Electronic control device, authentication method, and authentication program

JP7916815B2Active Publication Date: 2026-09-08DENSO CORP
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2023065145
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-04-12
Publication Date
2026-09-08
Estimated Expiration
2043-04-12

AI Technical Summary

Benefits of technology

【0010】 上述のような構成により、本開示の電子制御装置等によれば、グリッチ攻撃を受けた場合であっても、認証処理をスキップせずに実行することが可能となる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007916815000001
    Figure 0007916815000001
  • Figure 0007916815000002
    Figure 0007916815000002
  • Figure 0007916815000003
    Figure 0007916815000003
Patent Text Reader

Abstract

To provide an electronic control device, an electronic control system, an authentication method, and a program that perform authentication processing normally even when being subjected to a glitch attack.SOLUTION: An electronic control device 100 comprises a request acquisition unit, a timing determination unit, and an authentication unit. The request acquisition unit acquires an authentication request from another device. The timing determination unit randomly determines a timing of execution of authentication processing for the authentication request when an authentication request unit acquires the authentication request. The authentication unit executes the authentication processing at the timing determined by the timing determination unit.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention mainly relates to an electronic control device that performs authentication processing, an authentication method executed by the electronic control device, and an authentication program.

Background Art

[0002] Along with the development of the so-called IoT (Internet of Things), in which various devices are connected to networks, the necessity for countermeasures against cyber attacks has increased. One type of cyber attack is a glitch attack, which is a type of fault injection attack. A glitch attack is known as an attack that injects an abnormality called a glitch into a device to cause the device to malfunction. For example, an attacker injects voltage or clock as a glitch into an electronic control device. When subjected to such a glitch attack, processing that was scheduled to be executed at that clock may be skipped.

[0003] As a countermeasure against glitch attacks, for example, it is conceivable to mount a voltage sensor or a clock sensor on the device. When a voltage sensor or a clock sensor detects a glitch injected by an attack, it can detect that a glitch attack has occurred. For example, Patent Document 1 discloses that a supply voltage glitch detector provided in a monolithic integrated circuit device detects a glitch in a supply voltage.

[0004] Further, as another countermeasure against glitch attacks, there is a method of duplicating authentication processing. In this method, since an attacker needs to perform a glitch attack at each timing of two authentication processes, the possibility that the attack succeeds can be significantly reduced.

Prior Art Literature

Patent Literature

[0005]

Patent Literature 1

Summary of the Invention

[0006] Here, the inventors, after detailed investigation, identified the following problems. Methods that detect glitches using voltage sensors require the installation of such sensors in the device, necessitating hardware modifications and thus increasing implementation costs. Furthermore, while this method can detect that a glitch attack has occurred, it cannot prevent the glitch attack itself. On the other hand, methods that prevent glitch attacks by duplicating authentication processes increase the communication time required for authentication due to the double authentication process. In addition, changes to communication specifications and program rewriting are required not only on the device performing the authentication but also on the device receiving authentication. Therefore, it is desirable to prevent glitch attacks without hardware modifications or increased communication time.

[0007] Therefore, the present invention aims to realize an electronic control device, etc., that can prevent glitch attacks using a simple method without modifying the hardware or increasing communication time. [Means for solving the problem]

[0008] An electronic control device (100) according to one aspect of the present disclosure includes a request acquisition unit (101) that acquires an authentication request from another device (10), a timing determination unit (102) that randomly determines the timing for performing an authentication process for the authentication request when an authentication request is acquired, and an authentication unit (103) that performs the authentication process at the timing determined by the timing determination unit.

[0009] The numbers in parentheses attached to the claims and the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described later, and are not intended to limit the present invention. [Effects of the Invention]

[0010] With the configuration described above, the electronic control device, etc. of this disclosure makes it possible to execute the authentication process without skipping it, even if a glitch attack occurs. [Brief explanation of the drawing]

[0011] [Figure 1] Diagram illustrating the arrangement of the electronic control unit and related equipment in each embodiment. [Figure 2] This figure illustrates an example of the configuration of the electronic control unit of the first embodiment. [Figure 3] This diagram illustrates the operation of the electronic control unit of the first embodiment. [Figure 4] This diagram illustrates the operation of the electronic control unit and connected equipment according to the first embodiment. [Figure 5] A diagram illustrating the relationship between authentication processes in electronic control devices and glitch attacks. [Figure 6] This diagram illustrates the operation of the electronic control unit of the second embodiment. [Figure 7] This diagram illustrates the operation of the electronic control unit of the second embodiment. [Figure 8] This figure illustrates an example of the configuration of an electronic control system in a modified form of each embodiment. [Figure 9] This figure illustrates an example of the configuration of an electronic control unit in an electronic control system of a modified embodiment. [Modes for carrying out the invention]

[0012] Embodiments of the present invention will be described below with reference to the drawings.

[0013] Furthermore, "the present invention" means the invention described in the claims or means for solving the problem, and is not limited to the following embodiments. Also, at least the words in quotation marks mean the words described in the claims or means for solving the problem, and are likewise not limited to the following embodiments.

[0014] The configurations and methods described in the dependent claims of the claims are optional configurations and methods for the invention described in the independent claims of the claims. The configurations and methods of the embodiments corresponding to the configurations and methods described in the dependent claims, as well as the configurations and methods described only in the embodiments but not in the claims, are optional configurations and methods in the present invention. If the recitation in the claims is broader than the recitation in the embodiments, the configurations and methods described in the embodiments are also optional configurations and methods in the present invention in the sense that they are exemplifications of the configurations and methods of the present invention. In any case, the configurations and methods described in the independent claims of the claims are the essential configurations and methods of the present invention.

[0015] The effects described in the embodiments are effects obtained when having the configuration of the embodiment as an exemplification of the present invention, and are not necessarily the effects possessed by the present invention.

[0016] When there are a plurality of embodiments, the configurations disclosed in each embodiment are not limited to each individual embodiment, and can be combined across embodiments. For example, a configuration disclosed in one embodiment may be combined with another embodiment. In addition, configurations disclosed in each of a plurality of embodiments may be collected and combined together.

[0017] The problem described in the problem to be solved by the invention is not a known problem, but was independently found by the inventor, and is a fact that affirms the inventive step of the invention together with the configuration and method of the present invention.

[0018] 1. Arrangement of Electronic Control Unit Common to Each Embodiment and Relationship with Related Devices Figure 1 is a diagram explaining the arrangement of the electronic control unit 100 of each embodiment and the relationship with related devices. Two scenarios are assumed for the electronic control unit 100: for example, as shown in Figure 1(a), the electronic control unit 100, together with the connected device 10, is "mounted" on a vehicle which is a "moving body", and as shown in Figure 1(b), the electronic control unit 100 is mounted on the vehicle, and the connected device 10 is a device provided outside the vehicle.

[0019] Here, "moving object" refers to any object that can move, regardless of its speed. It also includes cases where the moving object is stationary. For example, this includes, but is not limited to, automobiles, motorcycles, bicycles, and items mounted on them. "Being mounted" includes not only cases where something is directly fixed to a moving object, but also cases where it is not fixed to a moving object but moves along with it. For example, this includes cases where it is carried by a person riding in a vehicle, or where it is mounted on cargo placed on a moving object.

[0020] The electronic control unit 100 can consist of a general-purpose CPU (Central Processing Unit), volatile memory such as RAM, non-volatile memory such as ROM, flash memory, or hard disk, various interfaces, and an internal bus connecting them. By executing software on this hardware, it can be configured to perform the functions of each functional block shown in Figure 2, which will be described later. Of course, the electronic control unit 100 may also be implemented using dedicated hardware such as an LSI.

[0021] In the following embodiments, the electronic control unit 100 is assumed to be in the form of a semi-finished product, but is not limited to this. For example, the form of a component may be a semiconductor circuit or semiconductor module, the form of a semi-finished product may be an electronic control unit, an electronic control unit, a microcontroller, or a system board, and the form of a finished product may be a server, a workstation, a personal computer (PC), a tablet, a mobile router, a smartphone, a mobile phone, or a navigation system. The electronic control unit 100 may consist of a single ECU or multiple ECUs.

[0022] The connecting device 10 only needs to be able to communicate with the electronic control unit 100, and its form is not limited. That is, like the electronic control unit 100, it can be a component, a semi-finished product, or a finished product. For example, in the example shown in Figure 1(a), the connecting device 10 is another electronic control unit mounted on the vehicle, and in the example shown in Figure 1(b), the connecting device 10 could be a server, a mobile terminal, or a digital key for the vehicle.

[0023] 2. First Embodiment (1) Configuration of the electronic control unit 100 Referring to Figure 2, an example configuration of the electronic control unit 100 will be described. The electronic control unit 100 includes a request acquisition unit 101, a timing determination unit 102, an authentication unit 103, a communication unit 104, and an application execution unit 105.

[0024] The request acquisition unit 101 acquires authentication requests from connected devices (corresponding to "other devices") 10 connected to the electronic control unit 100.

[0025] In this embodiment, the case in which the connected device 10 requests authentication from the electronic control unit 100 in order to execute an application installed on the electronic control unit 100 is described as an example, but the embodiment is not limited to this example. For example, if the electronic control unit 100 is a device that provides an interface for accessing debugging resources, authentication may be required to prevent unauthorized access to the resources. In that case, the connected device 10 may request authentication from the electronic control unit 100 in order to use the debugging function that the electronic control unit 100 has.

[0026] The timing determination unit 102 randomly determines the "timing" for performing authentication processing in response to an authentication request when the request acquisition unit 101 acquires an authentication request from the connected device 10. Hereinafter, the timing determined by the timing determination unit 102 will be referred to as the authentication timing. The timing determination unit 102 randomly determines the authentication timing using, for example, a random number generation function (not shown).

[0027] The timing determination unit 102 may determine the authentication timing by randomly determining the time at which the authentication unit 103 executes the authentication process, or it may determine the authentication timing by randomly determining the "period" from when the electronic control device 100 performs a predetermined process until the authentication unit 103 executes the authentication process. Details of the authentication timing will be described later.

[0028] Here, determining the "timing" includes not only determining a specific time to perform the authentication process, but also determining the length of time before the authentication process is performed. "Period" can refer to any time interval, including not only time but also the number of clock pulses, etc.

[0029] The authentication unit 103 performs authentication processing at the authentication timing determined by the timing determination unit 102. In this embodiment, the configuration in which the authentication unit 103 performs authentication processing using a challenge-response method is described as an example. However, the authentication unit 103 can perform authentication processing using any method. For example, the authentication unit 103 may perform authentication processing using methods such as a digital signature method, a MAC (Message Authentication Code) method, or a SCRAM (Salted Challenge Response Authentication Mechanism) method.

[0030] The communication unit 104 communicates with the connected device 10 based on instructions from the authentication unit 103. For example, if the authentication unit 103 performs authentication processing using a challenge-response method, the communication unit 104 transmits the challenge information generated by the authentication unit 103 to the connected device 10 and receives the response information transmitted from the connected device 10, based on instructions from the authentication unit 103.

[0031] The application execution unit 105 executes the application if the authentication process performed by the authentication unit 103 is successful.

[0032] Next, the authentication timing determined by the timing determination unit 102 will be described. As mentioned above, the authentication unit 103 of this embodiment performs authentication processing using a challenge-response method. Therefore, the timing determination unit 102 of this embodiment determines the period from when the challenge information is sent to the connected device 10 until the authentication processing is performed as the authentication timing. As an example, the timing determination unit 102 determines the authentication timing by setting the time corresponding to the random number generated by the random number generation function as the time from when the challenge information is sent until the authentication processing is performed.

[0033] In another example, the timing determination unit 102 may determine the authentication timing as the time from when the request acquisition unit 101 acquires the authentication request until the authentication process is completed. Similar to the example described above, the timing determination unit 102 determines the authentication timing by setting the time corresponding to the random number generated by the random number generation function as the time from when the authentication request is acquired until the authentication process is completed.

[0034] In yet another example, the timing determination unit 102 may determine the authentication timing as the difference between the reference timing, which is the timing at which the authentication unit 103 performs the authentication process, and the timing at which the authentication unit 103 actually performs the authentication process. For example, suppose the reference timing at which the authentication unit 103 performs the authentication process is set to 100 msec after the request acquisition unit 101 acquires the authentication request. In this case, the timing determination unit 102 randomly determines the period of difference between the reference timing and the timing at which the authentication unit 103 performs the authentication process. For example, if the period randomly determined by the timing determination unit 102 is 5 msec, the authentication timing is determined to be 5 msec after the reference timing.

[0035] In yet another example, the timing determination unit 102 may determine the authentication timing by the number of clock pulses instead of time. The electronic control unit 100 operates in accordance with clock pulses. In this case, the timing determination unit 102 determines the authentication timing as the number of clock pulses from the time the challenge information is sent to the connected device 10 until the authentication process is performed, the number of clock pulses from the time the authentication request is received until the authentication unit 103 performs the authentication process, or the number of clock pulses which is the difference between the reference timing and the timing at which the authentication unit 103 performs the authentication process.

[0036] Furthermore, there may be a time limit imposed between receiving an authentication request and completing the authentication process. In such cases, if the authentication process is not completed within the time limit, it will be determined that the authentication process has failed. Therefore, if a time limit is imposed, the timing determination unit 103 may randomly determine the authentication timing so that it falls within the predetermined time limit.

[0037] (2) Operation of the electronic control unit 100 Next, the operation of the electronic control unit 100 and the connected devices 10 connected to the electronic control unit 100 will be explained with reference to Figures 3 and 4. Figures 3 and 4 not only show the authentication method performed by the electronic control unit 100, but also the processing steps of the authentication program that can be executed by the electronic control unit 100. Furthermore, these processes are not limited to the order shown in Figures 3 and 4. That is, the order may be changed unless there are constraints such as a relationship where one step utilizes the result of the preceding step. Also, processes common to Figures 3 and 4 will be described using the same reference numerals. The same applies to Figures 6 and 7, which will be described later.

[0038] The request acquisition unit 101 acquires an authentication request from the connected device 10 (S101). The timing determination unit 102 randomly determines the timing for performing the authentication process for the authentication request obtained in S101 (S102). For example, the timing determination unit 102 determines the period from when the communication unit 104 transmits the challenge information until when the authentication unit 103 performs the authentication process as the authentication timing. The authentication unit 103 generates challenge information in order to perform authentication processing using the challenge-response method (S103). Based on instructions from the authentication unit 103, the communication unit 104 transmits the challenge information generated in S102 to the connected device 10 (S104). At this time, the authentication unit 103 begins measuring the period since the challenge information was transmitted in S104.

[0039] When the connected device 10 receives challenge information from the electronic control unit 100, it generates response information using the received challenge information (S11). Then, the connected device 10 transmits the generated response information to the electronic control unit 100.

[0040] The communication unit 104 receives response information from the connected device 10 (S105). If the authentication timing is reached (S106:Y), that is, if the period determined in S102 has elapsed since the communication unit 104 sent the challenge information to the connected device 10 in S103, the authentication unit 103 executes the authentication process (S107).

[0041] In S107, the authentication unit 103 performs the authentication process, and if the authentication is successful (S108), the application execution unit 105 executes the application (S109).

[0042] Figures 3 and 4 illustrate the operation of the electronic control unit 100 when the authentication unit 103 performs authentication processing using the challenge-response method. Therefore, if the authentication unit 103 performs authentication processing using a different method, the processes shown in Figures 3 and 4 will be appropriately modified according to the method. For example, if a method other than the challenge-response method is used, processes S103 to S105 in Figures 3 and 4 will not be executed.

[0043] (3) Relationship between the electronic control unit 100 and glitch attacks Next, with reference to Figure 5, the relationship between the electronic control unit 100 and glitch attacks will be explained. Figure 5(a) is a diagram illustrating a conventional authentication process, and Figure 5(b) is a diagram illustrating the authentication process according to this embodiment.

[0044] Figure 5(a) schematically shows a series of processes in which the communication unit 104 sends challenge information to the connected device 10, performs authentication processing after a predetermined period of time has elapsed, and executes the application if the authentication processing is successful. Figure 5(a) further shows the voltage change caused by the glitch attack and the clock pulse generated by the voltage change.

[0045] In conventional authentication processes, the authentication process is executed after a predetermined period has elapsed since the electronic control unit 100 sent the challenge information. Therefore, there is a possibility of glitch attacks targeting the timing of the authentication process execution. Figure 5(a) shows a case where a glitch attack occurs at the timing of the authentication process execution. For example, if a voltage is applied due to a power glitch attack, an abnormal clock pulse will be generated. Alternatively, an abnormal clock pulse may be directly generated by a clock glitch attack. In this case, the process that was scheduled to be executed at the corresponding clock may be skipped. In Figure 5(a), the authentication process was scheduled to be executed at the corresponding clock, but because an abnormal clock pulse was generated, the authentication process is skipped. As a result, the application will be executed regardless of whether the authentication process was successful or not.

[0046] In contrast, Figure 5(b) shows the authentication process according to this embodiment. As described above, in this embodiment, the period from when the communication unit 104 transmits challenge information until the authentication unit 103 executes the authentication process is randomly determined by the timing determination unit 102. Therefore, an attacker cannot predict the timing of the authentication process, and the possibility of being subjected to a glitch attack at the time of the authentication process is low. As a result, the timing of the glitch attack, and consequently the timing of the generation of abnormal clock pulses, is out of sync with the timing of the authentication process, allowing the authentication process to be executed normally.

[0047] Furthermore, the period from when the communication unit 104 transmits the challenge information until the authentication process is executed is longer than the predetermined period shown in Figure 5(a), as is the randomly determined period in this embodiment shown in Figure 5(b). Therefore, a waiting time occurs between when the communication unit 104 receives the response information and when the authentication unit 103 executes the authentication process. In this case, the application execution unit 105 may perform the processing necessary for application execution in advance during the waiting time before the authentication unit 103 executes the authentication process. However, since this is before the authentication process by the authentication unit 103 is executed, it is desirable that the processing performed by the application execution unit 105 during the waiting time does not affect the security of the electronic control device 100.

[0048] (4) Summary As described above, according to this embodiment, by randomly determining the timing of the authentication process, it is possible to avoid being subjected to glitch attacks timed to the authentication process, and consequently, to prevent the authentication process from being skipped due to glitch attacks. Furthermore, according to this embodiment, it is possible to prevent the authentication process from being skipped not only in the case of a clock glitch attack, but also in the case of a power glitch attack that applies an abnormal voltage.

[0049] 3. Second Embodiment In the first embodiment, an electronic control device 100 was described in which the authentication process in the authentication unit 103 is performed at a timing determined by the timing determination unit 102. In this embodiment, a configuration is described in which the electronic control device 100 performs the authentication process at a timing determined in response to the acquired authentication request, or performs the authentication process immediately. Since the configuration of the electronic control device 100 in this embodiment is basically the same as that of the electronic control device 100 in the first embodiment, the differences from the first embodiment will be explained with reference to Figure 2.

[0050] The request acquisition unit 101 of this embodiment acquires multiple different authentication requests. In the following embodiment, an example is described in which the request acquisition unit 101 acquires two authentication requests, namely a first authentication request and a second authentication request. The first authentication request is, for example, an authentication request for a predetermined "message," and the second authentication request is an authentication request for a message different from the predetermined message.

[0051] Here, "message" refers to a collection of data sent and received between an electronic control unit and another device, and includes what are called data frames and data blocks.

[0052] The electronic control unit 100 performs the same processing as in the first embodiment for the first authentication request. That is, the timing determination unit 102 randomly determines the timing for performing the authentication processing, and the authentication unit 103 performs the authentication processing at the authentication timing determined by the timing determination unit 102.

[0053] In contrast, for the second authentication request, the timing determination unit 102 does not determine the authentication timing. The authentication unit 103 then performs the authentication process for the authentication request "immediately". For example, the authentication unit 103 may perform the authentication process without delay after receiving the authentication request, or, if the authentication unit 103 performs the authentication process using a challenge-response method, it may perform the authentication process without delay after receiving response information from the connected device 10.

[0054] Here, "immediately" includes cases where the necessary preparations for performing the authentication process have been completed.

[0055] In other words, in this embodiment, the electronic control unit 100 may execute the authentication process at a specific authentication timing after receiving the authentication request, or it may execute the authentication process immediately after receiving the authentication request.

[0056] A predetermined message is, for example, a message of high importance. If a message related to vehicle driving control is forged by an attacker and authentication processing is not performed due to a glitch attack, there is a risk that the vehicle's driving control may be hijacked by a malicious attacker. Therefore, it is desirable that authentication processing be reliably performed for messages of high importance, such as messages related to vehicle driving control. Accordingly, if the authentication request is for a message whose importance is "greater than" a predetermined threshold, the authentication processing is performed at an authentication timing randomly determined by the timing determination unit 102, as described in the first embodiment. The judgment unit (not shown) of the electronic control device 100 may determine whether the importance of the message for which authentication is requested is higher than a predetermined threshold, depending on the content of the message, but the identification information and CAN-ID of messages whose importance is higher than the predetermined threshold may be stored in advance. In this case, if the identification information and CAN-ID of the message for which authentication is requested corresponds to the identification information and CAN-ID stored in advance, the judgment unit can determine that the authentication request is for a message whose importance is higher than the predetermined threshold. The message identification information and CAN-ID are stored by the dealer or vehicle manufacturer.

[0057] Here, "than" includes both cases where the comparison target has the same value and cases where it does not.

[0058] Another example of a predetermined message is one for which there are no constraints on the speed or time of the authentication process. For example, if the authentication process is performed at the authentication timing determined by the timing determination unit 102, the time required to complete the authentication process will be longer compared to performing the authentication process immediately. Therefore, for messages that require immediate authentication, the authentication process is performed immediately, while for messages for which there are no constraints on the speed or time of the authentication process, the authentication process is performed at an authentication timing randomly determined by the timing determination unit 102.

[0059] In yet another example, the predetermined message is, for example, a message sent from a connected device 10 located outside the vehicle. When the connected device 10 is located outside the vehicle, the authentication request sent is more likely to be sent by a malicious attacker compared to when the connected device 10 is located inside the vehicle. Therefore, as shown in Figure 1(a), it is desirable that authentication processing be reliably performed for authentication requests sent from a connected device 10 located outside the vehicle. Accordingly, in the case of an authentication request for a message sent from outside the vehicle, the authentication processing is performed at an authentication timing randomly determined by the timing determination unit 102, as described in the first embodiment. In contrast, as shown in Figure 1(b), for authentication requests sent from a connected device 10 located inside the vehicle, the authentication processing is performed immediately after the authentication request is received.

[0060] The operation of the electronic control device 100 of this embodiment will be described with reference to Figures 6 and 7. Processes common to Figures 3 and 4 are denoted by the same reference numerals as in Figures 3 and 4, and their descriptions are omitted.

[0061] The request acquisition unit 101 determines whether the authentication request acquired from the connected device 10 is an authentication request for a predetermined message (S201). Here, if the authentication request obtained in S101 is an authentication request for a predetermined message (S201:Y), the processing from S102 onwards is performed as in the first embodiment.

[0062] On the other hand, if the message is not an authentication request for a predetermined message (S201:N), the process shown in Figure 7 is performed. Specifically, the authentication unit 103 generates challenge information to perform authentication processing using the challenge-response method (S211), and the communication unit 104 transmits the challenge information generated in S211 to the connected device 10 based on instructions from the authentication unit 103 (S212). Then, the communication unit 104 receives response information from the connected device 10 (S213). Note that the processes in S211, S212, and S213 are the same as the processes in S103, S104, and S105 shown in Figure 6.

[0063] As described above, according to this embodiment, the electronic control device 100 can perform authentication processing at random timings or immediately in response to a message.

[0064] 4. Variations Next, modifications of the first and second embodiments will be described with reference to Figures 8 and 9. Figure 8 is a schematic diagram of an electronic control system S mounted on a vehicle, which is a mobile object. The electronic control system S consists of a plurality of electronic control devices, including an electronic control device 100. The electronic control system S shown in Figure 8 employs a multi-layered defense system to protect the security of the vehicle.

[0065] Multilayered defense is a defense method that provides security functions in a hierarchical and multilayered manner as a countermeasure against attacks. In a system employing multilayered defense, even if the first countermeasure (i.e., the first layer) is breached in the event of an attack, the next countermeasure (i.e., the second layer) will defend against the attack, and even if the next countermeasure is breached, the next countermeasure (i.e., the third layer) will defend against the attack, thus increasing the defensive capability. In other words, a system employing multilayered defense has multiple layers divided according to the "security level". The electronic control system S shown in Figure 8 has three layers (first layer, second layer, and third layer).

[0066] Here, "security level" refers to an indicator of safety against attacks, or the ability to defend against attacks.

[0067] Among the electronic control devices that constitute the electronic control system S shown in Figure 8, the electronic control device 100 is the same electronic control device 100 described in the first and second embodiments. Therefore, when the request acquisition unit 101 (corresponding to the "first request acquisition unit") acquires an authentication request (corresponding to the "first authentication request"), the timing determination unit 102 randomly determines the authentication timing, and the authentication unit (corresponding to the "first authentication unit") 103 performs the authentication process (corresponding to the "first authentication process") at the authentication timing determined by the timing determination unit 102.

[0068] In contrast, an example configuration of the electronic control unit 200, which constitutes the electronic control system S, will be explained using Figure 9. The electronic control unit 200 includes a request acquisition unit 201, an authentication unit 203, a communication unit 204, and an application execution unit 205, and each component has the same function as the corresponding component of the electronic control unit 100. However, unlike the electronic control unit 100 shown in Figure 2, the electronic control unit 200 does not have a timing determination unit. Therefore, in the electronic control unit 200, when the request acquisition unit 201 (corresponding to the "second request acquisition unit") acquires an authentication request (corresponding to the "second authentication request"), the authentication unit 203 (corresponding to the "second authentication unit") immediately performs authentication processing (corresponding to the "second authentication processing") for the authentication request.

[0069] Therefore, the electronic control system S is a system comprising an electronic control device 100 (corresponding to the "first electronic control device") that performs authentication processing at random timings, and an electronic control device 200 (corresponding to the "second electronic control device") that performs authentication processing immediately upon receiving an authentication request.

[0070] In the example shown in Figure 8, the electronic control unit 100 belongs to the first layer, and the electronic control unit 200 belongs to the second or third layer. The first layer in a multi-layer defense is the layer with the lowest security level and is therefore highly susceptible to attacks. Furthermore, the electronic control unit in the first layer is often an electronic control unit that communicates with the outside of the vehicle, and is highly likely to receive authentication requests sent by an attacker. In contrast, the second and third layers in a multi-layer defense have a higher security level than the first layer and are less susceptible to attacks. Therefore, the electronic control unit 100 is placed in the first layer to reliably perform authentication processing and prevent external attacks. Conversely, the electronic control unit 200, which does not perform authentication processing at random times, is placed in the higher security layers such as the second and third layers.

[0071] In Figure 8, an example is shown in which the electronic control unit 100 is placed on the first layer and the electronic control units 200 are placed on the second and third layers, but the system is not limited to this example. For example, the electronic control unit 100 may be placed on the second layer.

[0072] Furthermore, Figure 8 illustrates an example in which the electronic control system S includes an electronic control unit 100 and an electronic control unit 200 with a different configuration from the electronic control unit 100. However, the electronic control system S may also consist only of the electronic control unit 100. In this case, the electronic control unit 100 belonging to the second or third layer is configured to perform authentication processing immediately without the timing determination unit 102 determining the authentication timing.

[0073] 5. Summary The features of the electronic control devices and the like in each embodiment of the present invention have been described above.

[0074] The terms used in each embodiment are illustrative and may be replaced with synonymous terms or terms that include synonymous functions.

[0075] The block diagram used in describing the embodiment classifies and organizes the device configuration by function. Each block representing a function can be realized by any combination of hardware or software. Furthermore, since it represents a function, such a block diagram can also be understood as a disclosure of a method invention and a program invention that realizes said method.

[0076] The functional blocks that can be understood as processes, flows, and methods described in each embodiment may be reordered, unless there are constraints such as a relationship where one step utilizes the results of other preceding steps.

[0077] The terms "first," "second," through "nth" (where N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same kind, and do not imply any order or hierarchy.

[0078] Furthermore, the following are examples of the form of the electronic control device of the present invention. Examples of component forms include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include electronic control units (ECUs) and system boards. Examples of finished products include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other devices with communication capabilities include, for example, video cameras, still cameras, and car navigation systems.

[0079] Furthermore, necessary functions such as antennas and communication interfaces may be added to the electronic control unit.

[0080] The present invention can be realized not only with dedicated hardware having the configuration and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory capable of executing this program.

[0081] Programs stored on non-transitional physical recording media of dedicated or general-purpose hardware (e.g., external storage devices (hard disks, USB memory, CD / BD, etc.) or internal storage devices (RAM, ROM, etc.)) can also be provided to the dedicated or general-purpose hardware via the recording media, or via a communication line from a server without using the recording media. This allows for the provision of the latest functions at all times through program upgrades. [Industrial applicability]

[0082] The electronic control device of the present invention is applicable to any product in general, including microcomputers. [Explanation of Symbols]

[0083] 100 Electronic control unit, 101 Request acquisition unit, 102 Timing determination unit, 103 Authentication unit, 10 Connecting devices

Claims

1. A request acquisition unit (101) that acquires authentication requests from other devices (10), When the aforementioned authentication request is received, a timing determination unit (102) randomly determines the timing for performing the authentication process for the aforementioned authentication request, The authentication unit (103) performs the authentication process at the timing determined by the timing determination unit, An electronic control device (100) comprising:

2. The timing determination unit determines the period from the acquisition of the authentication request to the completion of the authentication process as the timing. The electronic control device according to claim 1.

3. The timing determination unit determines the timing as the difference between the reference timing that serves as the basis for performing the authentication process and the timing at which the authentication process is performed. The electronic control device according to claim 1.

4. The authentication unit performs the authentication process using a challenge-response method. The timing determination unit determines the period from the time the challenge information is transmitted to the other device until the authentication process is performed as the timing. The electronic control device according to claim 1.

5. The request acquisition unit further acquires a second authentication request that is different from the first authentication request, which is the authentication request. The authentication unit immediately performs the authentication process for the second authentication request. The electronic control device according to claim 1.

6. The first authentication request is an authentication request for a predetermined message, The second authentication request is an authentication request for a message different from the predetermined message. The electronic control device according to claim 5.

7. The aforementioned predetermined message is a message whose importance is higher than a predetermined threshold. The electronic control device according to claim 6.

8. The electronic control unit is mounted on a mobile device. The predetermined message is a message transmitted from outside the mobile device. The electronic control device according to claim 6.

9. An electronic control system having a first electronic control unit (100) and a second electronic control unit (100, 200), The first electronic control unit is A first request acquisition unit (101) that acquires a first authentication request, When the first authentication request is received, a timing determination unit (102) randomly determines the timing for performing the authentication process for the first authentication request, The system includes a first authentication unit (103) that performs a first authentication process at the timing determined by the timing determination unit, The second electronic control device described above is: A second request acquisition unit (101, 201) acquires a second authentication request, The system includes a second authentication unit (103, 203) that, upon receiving the second authentication request, immediately performs a second authentication process for the second authentication request. Electronic control system.

10. The electronic control system has multiple layers, which are divided according to the security level of the electronic control system. The first electronic control unit belongs to a layer with a lower security level than the layer to which the second electronic control unit belongs. The electronic control system according to claim 9.

11. Authentication method performed by an electronic control unit, A authentication request is obtained from another device (S101), When the aforementioned authentication request is obtained, the timing for performing the authentication process for the aforementioned authentication request is randomly determined (S102). The authentication process is performed at the determined timing (S107). Authentication method.

12. An authentication program that can be executed by an electronic control unit, A authentication request is obtained from another device (S101), When the aforementioned authentication request is obtained, the timing for performing the authentication process for the aforementioned authentication request is randomly determined (S102). The authentication process is performed at the determined timing (S107). An authentication program that causes the electronic control unit to perform a process that includes the above.

Citation Information

Patent Citations

  • Systems and methods for secure access to vehicle ECUs from external devices

    CN111431901B

  • Communication method

    JP2007153021A

  • Authentication system, authentication method, authentication device, and authenticated device

    JP2015122620A

  • Method and device for supply voltage glitch detection in monolithic integrated circuit device

    JP2015228639A

  • IC module, IC card, and manufacturing method for IC card

    JP2016045864A