F (interface) 19, a speaker 8, and a lamp 9.
[0012] The computer 11 has at least one memory 12 and one processor 13. The memory 12 may be at least one type of non-transitional physical storage medium, such as semiconductor memory, magnetic media, and optical media, which non-temporarily stores programs and data that can be read by the processor 13. The non-transitional physical storage medium may correspond to a non-volatile storage medium. Furthermore, the memory 12 may also be a rewritable volatile storage medium, such as RAM (Random Access Memory). The processor 13 includes at least one type as a core, such as a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), and a RISC (Reduced Instruction Set Computer)-CPU.
[0013] The power supply circuit 15 is electrically connected to the vehicle's power supply 40. When the vehicle's power supply 40 is turned on, the power supply circuit 15 supplies power to the computer. When the vehicle's power supply 40 is turned off, the power supply circuit 15 stops supplying power to the computer.
[0014] The communication circuit 17 is configured to be able to perform wireless communication with the roadside unit 60 by an active DSRC (Dedicated Short Range Communication) in the 5.8 GHz band. The communication circuit 17 includes a modulation circuit, a demodulation circuit, and an amplification circuit. The communication circuit 17 modulates and amplifies the message provided by the computer 11 and transmits it from the antenna 30. Also, the communication circuit 17 demodulates and amplifies the message received through the antenna 30 and provides it to the computer.
[0015] The card I / F 19 is an interface for electrically connecting cards such as an ETC card and a setup card 50 to the vehicle-mounted unit 10. When a card is inserted into the card I / F 19, the computer 11 can read the information of the card.
[0016] One vehicle-mounted unit specific ID 50a for specifying the security method to be activated is stored in the setup card 50. Further, setup information necessary for successfully setting up the security function according to the security method may be stored in the setup card 50. The setup information may include setup request information, encryption information, etc.
[0017] The speaker 8 is controlled by the computer 11 and is configured to be able to notify the user of the insertion state of the ETC card, the toll during toll collection, etc. The lamp 9 can display the insertion state of the ETC card, etc. to the user by lighting up in a switchable manner with a plurality of colors such as blue and red. The speaker 8 and the lamp 9 are collectively referred to as HMI (Human Machine Interface).
[0018] As shown in FIG. 2, the computer 11 realizes a plurality of processing units as functional blocks realized by the processor 13 executing a program. Specifically, the computer 11 includes a security method identification unit 21, an in-vehicle device unique ID holding unit 22, a security function activation unit 23, a setup information management unit 24, a security function unit 25, and a communication service management unit 26.
[0019] When the computer 11 detects that the setup card 50 has been inserted into the card I / F 19, the security method identification unit 21 identifies the security method. The security method may be, for example, an encryption algorithm method. Specifically, the security method identification unit 21 reads out the in-vehicle device unique ID 101 stored in the setup card 50. Then, the security method identification unit 21 compares the in-vehicle device unique ID 50a of the setup card 50 with the in-vehicle device unique ID 101 held by the in-vehicle device 10.
[0020] If all of the in-vehicle device unique ID 50a of the setup card 50 and the plurality of in-vehicle device unique IDs 101 held by the in-vehicle device 10 are different, the security method identification unit 21 ends the process without selecting a security method. If there is an in-vehicle device unique ID 101 that matches the in-vehicle device unique ID 101 of the setup card 50 among the plurality of in-vehicle device unique IDs 101 held by the in-vehicle device 10, the security method identification unit 21 selects a security method to be activated according to the security method identification information included in the matching in-vehicle device unique ID 101.
[0021] The in-vehicle device unique ID holding unit 22 holds and manages a plurality of in-vehicle device unique IDs 101 assigned for each security method on the in-vehicle device 10 side stored in the memory 12 (particularly a non-volatile storage medium). The in-vehicle device unique ID holding unit 22 provides the in-vehicle device unique ID 101 to the security method identification unit 21 in response to a request from the security method identification unit 21.
[0022] As shown in Figure 3, each in-vehicle device unique ID 101 has a configuration that includes one security method identification information and one in-vehicle device identification information. The security method identification information is information assigned to each security method and is used to identify the security method to be activated. The in-vehicle device identification information is information unique to each in-vehicle device 10 and is assigned to each individual in-vehicle device 10. Therefore, the in-vehicle device identification information is the same value among multiple in-vehicle device unique IDs 101.
[0023] The security function activation unit 23 executes a function migration process based on the security method identification unit 21's verification, in accordance with the selection of the security method to be activated. In other words, it reads the setup information stored on the setup card 50 and switches the security functions based on the currently used security method to the security functions based on the new security method specified by the setup card 50. The new security method can be said to be the security method to which the user is migrating.
[0024] For example, the security function activation unit 23 modifies the program branching processed by the security function unit 25 so that programs not used in the currently used security method but used in the new security method can function. The security function activation unit 23 also modifies the program branching processed by the security function unit 25 so that programs used in the currently used security method but not used in the new security method cannot function. There may be multiple program branches, and these branches are modified sequentially. In this way, security functions corresponding to the currently used security method are disabled, and the system becomes equivalent to past security functions.
[0025] In this case, problems during the function migration process may cause the process to terminate prematurely or fail to complete successfully. For example, if the system is designed to continue the function migration process only when the in-vehicle unit 10 has the setup card 50 inserted, the process will be interrupted if the setup card 50 is removed during the process. Also, for example, if the power supply to the in-vehicle unit 10 is interrupted during the function migration process due to a power supply problem, the function migration process may not be able to complete successfully.
[0026] To address the abnormal termination of such function migration processing, in this embodiment, the setup information management unit 24 manages the security function activation flag 102. At the start of the function migration processing, the security function activation unit 23 requests the setup information management unit 24 to set the security function activation flag 102 to "FALSE". Furthermore, if the function migration processing is completed successfully, the security function activation unit 23 requests the setup information management unit 24 to set the security function activation flag 102 to "TRUE".
[0027] The setup information management unit 24 rewrites the security function activation flag 102 in response to a request from the security function activation unit 23. The security function activation flag 102 is stored in a non-volatile storage medium, which is memory 12. In this way, its value is retained even if the power supply is cut off.
[0028] Here, “FALSE” is also referred to as a false value. “FALSE” indicates that the security function or its activation is in an abnormal state, and that the communication service related to toll collection with the roadside unit 60 is unavailable. “TRUE” is also referred to as a true value. “TRUE” indicates that the security function or its activation is in a normal state, and that the communication service related to toll collection with the roadside unit 60 is available. Note that the security function activation flag 102 only needs to be able to distinguish between the two states, and may take values of “0” and “1” instead of “FALSE” and “TRUE”.
[0029] The security function unit 25 is configured to implement multiple security functions that support multiple security methods. These multiple security methods may include, for example, the security method that is currently dominant at the time of delivery to the user and a security method that is expected to become dominant in the future. A program that executes multiple security functions that support multiple security methods is pre-installed on the computer 11 of the in-vehicle unit 10.
[0030] Furthermore, when the system is delivered to the user, security features corresponding to the prevailing security method at that time are enabled, while security features corresponding to security methods expected to become mainstream in the future are disabled.
[0031] When the security method of the roadside unit 60 is changed, it is preferable to also change the security method of the in-vehicle unit 10 in order to avoid a mismatch in security functions between the roadside unit 60 and the in-vehicle unit 10. On the other hand, replacing the in-vehicle unit 10 with one that has the latest security method at the same time as the security method of the roadside unit 60 is changed may be difficult due to the economic reasons of the owner of the in-vehicle unit 10 or due to the supply system of the in-vehicle unit 10.
[0032] For example, a setup worker such as a vehicle dealer or user inserts the setup card 50. The in-vehicle unit 10 then recognizes that setup is required. The security features corresponding to the prevailing security method used when the vehicle is delivered to the user are then disabled. Furthermore, security features corresponding to security methods expected to become mainstream in the future are enabled.
[0033] The communication service management unit 26 uses the communication circuit 17 and antenna 30 to communicate with the roadside unit 60 based on one of several security functions. Before starting communication with the roadside unit 60, the communication service management unit 26 checks the security function activation flag 102. That is, if the security function activation flag 102 is "TRUE", the communication service management unit 26 makes the communication service related to toll collection with the roadside unit 60 available. On the other hand, if the security function activation flag 102 is "FALSE", the communication service management unit 26 makes the execution of the communication service related to toll collection with the roadside unit 60 unavailable.
[0034] This prevents communication errors caused by communication being executed while the function transition process is in an abnormal state, as well as the execution of communications with security vulnerabilities.
[0035] Next, an example of a setup method implemented by the processor 13 executing a program in the computer 11 of the in-vehicle unit 10 will be explained using the flowchart in Figure 4. The series of processes shown in steps S11 to S16 are triggered when the setup card 50 is inserted into the in-vehicle unit 10.
[0036] In the first step, S11, the information stored in the setup card 50 is read. The information stored in the setup card 50 corresponds to the setup request information. After processing S11, the process proceeds to S12.
[0037] In S12, the security method identification unit 21 determines whether the vehicle-specific ID 50a of the setup card 50 matches the vehicle-specific ID 101 of the vehicle-specific unit 10 itself. If yes, proceed to S13. If no, terminate the series of processes at S12.
[0038] If the answer is No, the in-vehicle unit 10 may request that a warning be issued via the vehicle's display device or speaker 9 indicating that the in-vehicle unit's unique ID does not match.
[0039] In S13, the security method identification unit 21 selects the security method to be activated and the corresponding security function according to the security method identification information contained in the matching in-vehicle device unique ID 50a. After processing in S13, the process proceeds to S14.
[0040] In S14, the security function activation unit 23 sets the security function activation flag to "FALSE". After processing in S14, the process proceeds to S15.
[0041] In S15, the security function activation unit activates the selected security method. In other words, the function migration process is executed. After the processing in S15, the process proceeds to S16.
[0042] In S16, the security function activation unit 23 sets the security function activation flag 102 to "TRUE". The series of processes ends with S16.
[0043] In this way, if the S15 process terminates abnormally, the security function enablement flag 102 remains "FALSE".
[0044] Next, an example of a communication method implemented by the processor 13 executing a program in the computer 11 of the in-vehicle unit 10 will be explained using the flowchart in Figure 5. Steps S21 to S23 are assumed to apply whether or not the ETC card is inserted into the card I / F 19 and authenticated correctly.
[0045] In S21, the communication service management unit 26 acquires the security function activation flag 102. After processing in S21, the process proceeds to S22.
[0046] In S22, the communication service management unit 26 determines whether the security function activation flag 102 is "TRUE". If yes, proceed to S23. If no, proceed to S24.
[0047] In S23, the communication service management unit 26 enables the communication service related to toll collection with the roadside unit 60. When the communication service is available, the communication service management unit 26 permits the output (transmission) of information related to the toll collection service (such as payment information) to the roadside unit 60 or other devices. As a result, toll collection is performed when the vehicle passes through the ETC gate at the toll booth, and the vehicle is allowed to pass through the gate. The series of processes ends in S23.
[0048] In S24, the communication service management unit 26 disables the communication service related to toll collection with the roadside unit 60. When the communication service is unavailable, the communication service management unit 26 prohibits outputting (transmitting) information related to the toll collection service (such as payment information) to the roadside unit 60 or other devices. As a result, when a vehicle attempts to pass through the ETC gate at a toll booth, the on-board unit 10 attempts to communicate with the roadside unit 60, but the communication service related to toll collection fails, and the vehicle is unable to pass through the gate. The series of processes ends in S24. Note that the information related to the toll collection service may include information other than payment information, such as contract information and vehicle information.
[0049] Furthermore, an in-vehicle unit 10 in a service unavailable state behaves similarly to an in-vehicle unit that has not been set up or an in-vehicle unit with an unauthenticated ETC card. In addition, when a service becomes unavailable, the communication service management unit 26 should notify the dealer or user that the service is unavailable through the vehicle's display device, speaker 8, lamp 9, or other HMI.
[0050] Specifically, speaker 8 will notify the user by voice if the communication service is unavailable. Lamp 9 will indicate the status by lighting up blue when the communication service is available and red when it is unavailable.
[0051] Furthermore, if the function migration process terminates abnormally while the security function activation flag 102 remains "FALSE" and the service is unavailable, the setup operator can reinsert the setup card 50 into the in-vehicle unit 10 and perform the setup again. If the computer 11 executes the processes from S11 onwards again and successfully completes the function migration process, communication will be permitted and the ETC system will become available.
[0052] According to the first embodiment described above, if the function migration process to the target security function is not completed successfully after the process has started, the security function activation flag 102 will hold a value indicating that the service is unavailable. In this state, by referring to the security function activation flag 102, it is possible to determine in advance that the service is unavailable. As a result, the communication service between the in-vehicle unit 10 and the roadside unit 60 will ultimately fail. Therefore, if the function migration process is not completed successfully, it is possible to avoid the in-vehicle unit 10 remaining in an abnormal state and executing a communication service with security vulnerabilities.
[0053] Furthermore, according to the first embodiment, the security function activation unit 23, in the function migration process, disables past security functions corresponding to past security methods that were enabled before the destination security function was activated, among the multiple security methods. By disabling past security functions, it becomes possible to avoid executing communication services with security vulnerabilities, even after the security function activation flag 102 has been set to a value indicating communication permission.
[0054] Furthermore, according to the first embodiment, setup request information is obtained from a setup card 50 connected via a card I / F 19. In this configuration, since a setup worker is required to connect a physical card, it is possible to suppress situations in which the in-vehicle device 10 unintentionally switches to another security method due to automated processing or the like.
[0055] (Second Embodiment) As shown in Figure 6, the second embodiment is a modified version of the first embodiment. The second embodiment will be described focusing on the differences from the first embodiment.
[0056] In the second embodiment, the priority of each of the multiple security methods possessed by the in-vehicle device 10 is predetermined. The priority is set higher for security methods that employ more advanced encryption algorithms, for example. The priority may be held by, for example, the security function activation unit.
[0057] In the second embodiment, when activating a new security method, the security function activation unit 23 compares the priority of the new security method with other security methods possessed by the in-vehicle device 10. Based on the priority of the new security method, the security function activation unit 23 then determines whether or not to perform a function transition process.
[0058] Here, an example of a setup method implemented by the processor 13 executing a program in the computer 11 of the in-vehicle unit 10 will be explained using the flowchart in Figure 6. The series of processes shown in steps S111 to S118 are triggered when the setup card 50 is inserted into the in-vehicle unit 10.
[0059] Steps S111-113 are the same as steps S11-13 in Figure 4. In step S114, which is executed after the processing of step S113, the security function activation unit 23 determines whether or not there is a currently activated security method. If yes, proceed to step S115. If no, proceed to step S117.
[0060] In S115, the security function activation unit 23 determines whether the security method selected by the security method identification unit 21 has a lower priority than the currently enabled security method. If yes, the series of processes ends. If no, proceed to S116.
[0061] Steps S116 to S118 are the same as steps S14 to S16 in Figure 4.
[0062] Thus, by adopting the S115 process, it is possible to prevent setup personnel from accidentally reverting to the old security method for in-vehicle devices 10 that have already been migrated to an advanced security method.
[0063] (Third embodiment) As shown in Figures 7 and 8, the third embodiment is a modification of the first embodiment. The third embodiment will be described focusing on the differences from the first embodiment.
[0064] In the third embodiment, the setup information management unit 24 is configured to erase the old setup information used before the current setup when the setup card 50 is inserted into the in-vehicle unit 10 and the function transfer process is executed.
[0065] Here, "old setup information" refers to the setup and security function information of the security method used before the current setup. This old setup information includes, for example, data referenced by the program during past setups, and data referenced by the program used for the security function before the setup. It may also include vehicle type information and vehicle registration number information for the vehicle in which the in-vehicle unit 10 is installed. From the perspective of the new security method, the old setup information can be considered the setup information used for past security functions.
[0066] These old setup details remain, particularly in non-volatile storage media such as memory 12. After migrating to a new security system, if the old setup details persist, some malfunction in computer 11 may cause the system to access this information, potentially leading to processing errors. Alternatively, the remaining information could potentially lead to data leakage.
[0067] Therefore, in the third embodiment, the setup information management unit 24 erases all old setup information. Erasure here includes rewriting data. For example, in a non-volatile storage medium, the area where the old setup information is stored is rewritten with meaningless data. Meaningless data here refers to, for example, hexadecimal data such as "00" or "FF".
[0068] Alternatively, for example, the data storage area for setup information on a non-volatile storage medium may be limited in advance. In this example, when the setup information management unit 24 generates new setup information, it overwrites and updates the entire predetermined data storage area. Since the data size of the setup information is expected to vary, the setup information management unit 24 forcibly rewrites any remaining portion of the data storage area that cannot be overwritten with meaningless data. In this way, all old setup information is erased.
[0069] Next, an example of a setup method implemented by the processor 13 executing a program in the computer 11 of the in-vehicle unit 10 will be explained using the flowchart in Figure 7. The series of processes shown in steps S211 to S217 are triggered when the setup card 50 is inserted into the in-vehicle unit 10.
[0070] Steps S211 to S213 are the same as steps S11 to S13 in Figure 4. In step S214, which is executed after the processing of S213, the setup information management unit 24 erases all setup information. After the processing of S214, the process proceeds to S215. Steps S215 to S217 are the same as steps S14 to S16 in Figure 4.
[0071] Furthermore, the setup method may be performed as shown in the flowchart of Figure 8. The setup method shown in the flowchart of Figure 8 is a method that adds a process to clear the setup information to the priority method of the second embodiment.
[0072] S311 to S315 are the same as S111 to S115 in Figure 6. S316, which is executed when the answer to S315 is No, is the same as S214 in Figure 7. After processing S316, the process proceeds to S317, and S317 to S319 are the same as S116 to S118 in Figure 6.
[0073] In this way, deleting old setup information can help prevent the occurrence of security vulnerabilities.
[0074] (Other embodiments) Although several embodiments have been described above, this disclosure is not limited to those embodiments and can be applied to various embodiments and combinations without departing from the spirit of this disclosure.
[0075] In other embodiments, the number of security methods supported by the in-vehicle device 10 may be three or more.
[0076] In other embodiments, setup may be performed without using a physical card such as the setup card 50. For example, the setup terminal and the in-vehicle unit 10 may communicate wirelessly using, for example, Bluetooth®, Wi-Fi®, etc. The in-vehicle unit 10 may then obtain the in-vehicle unit unique ID 50a and setup information from the setup terminal via communication. In this case, the system may be configured to interrupt the function transition process if communication is interrupted during the function transition process.
[0077] The non-volatile storage medium in which the setup information is stored does not have to be the memory 12 built into the computer 11; for example, it may be a storage medium provided independently of the computer 11 in the in-vehicle device 10. The same applies to the non-volatile storage medium in which the security function activation flag 102 is stored.
[0078] The control unit and method described herein may be implemented by a dedicated computer comprising a processor programmed to perform one or more functions embodied by a computer program. Alternatively, the apparatus and method described herein may be implemented by a dedicated hardware logic circuit. Alternatively, the apparatus and method described herein may be implemented by one or more dedicated computers comprising a combination of a processor that executes a computer program and one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by the computer on a computer-readable non-transitional tangible recording medium. [Explanation of Symbols]
[0079] 10: In-vehicle unit, 21: Security method identification unit, 23: Security function activation unit, 25: Security function unit, 26: Communication service management unit, 60: Roadside unit (communication target), 102: Security function activation flag
Claims
1. An in-vehicle device used for communication services with a communication target (60), A security function unit (25) having multiple security functions that are individually corresponding to multiple security methods used in the aforementioned communication service, A security method identification unit (21) identifies the target security method to be enabled from among multiple security methods in response to setup request information from an external source, A security function activation unit (23) executes a function migration process to activate security functions corresponding to the security method of the destination, A communication service management unit configured to execute the communication service with the communication target based on any of multiple security functions, comprising: a communication service management unit (26) that refers to a security function activation flag (102) and, if the security function activation flag is a value indicating that the service is unavailable, puts the communication service with the communication target into an unavailable state; The in-vehicle device comprises a security function activation unit that, in the function migration process, sets the security function activation flag to a value indicating service unavailable before activating the security function of the destination, and sets the security function activation flag to a value indicating service available once the activation of the security function of the destination is complete.
2. The in-vehicle device according to claim 1, wherein the security function activation unit, in the function migration process, disables past security functions corresponding to past security methods that were activated before the destination security function was activated, among a plurality of security methods.
3. It is further equipped with a setup information management unit (24) that manages setup information, The in-vehicle device according to claim 2, wherein the setup information management unit erases the setup information used in the previous security function.
4. The system further includes a non-volatile storage medium (12) that stores setup information used in the aforementioned past security function, The in-vehicle device according to claim 3, wherein the setup information management unit overwrites the area of the storage medium in which the setup information used in the past security function is stored with meaningless data.
5. The system further includes a non-volatile storage medium (12) that stores setup information used in the aforementioned past security function, The in-vehicle device according to claim 3, wherein the setup information management unit pre-limits the data storage area for the setup information in the storage medium, and overwrites and updates the entire data storage area when generating new setup information.
6. Each of the aforementioned security functions has a predetermined priority. The in-vehicle device according to claim 1, wherein the security function activation unit determines whether or not to execute the function migration process based on the priority of the destination security method.
7. It further includes an interface (19) for connecting a setup card (50) from an external source, The in-vehicle device according to claim 1, wherein the setup request information is obtained from the setup card.
8. The aforementioned communication service is a toll collection service at a toll booth. The in-vehicle device according to claim 1, wherein the communication service management unit prohibits the transmission of information related to the toll collection service to the communication target when the toll collection service is unavailable, thereby causing the toll collection service to fail.
9. It also includes an HMI (8,9) that notifies the user of information, The in-vehicle device according to claim 1, wherein the communication service management unit notifies the user via the HMI of information indicating that the communication service is unavailable when the communication service is unavailable.
10. The in-vehicle device according to claim 9, wherein the communication service management unit causes the speaker, which acts as the HMI, to notify the user by voice that the communication service is unavailable.
11. The in-vehicle device according to claim 9 or 10, wherein the communication service management unit illuminates the lamp, which serves as the HMI, in red.