Electronic control device, key matching method, key matching program, and key management system

JP7913333B2Active Publication Date: 2026-09-01DENSO CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2022149536
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-09-20
Publication Date
2026-09-01
Estimated Expiration
2042-09-20

AI Technical Summary

Benefits of technology

【0009】 上述のような構成により、移動体の電子制御装置間の通信で使用される暗号鍵の信頼性を向上することができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007913333000001
    Figure 0007913333000001
  • Figure 0007913333000002
    Figure 0007913333000002
  • Figure 0007913333000003
    Figure 0007913333000003
Patent Text Reader

Abstract

To provide an electronic control device, a key verification method, a key verification program, and a key management system that provide stronger protection means against cyber-attacks within a mobile device in order to prevent an encryption key used in communications between a plurality of electronic control devices from being tampered with by cyber attacks.SOLUTION: In an electronic control system 100, electronic control units (ECU) 11 and 12 installed in a vehicle include storage units 111 and 121 that store keys, collation units 115 and 125 that collate the key stored in the storage unit with key information that is information regarding the key stored in a distributed ledger 200 provided outside the vehicle at predetermined timing.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an electronic control device, a key verification method, a key verification program, and a key management system for key verification used in encryption, decryption, and the like. [Background Art]

[0002] In recent years, technologies that use V2X such as vehicle-to-vehicle communication and road-to-vehicle communication to provide vehicle driving assistance and automatic driving control have attracted attention. Along with this trend, vehicles have come to be equipped with communication functions, increasing the possibility that vehicles will be subjected to cyberattacks such as hacking. Further, since vehicles may lose control as a result of cyberattacks, stronger defense measures against cyberattacks are required.

[0003] A vehicle is equipped with a plurality of electronic control devices interconnected via a network. For vehicle driving, particularly driving assistance and automatic driving control, transmission and reception of information through communication between the plurality of electronic control devices is required. As a countermeasure against cyberattacks on communication performed between a plurality of electronic control devices, for example, Patent Document 1 describes encrypting communication target data in communication between a plurality of control devices, and managing encryption keys used for the encryption inside the vehicle. [Prior Art Literature] [Patent Literature]

[0004] [Patent Document 1] Japanese Unexamined Patent Publication No. 2019-47281 [Summary of the Invention] [Problem to be Solved by the Invention]

[0005] Here, the present inventors have identified the following problem. As mentioned earlier, driver assistance and autonomous driving control require highly reliable vehicle control. Therefore, stronger countermeasures against cyberattacks in communication between multiple electronic control units are necessary. Of course, the same applies to normal driving. However, if the encryption keys used in communication between multiple electronic control units are managed only within the vehicle, there is a risk that the encryption keys could be tampered with in the event of a cyberattack on the vehicle, threatening the security of the vehicle's network.

[0006] The present invention aims to provide an electronic control device, a key matching method, a key matching program, and a key management system that can improve the reliability of cryptographic keys used in communication between electronic control devices of mobile devices. [Means for solving the problem]

[0007] The electronic control device of this disclosure is an electronic control device mounted on a vehicle, Memory units for storing keys (111, 121, 211, 221, 311, 321, 411, 421), Every set time , a matching unit (115, 125, 215, 225, 315, 325, 415, 425) that compares the key stored in the storage unit with key information, which is information about the key stored in a distributed ledger (200) located outside the vehicle, It is equipped with.

[0008] The numbers in parentheses attached to the claims and the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described later, and are not intended to limit the present invention. [Effects of the Invention]

[0009] The above-described configuration makes it possible to improve the reliability of the encryption keys used for communication between electronic control units of mobile devices. [Brief explanation of the drawing]

[0010] [Figure 1]Diagram illustrating a configuration example of a key management system according to each embodiment of the present disclosure [Figure 2] Block diagram illustrating a configuration example of an electronic control system according to each embodiment of the present disclosure [Figure 3] Block diagram illustrating an outline of features of each embodiment of the present disclosure [Figure 4] Block diagram illustrating an outline of features of each embodiment of the present disclosure [Figure 5] Block diagram illustrating a configuration example of an electronic control system and an electronic control device according to Embodiment 1 of the present disclosure [Figure 6] Flowchart illustrating the operation of the electronic control device according to Embodiment 1 of the present disclosure [Figure 7] Flowchart illustrating the operation of the electronic control device according to Embodiment 1 of the present disclosure [Figure 8] Block diagram illustrating a configuration example of an electronic control system and an electronic control device according to Embodiment 2 of the present disclosure [Figure 9] Block diagram illustrating a configuration example of an electronic control system and an electronic control device according to a modification of Embodiment 2 of the present disclosure [Figure 10] Block diagram illustrating a configuration example of an electronic control system and an electronic control device according to Embodiment 3 of the present disclosure [Figure 11] Block diagram illustrating a configuration example of an electronic control system and an electronic control device according to a modification of Embodiment 3 of the present disclosure [Figure 12] Flowchart illustrating the operation of the electronic control device according to Embodiment 3 of the present disclosure [Figure 13] Flowchart illustrating the operation of the electronic control device according to a modification of Embodiment 3 of the present disclosure [Figure 14] Block diagram illustrating an outline of an electronic control system according to Embodiment 4 of the present disclosure [Figure 15] Block diagram illustrating a configuration example of an electronic control system and an electronic control device according to Embodiment 4 of the present disclosure Description of Embodiments

[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0012] It should be noted that the present invention refers to the invention described in the claims or the section of means for solving the problem, and is not limited to the following embodiments. In addition, at least the phrases in angle brackets mean the phrases described in the claims or the section of means for solving the problem, and are likewise not limited to the following embodiments.

[0013] The configurations and methods described in the dependent claims of the claims are arbitrary configurations and methods in the invention described in the independent claims of the claims. The configurations and methods of the embodiments corresponding to the configurations and methods described in the dependent claims, as well as the configurations and methods that are not described in the claims but are only described in the embodiments, are arbitrary configurations and methods in the present invention. When the description of the claims is broader than the description of the embodiments, the configurations and methods described in the embodiments are also arbitrary configurations and methods in the present invention, in the sense that they are examples of the configurations and methods of the present invention. In any case, by being described in the independent claims of the claims, they become the essential configurations and methods of the present invention.

[0014] The effects described in the embodiments are effects obtained when having the configuration of the embodiments as examples of the present invention, and are not necessarily the effects possessed by the present invention.

[0015] When there are a plurality of embodiments, the configuration disclosed in each embodiment is not limited to only that embodiment, and combinations across embodiments are possible. For example, a configuration disclosed in one embodiment may be combined with another embodiment. In addition, the configurations disclosed in each of a plurality of embodiments may be collected and combined.

[0016] The problem described in the problem to be solved by the invention is not a publicly known problem, but has been independently identified by the inventor, and is a fact that affirms the inventive step of the invention together with the configuration and method of the present invention.

[0017] 1. Premises of Each Embodiment (1) Overall Configuration of Key Management System S First, the overall configuration of the key management system S will be described with reference to FIG. 1.

[0018] The key management system S comprises an electronic control system 100, a distributed ledger 200, and a certification authority 300, all of which are mounted on a mobile vehicle. Here, "Vehicle" refers to any movable object, regardless of its speed. It also includes vehicles that are stationary. Examples include, but are not limited to, automobiles, motorcycles, bicycles, and items mounted on them. "Loaded" includes not only cases where the item is directly fixed to the moving object, but also cases where it is not fixed to the moving object but moves with it. For example, this includes cases where the item is carried by a person riding on the moving object, or where it is loaded onto cargo placed on the moving object.

[0019] The electronic control system 100 consists of multiple electronic control units (ECUs (Electric Control Units), hereinafter abbreviated as ECUs) and an in-vehicle network connecting the ECUs. Details of the electronic control system 100 will be described later with reference to Figure 2.

[0020] Distributed Ledger 200, also known as a shared ledger or distributed ledger technology (DLT), is digital data agreed upon to be replicated, shared, and synchronized across multiple geographically different locations, countries, and institutions. More specifically, it involves sharing a portion of a database (ledger information) among multiple users, allowing each user to possess the same ledger information within their own system.

[0021] The distributed ledger 200 stores key information, which is information about keys used in the electronic control system 100 in the key management system S of each embodiment. In each embodiment, the distributed ledger 200 is located outside the vehicle. In each embodiment, a key is represented as key Xn (where n is an integer), and key information is represented as key information Xn (where n is an integer). Key information having the same Xn as a key means key information generated from key Xn. Note that for X, K represents a common key, S represents a private key, and P represents a public key, but this is an example, and other types of keys may be used.

[0022] In Figure 1, the distributed ledger 200 is shown as a single storage device, but in reality, it is distributed and stored across multiple storage devices. Each storage device is implemented, for example, on an external server or a cloud server. However, the distributed ledger 200 may be installed within the vehicle, connected to the electronic control system 100, or installed inside the electronic control system 100.

[0023] Certification Authority 300 issues digital certificates that electronically prove the trustworthiness of keys. For example, Certification Authority 300 verifies the identity of the key owner in some way and issues digital certificates that guarantee the key and its owner. In particular, in the key management system S of Embodiments 3 and 4, the certification authority 300 verifies the validity of the digital certificate in response to a request from the ECU constituting the electronic control system 100.

[0024] The certification authority 300 is implemented, for example, on an external server or a cloud server. Examples of external servers or cloud servers include servers installed by the manufacturer or distributor of the vehicle or electronic control system 100.

[0025] In Figure 1, the distributed ledger 200 and the certification authority 300 are implemented on separate devices, but the distributed ledger 200 and the certification authority 300 may be implemented on the same server or cloud server.

[0026] The electronic control system 100 and the distributed ledger 200, and the electronic control system 100 and the certification authority 300 are connected via a communication network using wireless communication and / or wired communication. Examples of wireless communication methods include IEEE 802.11 (Wi-Fi®), IEEE 802.16 (WiMAX®), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed ​​Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, and 5G. Alternatively, DSRC (Dedicated Short Range Communication) can be used. Examples of wired communication methods include LANs (Local Area Networks) such as Ethernet®, the Internet, fiber optic lines, and landline telephone lines. When a vehicle is parked in a parking lot or housed in a repair shop, a wired communication method can be used instead of a wireless communication method.

[0027] In addition, the communication line may be a combination of wireless communication lines and wired communication lines. For example, the connection between the electronic control system 100 and the base station equipment in the cellular system may be made using a wireless communication method such as 4G, and the connection between the base station equipment and the distributed ledger 200 or certification authority 300 may be made using a wired communication method such as a backbone line of a telecommunications carrier or the internet. A gateway device may be provided at the point of contact between the backbone line and the internet. Furthermore, communication between the distributed ledger 200 and the certification authority 300 can be conducted using any connection, including the internet.

[0028] (2) Overall configuration of the electronic control system 100 Figure 2 shows an example configuration of the electronic control system 100. The electronic control system 100 is composed of multiple ECUs, including an external communication ECU and an integrated ECU. Figure 2 illustrates one external communication ECU, one integrated ECU, and four individual ECUs, but naturally, the electronic control system 100 can be composed of any number of ECUs. Hereafter, the term "ECU" will be used to comprehensively refer to the external communication ECU, integrated ECU, and individual ECUs.

[0029] An external communication ECU is an ECU that communicates with the outside world. The communication methods used by the external communication ECU are as described above for wireless communication and wired communication. Multiple external communication ECUs may be provided to implement multiple communication methods.

[0030] An integrated ECU is an ECU equipped with a gateway function that mediates between individual ECUs and external communication ECUs. The integrated ECU may also be equipped with functions to control the entire electronic control system 100, such as security functions. The integrated ECU is sometimes called a gateway ECU (G-ECU) or a mobility computer (MC). Furthermore, the integrated ECU may also be a relay device or a gateway device.

[0031] The individual ECUs of the electronic control system 100 can be composed of ECUs having any function. For example, these include a drivetrain electronic control unit that controls the engine, steering wheel, brakes, etc., a vehicle system electronic control unit that controls meters, power windows, etc., an information system electronic control unit that controls navigation systems, etc., or a safety control system electronic control unit that controls to prevent collisions with obstacles or pedestrians. Furthermore, the ECUs do not have to be in parallel; they may be classified as masters and slaves.

[0032] Furthermore, the ECU may be a physically independent ECU, or it may be a virtually implemented virtual ECU (sometimes called a virtual machine).

[0033] In the case of Figure 2, the ECUs are connected via an in-vehicle communication network such as CAN (Controller Area Network) or LIN (Local Interconnect Network). Alternatively, they may be connected using any communication method, whether wired or wireless, such as Ethernet®, Wi-Fi®, or Bluetooth®. Note that "connection" refers to a state in which data can be exchanged, and includes not only cases where different hardware is connected via a wired or wireless communication network, but also cases where virtual machines implemented on the same hardware are virtually connected to each other.

[0034] (3) Outline of each embodiment Figures 3 and 4 show schematic diagrams of the features of each embodiment. Figure 3(a) corresponds to Embodiment 1. In Embodiment 1, when sending and receiving data between ECU11 and ECU12, ECU11 and ECU12 each verify the common key used against the key information stored in the distributed ledger 200. Figures 3(b1) and 3(b2) correspond to Embodiment 2. In Embodiment 2, when sending and receiving data between ECU21 and ECU22, ECU21 or ECU22 verifies the public key used against key information stored in the distributed ledger 200. Figures 4(c1) and 4(c2) correspond to Embodiment 3. In Embodiment 3, in addition to the configuration of Embodiment 2 shown in Figures 3(b1) and 3(b2), ECU31 or ECU32 performs a validity check of the electronic certificate with the certification authority. The features of Embodiment 4 will be described separately using Figure 14.

[0035] 2. Embodiment 1 (1) Configuration of Electronic Control Units (ECUs) 11 and 12 The configurations of ECU11 and ECU12 in this embodiment will be explained using Figure 5. This embodiment corresponds to Figure 3(a).

[0036] ECU11 and ECU12 can be any combination of ECUs shown in Figure 2, but in this embodiment, they are individual ECUs connected via an integrated ECU. The ECU 11 includes a storage unit 111, a control unit 112, a transmission unit 113, and a reception unit 114. The control unit 112 also includes a verification unit 115. The ECU12 includes a storage unit 121, a control unit 122, a transmission unit 123, and a reception unit 124. The control unit 122 also includes a verification unit 125.

[0037] ECUs 11 and 12 can be composed of a general-purpose CPU (Central Processing Unit), volatile memory such as RAM, non-volatile memory such as ROM, flash memory, or hard disk, various interfaces, and an internal bus connecting them. By executing software on this hardware, the functions of each functional block shown in Figure 5 can be performed. Of course, ECUs 11 and 12 may also be implemented using dedicated hardware such as LSIs. The same applies to ECUs in other embodiments.

[0038] In this embodiment, ECUs 11 and 12 are assumed to be in the form of semi-finished electronic control devices, but are not limited to this. For example, they can take the form of semiconductor circuits or semiconductor modules as components, and the form of finished products can be personal computers (PCs), smartphones, mobile phones, or navigation systems. The same applies to ECUs in other embodiments.

[0039] In the following, each block of ECU12 corresponding to each block of ECU11 will be described using ECU11 as a representative example, unless they have different operations or functions, and each block of ECU12 will refer to the description of the ECU11 block.

[0040] Memory units 111 and 121 store the common key K1 and common key K2 as "keys," respectively. Although common key K1 and common key K2 are the same key, they are stored in different memory units, and tampering with one of them can result in different keys. Therefore, different codes are assigned to distinguish them. Here, "key" refers to data used to control the steps of an encryption algorithm, and is used not only for encryption but also for digital signatures, message authentication codes (such as keyed hashes), etc. The seed used in pseudorandom numbers is also a type of key. Furthermore, the "key" stored in the memory unit may be a key used by this electronic control unit, or a key used by other electronic control units, etc. "Keys" include, for example, symmetric keys, private keys, and public keys. They may also be newly generated keys or keys that have been updated from old keys. Keys may have an expiration date.

[0041] The control unit 112 controls the operation of the storage unit 111, the transmission unit 113, and the reception unit 114. Furthermore, the control unit 112 itself implements the verification unit 115. In addition, the control unit 112 uses the common key K1 read from the storage unit 111 to decrypt encrypted data transmitted from the ECU 12 to the ECU 11, generate a message authentication code, and compare it with the received message authentication code. The control unit 122 uses the common key K2 read from the storage unit 121 to encrypt the data transmitted from the ECU 12 to the ECU 11 and to generate a message authentication code.

[0042] The transmitting unit 113 transmits data to the ECU 12 and other ECUs of the electronic control system 100. It also transmits data to the distributed ledger 200 and other devices via the external communication ECU.

[0043] The receiving unit 114 receives data from the ECU 12 and other ECUs of the electronic control system 100. It also receives data from the distributed ledger 200 and other devices via the external communication ECU.

[0044] The matching unit 115 "matches" the common key K1 stored in the storage unit 111 with the "key information" K1 stored in the distributed ledger 200 at a "predetermined timing". Similarly, the matching unit 125 "matches" the common key K2 stored in the storage unit 121 with the "key information" K2 stored in the distributed ledger 200 at a "predetermined timing". The matching results by the matching unit 115 may be stored in the storage units 111 and 121. Details of the matching unit 115 will be explained in the next section. Here, "Predetermined timing" can be any temporal indicator based on a predetermined rule, such as time, duration, clock cycle, counter, period, or frequency. It can also be a fixed value or a variable value that changes depending on the conditions. "Key information" can refer to information about the key itself, or it can refer to the key itself. "To verify" includes not only directly verifying the identity of keys, but also indirectly verifying whether key information, which is information about a key, originates from that key.

[0045] (2) Details of the verification unit 115 (a) Reasons for providing the verification unit 115 The control unit 122 of ECU12 encrypts the data to be transmitted to ECU11 using the common key K2 read from the storage unit 121. The transmission unit 123 transmits the encrypted data to ECU11 via the integrated ECU. The receiving unit 114 of ECU11 receives the encrypted data. Then, the control unit 112 decrypts the encrypted data using the common key K1 read from the storage unit 111.

[0046] When sending and receiving such data, if the shared key K1 is tampered with through hacking or other means, it will be impossible to decrypt the data that is actually needed. Furthermore, if both the shared key K1 and the shared key K2 are tampered with through hacking or other means, there is a possibility that false data will be decrypted and used. To prevent this, in this embodiment, the shared key K1 is compared with the key information K1 stored in the distributed ledger 200 to check whether it has been rewritten through hacking or other means.

[0047] Instead of managing the common key K1 solely within the electronic control system 100, managing it using a distributed ledger 200 located outside the electronic control system 100 makes it difficult to tamper with the common key K1. In other words, attempting to tamper with the common key K1 would require hacking not only the electronic control system 100 but also the distributed ledger 200. Furthermore, by storing the key information K1 on the distributed ledger 200 rather than on a regular server or cloud server, the key information K1 becomes more resistant to tampering in light of the characteristics of blockchain, and even if it is tampered with, detection becomes easier.

[0048] (b) Key information stored in the distributed ledger 200 The key information K1 stored in the distributed ledger 200 is information about key K1. Key information K1 only needs to contain enough information to verify the identity of key K1. For example, it could be the serial number of the common key K1, the MAC value of that serial number, the MAC value of the common key K1, or attribute information of the common key K1. Of course, key information K1 can also be the common key K1 itself.

[0049] The method for registering key information K1 in the distributed ledger 200, that is, the method for storing key information K1 in the distributed ledger 200, is arbitrary, but we will explain with a few examples.

[0050] As a first example, the ECU 11 itself may transmit key information K1 to the distributed ledger 200. That is, the control unit 112 may read the common key K1 from the storage unit 111 and transmit the common key K1 from the transmission unit 113, or the control unit 112 may obtain and transmit the serial number of the common key K1, the MAC value of the common key, etc. When transmitting, the data may be transmitted directly to the distributed ledger 200 or indirectly. That is, the transmission unit 113 may transmit to other ECUs within the electronic control system 100 (for example, a DCM (Data Communication Module) or other ECUs in the mobile unit), and the other ECUs may then transmit the information to the distributed ledger 200. Alternatively, the data may be transmitted via other external devices such as a server, relay device, or certification authority 300. A distributed ledger that receives key information K1 may store the received key information K1 as is, or it may, for example, retrieve and store the serial number or MAC value of the shared key K1 from the received shared key K1.

[0051] As a second example, when registering a vehicle or performing repairs, the vehicle manufacturer, dealer, or repair shop may write the common key K1 and key information K1 to the ECU11 and distributed ledger 200 from a computer or other device under their control.

[0052] As a third example, the integrated ECU of the electronic control system 100 may transmit the common key K1 and key information K1 to the ECU 11 and the distributed ledger.

[0053] (c) Method of verification The comparison between the common key K1 stored in the memory unit 111 and the key information K1 stored in the distributed ledger may be performed by the ECU 11 itself or by another device.

[0054] If the ECU 11 performs the operation itself, the control unit 112 reads the common key K1 from the storage unit 111, and the receiving unit 114 receives the key information K1 sent from the distributed ledger 200 in response to the key information request sent from the transmission unit 113 based on the instructions of the control unit 112. Then, the verification unit 115 compares the common key K1 and the key information K1 and verifies whether the common key K1 has not been tampered with based on whether or not the common points that the common key K1 and the key information K1 should have.

[0055] An example of this being performed by another device is when the verification is carried out by a device that manages the distributed ledger 200. Based on instructions from the control unit 112 of the ECU 11, the transmission unit 113 generates key information K1 from the common key K1 stored in the storage unit 111 and transmits it. The device that manages the distributed ledger 200 then verifies the key information K1 stored in the distributed ledger 200 by comparing it with the key information K1 transmitted from the ECU 11 and transmits the result to the ECU 11. The ECU 11 receives the result with the receiving unit 114 and verifies the result with the verification unit 115. Other devices besides the one managing the distributed ledger 200 include other external devices and other ECUs other than ECU11, such as ECU12.

[0056] (d) Timing of matching To detect tampering caused by cyberattacks, it is desirable for ECU11 to perform a verification each time it receives encrypted data from ECU12. However, the number of communications between ECUs in the electronic control system 100 is very high, for example, more than 10 times per second. Furthermore, since vehicles equipped with the electronic control system 100 are constantly moving, communication with the outside world is not always stable. Therefore, if the data is compared against the distributed ledger 200 every time there is communication between ECUs, the volume of communication will increase, potentially saturating the communication lines and making the comparison itself difficult. Furthermore, since communication with the outside is generally not possible while parked, verification is impossible. Therefore, it is desirable to perform verification as soon as communication with the outside is restored. Therefore, the matching unit 115 performs matching at a predetermined timing. The following are examples of predetermined timings.

[0057] (Example 1) While the vehicle is in motion, if the electronic control system 100 installed in the vehicle is capable of communicating with the outside, the system performs verification once or multiple times at predetermined intervals (corresponding to the "first predetermined interval"), or once or multiple times for every predetermined number of communications (corresponding to the "first predetermined interval") between the ECU 11 and other ECUs within the electronic control system 100. In other words, the verification may be synchronized with the timing of communication between the ECU 11 and other ECUs, or it may not be synchronized. With the above configuration, it is possible to prevent the communication volume with the distributed ledger 200 from increasing and saturating the communication line, and to perform matching of the common key K1 more stably.

[0058] Furthermore, this predetermined time or predetermined number of communications may be determined according to the vehicle speed. In other words, it may change depending on the vehicle speed. Generally, the amount of communication between ECUs is large when the vehicle speed is high, and generally the amount of communication between ECUs is small when the vehicle speed is low, so the faster the vehicle speed, the shorter the predetermined time should be. For example, the predetermined time could be 1 second when the speed is high (e.g., 40 km / h or more), and 3 seconds when the speed is low (e.g., 10 km / h or less). Alternatively, the predetermined time may be set for each category such as low speed, medium speed, and high speed. The number of categories is arbitrary. Alternatively, there may be no categories, and the time may change continuously. This configuration reduces and equalizes the risks and resulting damages caused by cyberattacks. In particular, it prevents excessive use of resources necessary for external communication.

[0059] (Example 2) If the electronic control system 100 installed in the vehicle does not communicate with the outside for a predetermined time (corresponding to the "second predetermined time") or longer, verification is performed within a predetermined time (corresponding to the "third predetermined time") after communication with the outside is resumed. Examples of resuming communication include the start of communication after a communication interruption is resolved, as well as the start of communication associated with vehicle startup, such as engine start. It also includes the start of communication with a new external device. The second predetermined time is any time, such as 5 minutes or 10 minutes. The third predetermined time is any time, such as within 1 second or within 3 seconds from the start of communication with the outside, and a shorter time is preferable. With the above configuration, verification can be performed quickly at the time of communication restoration after a communication interruption when verification is not possible, or at the time of vehicle startup when the system is unstable and susceptible to cyberattacks.

[0060] (Example 3) When the vehicle is parked, if the electronic control system 100 installed in the vehicle is capable of communicating with the outside, it is necessary to perform checks at predetermined intervals (corresponding to the "fourth predetermined interval"). When the vehicle is parked, it means that the engine is turned off. When the vehicle is parked, the vehicle is often unoccupied, and unlike cyberattacks, there is a risk of attacks such as hacking by suspicious individuals through physical connections. Therefore, it is desirable to perform periodic checks even when the vehicle is parked. The fourth predetermined interval is any time, such as one or two hours. Since the risk associated with vehicle loss of control is lower than when the vehicle is in motion, the fourth predetermined interval can be set to be longer than the first and second predetermined intervals. Since communication is necessary even when the engine is off, it is desirable to use a low-power communication method such as LPWA (Low Power Wide Area). With the above configuration, even when the vehicle is parked, it is possible to perform a check in anticipation of the possibility of an attack on the electronic control system 100.

[0061] (e) Vehicle communication status The predetermined timing may be determined according to the vehicle's communication status. The vehicle's communication status can change depending on factors such as the vehicle's driving status (including stopping and parking), driving location, and driving speed. Furthermore, if multiple wireless communication methods are used for communication with the outside world, the wireless communication method used can be changed. For example, the frequency of matching when using a high-speed connection may be greater than the frequency of matching when using a slow-speed connection. This helps to avoid saturation of the communication line. Alternatively, the frequency of matching when using a free or low-cost line may be higher than the frequency of matching when using a high-cost line. Alternatively, when using the same line continuously, the frequency of matching may be changed according to the line's response speed, signal-to-noise ratio, or radio wave reception strength.

[0062] (f) Verification in electronic control systems The above explanation focuses on ECU 11, but as shown in Figure 2, the electronic control system 100 installed in a vehicle is usually composed of multiple ECUs. Each ECU included in the electronic control system 100 performs the verification described above individually. However, it is not always necessary for all ECUs included in the electronic control system 100 to perform the verification.

[0063] The predetermined timings in each ECU may differ. For example, it is desirable to set the frequency of a predetermined timing for the external communication ECU that serves as the entry point (corresponding to the "first electronic control unit") to be higher than the frequency of predetermined timings for other ECUs (corresponding to the "second electronic control unit"). This can raise the security level of the external communication ECU, which is at high risk of cyberattacks. Alternatively, it is desirable to set the frequency of predetermined timings for the ECUs that control autonomous driving and the drivetrain ECUs (corresponding to the "first electronic control unit") to be higher than the frequency of predetermined timings for other ECUs (corresponding to the "second electronic control unit"). This can suppress the manifestation of risks due to cyberattacks. Alternatively, it is desirable that the frequency of predetermined timings in ECUs with a high volume and frequency of communication within the vehicle (corresponding to the "first electronic control unit") be higher than the frequency of predetermined timings in other ECUs (corresponding to the "second electronic control unit"). For example, the integrated ECU has a gateway function, so it has a higher volume of communication than other ECUs. This can improve the reliability of each communication within the vehicle.

[0064] (g) Other In the above description of the matching unit 115, the case in which the common key K1 is used to decrypt encrypted data was given, but it may also be used for other purposes such as message authentication. Furthermore, the matching process may or may not be synchronized with the sending and receiving of data. Furthermore, although the above explanation of the matching unit 115 focused on the ECU 11 and the common key K1 that decrypt the encrypted data, the same applies to the ECU 12 and the common key K2 that encrypt the data, in which case the explanation should be read as the explanation of ECU 12 and the common key K2. The distributed ledger 200 may store key information along with a vehicle ID to identify the vehicle and an ECU ID to identify the ECU. When retrieving key information from the distributed ledger, the vehicle ID or ECU ID may be specified. Furthermore, the above description of the matching unit 115 can be applied not only to this embodiment but also to other embodiments. In other embodiments, a private key and a public key are used, so the description of the common key K1 should be read as the public key Pn (where n is an integer).

[0065] (3) Operation of electronic control units (ECUs) 11 and 12 The operation of matching the common key K1 and decoding the received data in the ECU11 of this embodiment will be explained using the flowchart in Figure 6. The following operations not only illustrate the key verification method executed by ECU11, but also the processing steps of the key verification program that can be executed by ECU11. Furthermore, these processes are not limited to the order shown in Figure 6. That is, the order can be changed unless there are constraints such as a relationship where one step utilizes the result of the preceding step. The same applies to flowcharts other than Figure 6 in all embodiments.

[0066] ECU11 stores the common key K1 in the memory unit 111 (S111). The transmission unit 113 of the ECU 11 transmits the key information K1, which is information about the common key K1 stored in the storage unit 111, to the distributed ledger 200 (S112). Subsequently, at any time, the receiving unit 114 of ECU11 receives the encrypted data (S113). For example, if the common key K1 and common key K2 are the same key, the receiving unit 114 of ECU11 receives the data encrypted by ECU12 using common key K2.

[0067] The matching unit 115 determines whether it is the predetermined timing (S114). If it determines that it is the predetermined timing (S114: YES), the transmitting unit 113 sends a request for key information to the distributed ledger 200, and the receiving unit 114 receives the key information K1 sent from the distributed ledger 200 (S115). The matching unit 115 compares the common key K1 read from the storage unit 111 with the key information K1 received from the distributed ledger 200 (S116). If it determines that the common key K1 has not been tampered with (S117: YES), it decrypts the encrypted data received in S113 using the common key K1 (S118). If it determines that the common key K1 has been tampered with (S117: NO), it does not decrypt the encrypted data received in S113 (S119). Also, if it is not determined that the predetermined timing has arrived (S114: NO), it decrypts the encrypted data received in S113 (S118).

[0068] As previously mentioned, it is not necessarily the ECU11 that transmits the key information K1, which is information related to the common key K1, to the distributed ledger 200; therefore, S112 is an optional step in this embodiment. Furthermore, decryption may involve decrypting all data transmitted and received between ECUs, or it may involve decrypting only a portion of the data, such as the data portion within an Ethernet frame. Furthermore, although Figure 6 shows that the predetermined timing and the decryption of encrypted data are synchronized, they may be asynchronous. For example, the matching result by the matching unit 115 may be stored in the storage unit 111, and when decrypting encrypted data using the common key K1, the matching result may be read from the storage unit 111, and the control unit 112 may determine whether or not to use the common key K1 based on the matching result.

[0069] The operation of matching the common key K2 and encrypting the transmitted data in the ECU12 of this embodiment will be explained using the flowchart in Figure 7.

[0070] ECU12 stores the common key K2 in the memory unit 121 (S121). The transmission unit 123 of the ECU 12 transmits the key information K2, which is information about the common key K2 stored in the storage unit 121, to the distributed ledger 200 (S122).

[0071] The matching unit 125 determines whether it is the predetermined timing (S123). If it determines that it is the predetermined timing (S123: YES), the transmitting unit 123 sends a request for key information to the distributed ledger 200, and the receiving unit 124 receives the key information K2 sent from the distributed ledger 200 (S124). The matching unit 125 compares the common key K2 read from the storage unit 121 with the key information K2 received from the distributed ledger 200 (S125). If it determines that the common key K2 has not been tampered with (S126: YES), it encrypts the data using the common key K2 and transmits it (S127). If it determines that the common key K2 has been tampered with (S126: NO), it does not encrypt the data and does not transmit it (S128). Also, if it is not determined that the predetermined timing has arrived (S123: NO), it encrypts the data and transmits it (S127).

[0072] As previously mentioned, it is not necessarily the ECU12 that transmits the key information K2, which is information related to the common key K2, to the distributed ledger 200; therefore, S122 is an optional step in this embodiment. Furthermore, encryption may involve encrypting all data transmitted and received between ECUs, or it may involve encrypting only a portion of the data, such as the data portion within an Ethernet frame. Furthermore, although Figure 7 shows that the encryption and transmission of data are synchronized with a predetermined timing, they may be asynchronous. For example, the matching result by the matching unit 125 may be stored in the storage unit 121, and when encrypting data using the common key K2, the matching result may be read from the storage unit 121, and the control unit 122 may determine whether or not to use the common key K2 based on the matching result.

[0073] (4) Summary As described above, according to this embodiment, since key information K1 and key information K2 are stored in a distributed ledger and compared with the common key K1 and common key K2, tampering with the common key K1 and common key K2 can be detected more accurately. Furthermore, according to this embodiment, since the common key K1 is compared with key information K1 and the common key K2 with key information K2 at predetermined timings, it is possible to prevent the communication volume with the distributed ledger 200 from increasing and saturating the communication line, and to perform the comparison of common keys K1 and K2 more stably. As a result, the security of common keys K1 and K2 can be ensured.

[0074] 3. Embodiment 2 (1) Configuration of Electronic Control Units (ECUs) 21 and 22 Embodiment 1 used a common key to send and receive data in the electronic control system 100. This embodiment differs from Embodiment 1 in that it uses a private key and a public key instead of a common key. Below, only the parts that differ from Embodiment 1 will be described, and parts that are the same as Embodiment 1 will be referenced from the description of Embodiment 1.

[0075] The configurations of ECU21 and ECU22 in this embodiment will be explained using Figure 8. This embodiment corresponds to Figure 3(b1).

[0076] ECU21 and ECU22 can be any combination of ECUs shown in Figure 2, but in this embodiment, they are individual ECUs connected via an integrated ECU. The ECU21 includes a storage unit 211, a control unit 212, a transmission unit 213, and a reception unit 214. The ECU22 includes a storage unit 221, a control unit 222, a transmission unit 223, and a reception unit 224. The control unit 222 also includes a verification unit 225.

[0077] Memory unit 221 stores the public key P2. Memory unit 211 stores the private key S1 and the public key P1. Although public key P2 and public key P1 are the same key, they are stored in different memory units, and tampering with one of them can result in different keys. Therefore, different codes are assigned to distinguish them here.

[0078] In this embodiment, ECU21 generates a public key P1 using the private key S1. Then, the transmitting unit 213 transmits the public key P1 to ECU22, and the receiving unit 224 of ECU22 receives the public key P1. Upon receiving the public key, ECU22 stores the public key P1 as public key P2 in the storage unit 221.

[0079] In this embodiment, the control unit 222 of ECU22 encrypts the data to be transmitted to ECU21 using the public key P2 read from the storage unit 221. The transmission unit 223 transmits the encrypted data to ECU21 via the integrated ECU. The receiving unit 214 of ECU21 receives the encrypted data. Then, the control unit 212 decrypts the encrypted data using the secret key S1 read from the storage unit 211.

[0080] The matching unit 225 of the ECU 22 compares the public key P2 stored in the storage unit 221 with the key information P2 stored in the distributed ledger 200 at a predetermined timing. The details of the matching unit 225 are the same as those of the matching unit 115 described in Embodiment 1, except that the matching unit 225 uses the public key P2 and the key information P2. Therefore, the description of Embodiment 1 is referenced with the assumptions of this embodiment and the explanation is omitted. However, although ECU21 also has a public key P1, it is intended for distribution to other ECUs, etc., and ECU21 does not normally use the public key P1. Therefore, the control unit 212 is not provided with a matching unit. However, similar to Embodiment 1, ECU21 may also be provided with a matching unit 215 to perform a comparison between the public key P1 stored in the storage unit 211 and the key information P1 stored in the distributed ledger 200.

[0081] Since the operation of ECU22 is the same as that of ECU12 in Embodiment 1 and in Figure 7, the description of Embodiment 1 is referenced with the assumptions of this embodiment, and the explanation is omitted.

[0082] (2) Variant Figure 9 shows the configuration of ECU21 and ECU22 in a modified example of this embodiment, and corresponds to Figure 3(b2).

[0083] ECU21 and ECU22 can be any combination of ECUs shown in Figure 2, but in this embodiment, they are individual ECUs connected via an integrated ECU. The ECU21 includes a storage unit 211, a control unit 212, a transmission unit 213, and a reception unit 214. The control unit 212 also includes a verification unit 215. The ECU22 includes a storage unit 221, a control unit 222, a transmission unit 223, and a reception unit 224.

[0084] Memory unit 221 stores the private key S1 and the public key P1. Memory unit 211 stores the public key P2. Although public key P1 and public key P2 are the same key, they are stored in different memory units, and tampering with one of them can result in different keys. Therefore, different codes are assigned to distinguish them here.

[0085] In this modified example, ECU22 generates a public key P1 using the private key S1. Then, the transmitting unit 223 sends the public key P1 to ECU21, and the receiving unit 214 of ECU21 receives the public key P1. Upon receiving the public key, ECU21 stores the public key P1 as public key P2 in the storage unit 211.

[0086] In this embodiment, the control unit 222 of ECU22 generates an electronic signature for the data to be transmitted to ECU21 using the secret key S1 read from the storage unit 221. The transmission unit 223 transmits the data and electronic signature to ECU21 via the integrated ECU. The receiving unit 214 of ECU21 receives the data and electronic signature. The control unit 212 then decrypts the electronic signature using the public key P2 read from the storage unit 211.

[0087] The matching unit 215 of the ECU 21 compares the public key P2 stored in the storage unit 211 with the key information P2 stored in the distributed ledger 200 at a predetermined timing. The details of the matching unit 215 are the same as those of the matching unit 115 described in Embodiment 1, except that the matching unit 215 uses the public key P2 and the key information P2. Therefore, the description of Embodiment 1 is referenced with the assumptions of this embodiment and the explanation is omitted. However, although ECU22 also possesses a public key P1, it is intended for distribution to other ECUs, etc., and ECU22 does not normally use the public key P1. Therefore, the control unit 222 is not provided with a matching unit. However, similar to Embodiment 1, ECU22 may also be provided with a matching unit 225 to perform a comparison between the public key P1 stored in the storage unit 221 and the key information P1 stored in the distributed ledger 200.

[0088] Since the operation of ECU21 is the same as that of ECU11 in Embodiment 1 and in Figure 6, the description of Embodiment 1 is referenced with the assumptions of this embodiment, and the explanation is omitted.

[0089] (3) Summary As described above, according to this embodiment, since key information K1 and key information K2 are stored in a distributed ledger and compared with the common key K1 and common key K2, tampering with the common key K1 and common key K2 can be detected more accurately. Furthermore, by comparing the public key P2 with the key information P2 at predetermined timings, it is possible to prevent the communication volume with the distributed ledger 200 from increasing and saturating the communication line, thereby enabling more stable matching of the public key P2. As a result, the security of the public key P2 can be ensured.

[0090] 4. Embodiment 3 (1) Configuration of Electronic Control Units (ECUs) 31 and 32 This embodiment, in addition to verifying the public key as in Embodiment 2, also issues an electronic certificate for the public key and verifies the validity of the electronic certificate. Below, only the parts added to Embodiment 2 or the parts that differ from Embodiment 2 will be described, and parts that are the same as Embodiment 2 will be referenced from the description of Embodiment 2.

[0091] The configurations of ECU31 and ECU32 in this embodiment will be described using Figure 10. This embodiment corresponds to Figure 4(c1).

[0092] ECU31 and ECU32 can be any combination of ECUs shown in Figure 2, but in this embodiment, they are individual ECUs connected via an integrated ECU. The ECU31 includes a storage unit 311, a control unit 312, a transmission unit 313, and a reception unit 314. The ECU32 includes a storage unit 321, a control unit 322, a transmission unit 323, and a reception unit 324. The control unit 322 also includes a verification unit 325 and a validity verification unit 326.

[0093] Memory unit 321 stores the public key P2. Memory unit 311 stores the private key S1 and the public key P1. Although public key P2 and public key P1 are the same key, they are stored in different memory units, and tampering with one of them can result in different keys. Therefore, different codes are assigned to distinguish them here.

[0094] In this embodiment, similar to Embodiment 2, ECU 31 generates a public key P1 using the private key S1. Then, the transmitting unit 313 transmits the public key P1 to ECU 32, and the receiving unit 324 of ECU 32 receives the public key P1. Upon receiving the public key, ECU 32 stores the public key P1 as public key P2 in the storage unit 321.

[0095] Furthermore, in this embodiment, the ECU 31 transmits the generated public key P1 to the certification authority 300 via the transmission unit 313, and the certification authority 300 issues an electronic certificate for the public key P1 and transmits it to the ECU 31. The electronic certificate is a certificate that guarantees the public key P1 and the device that owns it. The receiving unit 314 of the ECU 31 receives the public key P1 with the electronic certificate attached and stores the electronic certificate in the storage unit 311. Then, the transmission unit 313 of the ECU 31 transmits the electronic certificate to the ECU 32, and the receiving unit 324 of the ECU 32 receives the electronic certificate. The ECU 32, having received the electronic certificate, stores it in the storage unit 321. The electronic certificate from ECU31 to ECU32 may be sent at the same time as the public key P1 is sent. Furthermore, the electronic certificate can be sent only once initially, or it can be sent periodically.

[0096] The method for storing key information P2 in the distributed ledger 200 can be the method illustrated in Embodiment 1, but the certification authority 300 may send the public key P1 to the distributed ledger 200, and the distributed ledger 200 may generate and store the key information P2. Alternatively, the certification authority 300 may generate and send key information P2 from the public key P1, and the distributed ledger 200 may store the key information P2.

[0097] In this embodiment, the control unit 322 of ECU 32 encrypts the data to be transmitted to ECU 31 using the public key P2 read from the storage unit 321. The transmission unit 323 transmits the encrypted data to ECU 31 via the integrated ECU. The receiving unit 314 of ECU 31 receives the encrypted data. Then, the control unit 312 decrypts the encrypted data using the secret key S1 read from the storage unit 311.

[0098] The matching unit 325 compares the public key P2 stored in the storage unit 321 with the key information P2 stored in the distributed ledger 200 at a predetermined timing. The details of the matching unit 325 are the same as those of the matching unit 115 described in Embodiment 1, except that the matching unit 325 uses the public key P2 and the key information P2. Therefore, the description of Embodiment 1 is referenced with the assumptions of this embodiment and the explanation is omitted.

[0099] The validity verification unit 326 verifies the validity of the digital certificate received from the ECU 31. Specifically, the validity verification unit 326 sends a verification signal from the transmission unit 323 to the certification authority 300 inquiring about the validity of the digital certificate for public key P2. Upon receiving the verification signal, the certification authority 300 verifies the validity of the digital certificate indicated in the verification signal and sends the verification result to the ECU 32. The validity verification checks, for example, the authenticity of the digital certificate and the expiration date of the digital certificate. The receiving unit 324 of the ECU 32 receives the verification result.

[0100] The "frequency" of validity verification by the validity verification unit 326 is preferably lower than the "frequency" of the predetermined timing of verification in the verification unit 325. Here, "frequency" refers to any number of times information is transmitted within a given time, either directly or indirectly, and may be expressed in terms of cycle, time, etc., in addition to the number of times.

[0101] For example, the frequency of validity checks could be set to coincide with the vehicle's mandatory inspections or vehicle inspections, or it could be set to occur at relatively long intervals, such as once a year. Alternatively, the frequency of validity checks could be set arbitrarily. Or it could be done when the vehicle is started up or as a one-time check upon delivery. Alternatively, the validity check may be performed if a defect is detected during the verification by the verification unit 325.

[0102] (2) Variant Figure 11 shows the configuration of ECU31 and ECU32 in a modified example of this embodiment, and corresponds to Figure 4(c2).

[0103] ECU31 and ECU32 can be any combination of ECUs shown in Figure 2, but in this embodiment, they are individual ECUs connected via an integrated ECU. The ECU31 includes a storage unit 311, a control unit 312, a transmission unit 313, and a reception unit 314. The control unit 312 also includes a verification unit 315 and a validity verification unit 316. The ECU32 includes a storage unit 321, a control unit 322, a transmission unit 323, and a reception unit 324.

[0104] Memory unit 321 stores the private key S1 and the public key P1. Memory unit 311 stores the public key P2. Although public key P1 and public key P2 are the same key, they are stored in different memory units, and tampering with one of them can result in different keys. Therefore, different codes are assigned to distinguish them here.

[0105] In this embodiment, similar to the modified embodiment of Embodiment 2, the ECU 32 generates a public key P1 using the private key S1. The transmitting unit 323 then transmits the public key P1 to the ECU 31, and the receiving unit 314 of the ECU 31 receives the public key P1. Upon receiving the public key, the ECU 31 stores the public key P1 as public key P2 in the storage unit 311.

[0106] Furthermore, in this embodiment, the ECU 32 transmits the generated public key P1 to the certification authority 300 via the transmission unit 323, and the certification authority 300 issues a digital certificate for the public key P1 and transmits it to the ECU 32. The digital certificate is a certificate that guarantees the public key P1 and the device that owns it. The receiving unit 324 of the ECU 32 receives the public key P1 with the digital certificate attached and stores the digital certificate in the storage unit 321. Then, the transmission unit 323 of the ECU 32 transmits the digital certificate to the ECU 31, and the receiving unit 314 of the ECU 31 receives the digital certificate. The ECU 31, having received the digital certificate, stores it in the storage unit 311. Furthermore, the sending of the digital certificate from ECU32 to ECU31 may be performed simultaneously with the sending of the public key P1. Furthermore, the electronic certificate can be sent only once initially, or it can be sent periodically.

[0107] The method for storing key information P2 in the distributed ledger 200 can be the method illustrated in Embodiment 1, but the certification authority 300 may send the public key P1 to the distributed ledger 200, and the distributed ledger 200 may generate and store the key information P2. Alternatively, the certification authority 300 may generate and send key information P2 from the public key P1, and the distributed ledger 200 may store the key information P2.

[0108] In this embodiment, the control unit 322 of ECU 32 generates an electronic signature for the data to be transmitted to ECU 31 using the secret key S1 read from the storage unit 321. The transmission unit 323 transmits the data and electronic signature to ECU 31 via the integrated ECU. The receiving unit 314 of ECU 31 receives the data and electronic signature. The control unit 312 then decrypts the electronic signature using the public key P1 read from the storage unit 311.

[0109] The matching unit 315 compares the public key P2 stored in the storage unit 311 with the key information P2 stored in the distributed ledger 200 at a predetermined timing. The details of the matching unit 315 are the same as those of the matching unit 115 described in Embodiment 1, except that the matching unit 315 uses the public key P2 and the key information P2. Therefore, the description of Embodiment 1 is referenced with the assumptions of this embodiment and the explanation is omitted.

[0110] The validity verification unit 316 verifies the validity of the digital certificate received from the ECU 32. Specifically, the validity verification unit 316 sends a verification signal from the transmission unit 313 to the certification authority 300 inquiring about the validity of the digital certificate for public key P2. Upon receiving the verification signal, the certification authority 300 verifies the validity of the digital certificate indicated in the verification signal and sends the verification result to the ECU 31. The validity verification checks, for example, the authenticity of the digital certificate and the expiration date of the digital certificate. The receiving unit 314 of the ECU 31 receives the verification result.

[0111] (3) Operation of electronic control units (ECUs) 31 and 32 The operation of verifying the public key P2 and encrypting the transmitted data in the ECU32 of this embodiment will be explained using the flowchart in Figure 12.

[0112] First, let's look at the operation of ECU31. The control unit 312 of ECU31 generates a public key P1 using the private key S1 (S311). The transmitting unit 313 sends the generated public key P1 and a request for issuance of an electronic certificate to the certification authority 300 (S312). The receiving unit 314 receives the digital certificate issued by the certification authority 300 (S313). Then, the transmitting unit 313 transmits the public key P1 and the digital certificate to the ECU 32 (S314).

[0113] Next, let's look at the operation of the ECU32. The receiving unit 324 of the ECU32 receives the public key P1 and the digital certificate and stores them in the storage unit 321 as the public key P2 and the digital certificate (S321). The validity verification unit 326 determines whether it is time to verify the validity of the electronic certificate (S322). If it is time to verify the validity of the electronic certificate (S322: YES), the validity verification unit 326 sends a verification signal to the certification authority 300 to inquire about the validity of the electronic certificate and receives an authentication result from the certification authority 300 (S323). If it is not time to verify the validity (S322: NO), the process proceeds to determining whether it is a predetermined time (S325). If the digital certificate is valid (S324:YES), the verification unit 325 determines whether the predetermined timing has arrived (S325). If it determines that the predetermined timing has arrived (S325:YES), the transmission unit 323 sends a request for key information to the distributed ledger 200, and the receiving unit 324 receives the key information P2 sent from the distributed ledger 200 (S326). The matching unit 325 compares the public key P2 read from the storage unit 321 with the key information P2 received from the distributed ledger 200 (S327). If it determines that the public key P2 has not been tampered with (S328: YES), it encrypts the data using the public key P2 and transmits it (S329). If it determines that the public key P2 has been tampered with (S328: NO), it does not encrypt the data and does not transmit it (S330). Also, if the digital certificate is not valid (S324: NO), it does not encrypt the data and does not transmit it (S330). Furthermore, if it does not determine that the predetermined timing has not occurred (S325: NO), it encrypts the data using the public key P2 and transmits it (S329).

[0114] Using the flowchart in Figure 13, the operations of verifying the public key P2 and decrypting the digital signature in the modified ECU31 of this embodiment will be explained.

[0115] First, let's look at the operation of ECU32. The control unit 322 of ECU32 generates a public key P1 using the private key S1 (S311). The transmitting unit 323 sends the generated public key P1 and a request for issuance of an electronic certificate to the certification authority 300 (S312). The receiving unit 324 receives the digital certificate issued by the certification authority 300 (S313). Then, the transmitting unit 323 transmits the public key P1 and the digital certificate to the ECU 31 (S314).

[0116] Next, let's look at the operation of the ECU31. The receiving unit 314 of the ECU31 receives the public key P1 and the digital certificate and stores them in the storage unit 311 as the public key P2 and the digital certificate (S321). Subsequently, at any time, the receiving unit 314 of ECU31 receives the encrypted data (S322). For example, the receiving unit 314 of ECU31 receives the digital signature and data generated by ECU32 using the secret key S1. The validity verification unit 316 determines whether it is time to verify the validity of the electronic certificate (S323). If it is time to verify the validity of the electronic certificate (S323:YES), the validity verification unit 316 sends a verification signal to the certification authority 300 to inquire about the validity of the electronic certificate and receives an authentication result from the certification authority 300 (S324). If it is not time to verify the validity (S323:NO), the process proceeds to determining whether it is a predetermined time (S326). If the digital certificate is valid (S325:YES), the verification unit 315 determines whether it is the predetermined timing (S326). If it determines that it is the predetermined timing (S326:YES), the transmission unit 313 sends a request for key information to the distributed ledger 200, and the receiving unit 314 receives the key information P2 sent from the distributed ledger 200 (S327). The matching unit 315 compares the public key P2 read from the storage unit 311 with the key information P2 received from the distributed ledger 200 (S328). If it determines that the public key P2 has not been tampered with (S329: YES), it decrypts the data and digital signature using the public key P2 (S330). If it determines that the public key P2 has been tampered with (S329: NO), it does not decrypt the data and digital signature (S331). Also, if the digital certificate is not valid (S325: NO), it does not decrypt the data and digital signature (S331). Furthermore, if it does not determine that the predetermined timing has not arrived (S326: NO), it decrypts the data and digital signature using the public key P2 (S330).

[0117] (4) Others In this embodiment and its modified form, the description focuses on the two ECUs of the electronic control system 100, namely the data transmission side and the data reception side, but the same applies to other ECUs included in the electronic control system 100. In this case, the distributed ledger and certification authority used by the other ECUs may be different from the distributed ledger 200 and certification authority 300. That is, if the electronic control system 100 includes ECUs manufactured by multiple manufacturers or ECUs provided for individual services, for example, each ECU manufacturer or service provider may use its own managed distributed ledger and certification authority.

[0118] (5) Summary In this embodiment, in addition to the effects of Embodiment 1 or Embodiment 2, a validity verification unit is included, so that the security of the public key P2 can be further ensured by the electronic certificate issued by the certification authority. Furthermore, by setting the frequency of validity verification by the validity verification unit lower than the frequency of the predetermined timing for matching, the security of the public key P2 can be enhanced while moderately reducing the amount of data transmitted over the communication line.

[0119] 5. Embodiment 4 In embodiments 1 to 3, it was assumed that the distributed ledger 200 was located outside the vehicle. This embodiment, however, is a case where the distributed ledger 200 is also located inside the vehicle, that is, in other ECUs included in the electronic control system 100 mounted on the vehicle.

[0120] The outline of this embodiment will be explained using Figure 14. Figure 14(a) shows the counterparties for verification and validity confirmation in Embodiment 3. In Embodiment 3, the verification unit 325 of the ECU 32 used the distributed ledger 200 as the verification target, and the validity confirmation unit 326 used the certification authority 300 as the confirmation target. Figures 14(b) and 14(c) show the counterparties for verification and validity confirmation in this embodiment. In this embodiment, the verification unit 425 of the ECU 42 uses the distributed ledger set in the storage unit 411 of the integrated ECU as the verification target, and the validity confirmation unit 426 uses the certification authority 300 as the confirmation target. Furthermore, in Figure 14(c), the matching unit 415 of the integrated ECU uses the distributed ledger 200 as the matching target. The case of Figure 14(c) will be explained below.

[0121] The configuration of the ECU42 and the integrated ECU in this embodiment will be explained using Figure 15.

[0122] ECU41 and ECU42 can be any combination of ECUs shown in Figure 2, but in this embodiment, ECU41 is an integrated ECU and ECU42 is an individual ECU. The ECU 41 (integrated ECU) (corresponding to the "second electronic control unit") has a storage unit 411, a control unit 412, a transmission unit 413, and a reception unit 414. The control unit 412 also includes a verification unit 415. The ECU42 (corresponding to the "first electronic control unit") has a storage unit 421, a control unit 422, a transmission unit 423, and a reception unit 424. The control unit 422 also includes a verification unit 425 and a validity verification unit 426. The following description will only cover the parts that differ from Embodiment 3, and the parts that are the same as Embodiment 3 will be referenced from the description of Embodiment 3.

[0123] In this embodiment, the function of the distributed ledger as seen from ECU42 is handled by the storage unit 411 of ECU41 (integrated ECU). That is, the public key P1 generated from the private key S1 is stored in the distributed ledger (corresponding to the "first distributed ledger") set up in the storage unit 411.

[0124] Then, the matching unit 425 of ECU42 (corresponding to the "first matching unit") compares the public key P2 stored in its own memory unit 421 with the public key P1 stored in the distributed ledger set in the memory unit 411 of ECU41 (integrated ECU), rather than the distributed ledger 200, at a predetermined timing (corresponding to the "first predetermined timing"). In this example, the distributed ledger configured in the memory unit 411 stores the public key P1 itself, but it may also store the key information P1 of the public key P1. It is not necessary to set up a distributed ledger in the storage unit 411; it is sufficient if the storage unit 411 stores the public key P1 or key information P1.

[0125] Furthermore, the matching unit 415 of the ECU 41 (integrated ECU) (corresponding to the "second matching unit") compares the public key P1 stored in the storage unit 411 with the key information P2 stored in the distributed ledger 200 (corresponding to the "second distributed ledger") at a predetermined timing (corresponding to the "second predetermined timing"). The configuration and operation of the ECU 41 (integrated ECU) are the same as in Embodiments 2 and 3.

[0126] When comparing the frequency of predetermined timings in the matching of ECU41 (integrated ECU) and the frequency of predetermined timings in the matching of ECU42, it is desirable that the former be lower than the latter. Since it is relatively rare for the keys of multiple ECUs included in the electronic control system 100 to be tampered with simultaneously, the presence or absence of tampering can usually be confirmed by matching with the public key P1 of the integrated ECU. In addition, in case of simultaneous tampering, the presence or absence of tampering can also be confirmed by accessing the distributed ledger 200 outside the vehicle. This allows for a reduction in the frequency of external communication without decreasing the frequency of matching the public key P1, enabling more efficient use of communication line resources.

[0127] Although this embodiment corresponds to the configuration shown in Figure 10 of Embodiment 3, it may also correspond to the configuration shown in Figure 11 of Embodiment 3.

[0128] 6. Other Embodiments The examples of Embodiments 1 to 4 may be applied to the entire in-vehicle electronic control system 100, or to only a part of the electronic control system 100. For example, they may be applied only between ECUs that control cameras, radar, and LiDAR, or between these and an integrated ECU.

[0129] 7. Summary The features of the electronic control device, distributed ledger, certification authority, etc., in each embodiment of the present invention have been described above.

[0130] The terms used in each embodiment are illustrative and may be replaced with synonymous terms or terms that include synonymous functions.

[0131] The block diagram used in describing the embodiment classifies and organizes the device configuration by function. Each block representing a function can be realized by any combination of hardware or software. Furthermore, since it represents a function, such a block diagram can also be understood as a disclosure of a method invention and a program invention that realizes said method.

[0132] The functional blocks that can be understood as processes, flows, and methods described in each embodiment may be reordered, unless there are constraints such as a relationship where one step utilizes the results of other preceding steps.

[0133] The terms "first," "second," through "nth" (where N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same kind, and do not imply any order or hierarchy.

[0134] In each embodiment, the description was based on the premise that the electronic control device disclosed in each embodiment is mounted on a vehicle, but it may also be based on the premise that it is carried by a pedestrian.

[0135] Furthermore, the following are examples of the forms of the electronic control device, distributed ledger, and certification authority of the present invention. Examples of component forms include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include electronic control units (ECUs) and system boards. Examples of finished products include mobile phones, smartphones, tablets, personal computers (PCs), workstations, servers, and cloud servers. Other devices with communication capabilities include, for example, video cameras, still cameras, and car navigation systems.

[0136] Furthermore, necessary functions such as antennas and communication interfaces may be added to the electronic control unit, distributed ledger, and certification authority.

[0137] The distributed ledger and certification authority of the present invention are intended to be used for the purpose of providing various services. In connection with the provision of such services, the distributed ledger and certification authority of the present invention will be used, the methods of the present invention will be used, and / or the programs of the present invention will be executed.

[0138] In addition, the present invention can be realized not only with dedicated hardware having the configuration and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory capable of executing this program.

[0139] Programs stored on non-transitional physical recording media of dedicated or general-purpose hardware (e.g., external storage devices (hard disks, USB memory, CD / BD, etc.) or internal storage devices (RAM, ROM, etc.)) can also be provided to the dedicated or general-purpose hardware via the recording media, or via a communication line from a server without using the recording media. This allows for the provision of the latest functions at all times through program upgrades. [Industrial applicability]

[0140] Although the present invention has been described primarily as an electronic control device for vehicles mounted on automobiles, it can be applied to all types of moving objects, including motorcycles, electric bicycles, railways, pedestrians, ships, and aircraft. [Explanation of Symbols]

[0141] 11, 12, 21, 22, 31, 32, 41, 42 ECU 111, 121, 211, 221, 311, 321, 411, 421 Storage section 112, 122, 212, 222, 312, 322, 412, 422 Control Unit 113, 123, 213, 223, 313, 323, 413, 423 Transmitting section 114, 124, 214, 224, 314, 324, 414, 424 Receiving Unit 115, 125, 215, 225, 315, 325, 415, 425 Verification section 316, 326, 426 Validity Verification Unit 200 Distributed Ledger 300 Certificate Authorities

Claims

1. An electronic control device mounted on a vehicle, Memory units for storing keys (111, 121, 211, 221, 311, 321, 411, 421), The system includes a matching unit (115, 125, 215, 225, 315, 325, 415, 425) that, at predetermined intervals, compares the key stored in the storage unit with key information, which is information about the key stored in a distributed ledger (200) located outside the vehicle. Electronic control devices (11, 12, 21, 22, 31, 32, 41, 42).

2. The aforementioned electronic control device further includes a receiving unit (314, 324) that receives the electronic certificate of the key, The system includes validity verification units (316, 326) that verify the validity of the electronic certificate with respect to a certification authority (300), The electronic control device according to claim 1.

3. The frequency of effectiveness verification by the effectiveness verification unit is lower than the frequency at predetermined time intervals. The electronic control device according to claim 2.

4. The storage unit stores the verification result from the verification unit. When using the aforementioned key, a determination is made based on the matching result whether or not to use the aforementioned key. The electronic control device according to claim 1.

5. In addition to the second distributed ledger, which is the aforementioned distributed ledger, the first distributed ledger is provided in the vehicle. The electronic control device according to claim 1.

6. Each of the aforementioned predetermined time intervals, If the vehicle is able to communicate with the outside while it is in motion, then at first predetermined intervals, The electronic control device according to any one of claims 1 to 5.

7. The first predetermined time is determined according to the speed of the vehicle. The electronic control device according to claim 6.

8. At each predetermined time interval, If the vehicle is parked and capable of communicating with the outside, then at the fourth predetermined interval, The electronic control device according to any one of claims 1 to 5.

9. Each of the aforementioned predetermined time intervals, If the vehicle is able to communicate with the outside while it is in motion, then it will do so at first predetermined intervals. If the vehicle is parked and capable of communicating with the outside, the communication occurs at the fourth predetermined interval, The fourth predetermined time is longer than the first predetermined time. The electronic control device according to claim 8.

10. A key verification method performed in an electronic control unit installed in a vehicle, The key is stored in the memory unit (S111, S121, S321), At predetermined intervals, the key stored in the storage unit is compared with key information, which is information about the key stored in a distributed ledger located outside the vehicle (S116, S125, S327, S328). Key verification method.

11. A key verification program that can be executed in an electronic control unit installed in a vehicle, The key matching program is The key is stored in the memory unit (S111, S121, S321), The electronic control unit is instructed to perform a process at predetermined intervals that includes comparing the key stored in the storage unit with key information, which is information about the key stored in a distributed ledger located outside the vehicle (S116, S125, S327, S328). Key matching program.

12. An electronic control system consisting of multiple electronic control devices mounted on a vehicle, Each of the aforementioned electronic control devices is: A memory unit that stores keys, The system includes a matching unit that, at predetermined intervals, compares the key stored in the storage unit with key information, which is information relating to the key, stored in a distributed ledger. Electronic control system (100).

13. When the multiple electronic control devices are designated as a first electronic control device and a second electronic control device, The predetermined time intervals in the first electronic control unit and the predetermined time intervals in the second electronic control unit are different, The electronic control system according to claim 12.

14. A key management system comprising an electronic control device mounted on a vehicle and a distributed ledger (200) located outside the vehicle, The aforementioned electronic control device is A memory unit that stores keys, The system includes a matching unit that, at predetermined intervals, compares the key stored in the storage unit with key information, which is information relating to the key, stored in the distributed ledger. Key management system.

15. A key management system comprising an electronic control device mounted on a vehicle, a distributed ledger (200) located outside the vehicle, and a certification authority (300), The aforementioned electronic control device is A memory unit that stores keys, A matching unit compares the key stored in the storage unit with key information, which is information relating to the key, stored in the distributed ledger, at predetermined intervals. The system includes a validity verification unit that verifies the validity of the electronic certificate relating to the key with respect to the certification authority. Key management system.

16. A key management system comprising an electronic control system consisting of a first electronic control unit and a second electronic control unit mounted on a vehicle, The first electronic control unit is A first memory unit that stores the key, The system includes a first matching unit that, at first predetermined intervals, compares the key stored in the first storage unit with first key information, which is information relating to the key stored in the second electronic control unit. The second electronic control device described above is: A second storage unit for storing the aforementioned key, The system includes a second matching unit that, at second predetermined intervals, compares the key stored in the second storage unit with second key information, which is information about the key stored in a distributed ledger located outside the vehicle. Key management system.

17. The frequency of the second predetermined time interval is lower than the frequency of the first predetermined time interval. The key management system according to claim 16.

Citation Information

Patent Citations

  • Vehicle-mounted network message authentication method and system based on block chain and ECC

    CN113300836A

  • Communication system, hardware security module, terminal device, communication method and program

    JP2017157984A

  • Key management system

    JP2019047281A

  • Control device, program for control device, and control method

    JP2019177808A

  • Control method, control program and information processing device

    JP2021136645A