Communication planning device, control method, and computer program

JPWO2024252705A5Pending Publication Date: 2026-03-05
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Filing Date
2024-01-05
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

Existing communication planning devices in in-vehicle systems face risks of information leakage and falsification due to unauthorized access, even when using secure communication paths, as assumed in previous technologies.

Method used

A communication planning device that detects state identification information, plans communication of fragmented information based on detection results, and includes a security strength evaluation unit to determine secure communication paths, restricting external communication if necessary, and uses a secret sharing method to divide and manage confidential information across multiple nodes.

Benefits of technology

Prevents information leakage and falsification by ensuring secure communication of fragmented information, maintaining real-time performance, and controlling communication according to the risk of information leakage, even in insecure states.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

This communication planning device is mounted on a system including a first device, a second device, and a communication device, and includes: a planning unit that plans communication of predetermined information between the first device and the second device; and a detection unit that detects state specification information required for the planning unit to plan communication. The planning unit plans communication of a plurality of pieces of split information between the first device and the second device on the basis of the result of detection by the detection unit, and the split information is information generated by splitting the predetermined information.
Need to check novelty before this filing date? Find Prior Art

Description

Communication planning device, control method, and computer program

[0001] This application claims priority to Japanese Patent Application No. 2023-095150, filed on June 9, 2023, and incorporates by reference all of the contents of that application.

[0002] Security is important in in-vehicle systems. To achieve this, information must be kept confidential. Encryption is a commonly known method of confidentiality, but there is another method called secret sharing. Secret sharing achieves confidentiality by distributing and managing the data to be protected.

[0003] Patent Document 1 below discloses a distributed information transfer system that uses a secret sharing scheme to distribute and hold secret information among multiple node groups in a network where full-mesh secure communication paths exist between all node pairs. In this distributed information transfer system, when there are multiple nodes operated by an attacker, the system redistributes and distributes the first shares, thereby preventing the attacker from collecting a sufficient number of shares and maintaining a secure state.

[0004] JP 2012-100140 A

[0005] A communication planning device according to one aspect of the present disclosure is a communication planning device mounted on a system including a first device, a second device, and a communication device, and includes a planning unit that plans communication of specified information between the first device and the second device, and a detection unit that detects state-specific information required for the planning unit to plan the communication, wherein the planning unit plans communication of multiple fragmented information between the first device and the second device based on the detection results by the detection unit, and the fragmented information is information generated by dividing the specified information.

[0006] FIG. 1 is a block diagram showing a configuration of an in-vehicle system according to an embodiment of the present disclosure. FIG. 2 is a block diagram showing a functional configuration of a second relay device shown in FIG. 1. FIG. 3 is a flowchart showing processing executed by the second relay device shown in FIG. 1. FIG. 4 is a block diagram showing a functional configuration of a second relay device according to a first modified example. FIG. 5 is a diagram showing, in table format, communication information taken into account for determining security strength. FIG. 6 is a diagram showing, in table format, information on available ports taken into account for determining security strength and the presence or absence of connections of unexpected communication devices. FIG. 7 is a flowchart showing processing executed by the second relay device according to the first modified example. FIG. 8 is a block diagram showing an example configuration of an in-vehicle system according to the first modified example. FIG. 9 is a block diagram showing a functional configuration of a second relay device according to a second modified example. FIG. 10 is a flowchart showing processing executed by the second relay device according to the second modified example.

[0007] [Problem to be Solved by the Present Disclosure] Patent Literature 1 assumes that the communication path is secure, but in reality, there are cases where the communication path is not secure. In such cases, the technology disclosed in Patent Literature 1 cannot avoid the risk of information leakage due to unauthorized access on the communication path.

[0008] Therefore, the present disclosure aims to provide a communication planning device, control method, and computer program that can prevent leakage and tampering when communicating divided information in information management in which secret information is divided into multiple pieces and stored in multiple nodes.

[0009] [Effects of the Present Disclosure] According to the present disclosure, in information management in which secret information is divided into multiple pieces and stored in multiple nodes, a communication planning device, a control method, and a computer program can be provided that can prevent leakage and tampering when communicating the divided information.

[0010] [Description of Embodiments of the Present Disclosure] The contents of the embodiments of the present disclosure will be listed and described below. At least some of the embodiments described below may be combined in any combination.

[0011] (1) A communication planning device according to a first aspect of the present disclosure is a communication planning device mounted on a system including a first device, a second device, and a communication device, and includes a planning unit that plans communication of predetermined information between the first device and the second device, and a detection unit that detects state-specific information required for the planning unit to plan the communication, wherein the planning unit plans communication of a plurality of pieces of fragmented information between the first device and the second device based on a detection result by the detection unit, and the fragmented information is information generated by dividing the predetermined information. This makes it possible to prevent leakage and tampering when communicating the divided fragmented information in information management in which the predetermined information (e.g., information that should be kept secret (hereinafter referred to as secret information)) is divided into multiple pieces and stored in multiple devices.

[0012] (2) In the above (1), the state specifying information includes information indicating at least one of the following: a communication state of external communication by the communication device with outside the system, a state of the input / output ports of the communication planning device and the first device, and whether or not an unexpected communication device is connected to a communication path within the system. This makes it possible to further prevent leakage and tampering of fragmented information when communicating it.

[0013] (3) In the above (1) or (2), when the planning unit determines based on the detection result that the plurality of pieces of fragmented information will not be communicated, the planning unit can plan to communicate the plurality of pieces of fragmented information after the first predetermined period has elapsed. This makes it possible to avoid a situation in which the plurality of pieces of fragmented information cannot be communicated for an extended period of time.

[0014] (4) In the above (3), the first predetermined period may be determined based on the real-time nature of a function that requires communication of a plurality of pieces of fragmented information, thereby preventing the real-time nature required for the function from being impaired.

[0015] (5) In any one of (1) to (4) above, the communication planning device may further include a security strength evaluation unit that evaluates security strength regarding information leakage from the system, and when the planning unit determines not to communicate the multiple pieces of fragmented information based on the detection result, the planning unit may plan to communicate the multiple pieces of fragmented information if the security strength evaluated by the security strength evaluation unit is equal to or higher than a predetermined level. This makes it possible to avoid unnecessary suppression of communication of the multiple pieces of fragmented information and to control communication of the multiple pieces of fragmented information according to the risk of information leakage.

[0016] (6) In the above (5), the security strength evaluation unit may evaluate the security strength based on the detection result by the detection unit. This allows the security strength to be evaluated appropriately.

[0017] (7) In any one of (1) to (6) above, the communication planning device may further include a communication control unit that causes the communication device to restrict external communication, which is communication by the communication device with outside the system, and if the external communication can be restricted, the planning unit may cause the communication control unit to restrict the external communication for a second predetermined period and plan to communicate the plurality of pieces of fragmented information for the second predetermined period. This makes it possible to avoid a state in which the plurality of pieces of fragmented information cannot be communicated for an extended period of time.

[0018] (8) In the above (7), the planning unit may determine that the external communication can be restricted if the external communication is not being performed for a function that requires real-time communication. This allows multiple pieces of fragmented information to be communicated while avoiding the loss of real-time communication required for the function.

[0019] (9) In the above (7), the planning unit may determine that the external communication can be restricted if the period from when a predetermined amount of data is stored in the buffer to when the use of the data is completed is longer than the period required to communicate the plurality of pieces of fragmented information. This allows the plurality of pieces of fragmented information to be communicated without affecting the function executing the external communication.

[0020] (10) In any one of (1) to (9) above, the communication planning device may further include an information processing unit that divides the predetermined information into a plurality of pieces of fragmented information, the predetermined information may be transmitted from the first device to the second device via the communication planning device, and the information processing unit may generate the fragmented information using a secret sharing scheme. This makes it possible to further prevent information leakage and tampering.

[0021] (11) In the above (10), the communication planning device may further include a communication destination determination unit that determines, from among the plurality of second devices, a number of communication destination devices equal to or less than the number of pieces of fragmented information, and the plurality of pieces of fragmented information may be communicated between the communication destination devices and the communication planning device based on a plan by the planning unit. This makes it possible to further prevent information leakage and tampering.

[0022] (12) In the above (11), the communication destination determination unit may determine, from among the plurality of communication destination devices, a plurality of partner devices that will receive the fragmented information in response to a request for the predetermined information input from the first device to the communication planning device, and the communication planning device may further include a restoration unit that generates the predetermined information from the fragmented information received from the plurality of partner devices. This allows the predetermined information to be generated from the fragmented information distributed and stored in the plurality of second devices and provided to the first device.

[0023] (13) In any one of (1) to (12) above, the communication planning device may be mounted on a vehicle. This makes it possible to prevent leakage and tampering of fragmented information when communicating it in information management in which predetermined information (e.g., confidential information) in the vehicle is divided into multiple pieces and stored in multiple second devices.

[0024] (14) A control method according to a second aspect of the present disclosure is a control method for communication between a first device and a second device in a system including a first device, a second device, and a communication device, the control method including: a planning step in which a control unit plans communication of predetermined information between the first device and the second device; and a detection step in which the control unit detects state-specific information required for planning the communication by the planning step, the planning step including a step in which the control unit plans communication of a plurality of pieces of fragmented information between the first device and the second device based on a detection result by the detection step, the fragmented information being information generated by dividing the predetermined information. This makes it possible to prevent leakage and tampering when communicating the divided fragmented information in information management in which the predetermined information (e.g., secret information) is divided into multiple pieces and stored in a plurality of second devices.

[0025] (15) A computer program according to a third aspect of the present disclosure causes a computer installed in a system including a first device, a second device, and a communication device to execute a planning function for planning communication of predetermined information between the first device and the second device and a detection function for detecting state-specific information required for the communication to be planned by the planning function, the planning function including a function for planning communication of a plurality of pieces of fragmented information between the first device and the second device based on a detection result by the detection function, the fragmented information being information generated by dividing the predetermined information. This makes it possible to prevent leakage and tampering when communicating the divided fragmented information in information management in which the predetermined information (e.g., confidential information) is divided into multiple pieces and stored on a plurality of second devices.

[0026] [Details of the embodiments of the present disclosure] In the following embodiments, the same components are denoted by the same reference numerals, and their names and functions are also the same. Therefore, detailed descriptions thereof will not be repeated.

[0027] (Overall Configuration) Referring to FIG. 1 , an in-vehicle system 100 according to an embodiment of the present disclosure is mounted on a vehicle. The in-vehicle system 100 includes a first relay 102, a second relay 104, an E-ECU (End-Electronic Control Unit) 106, an E-ECU 108, and an E-ECU 110, an off-vehicle communication unit 120, and a bus 122. The first relay 102 is, for example, a C-ECU (Central-Electronic Control Unit). The second relay is, for example, a Z-ECU (Zone-Electronic Control Unit). The external device 130 is, for example, a server computer (hereinafter simply referred to as a server), a roadside device, or an in-vehicle device of another vehicle. The in-vehicle system 100 communicates with an external device 130 via the external communication unit 120 and receives various information (traffic information and information to assist the driver (hereinafter referred to as driving assistance information)). The in-vehicle system 100 realizes various functions using information acquired from the external device 130 and information obtained from sensors mounted on a vehicle in which the in-vehicle system 100 is installed (hereinafter referred to as the host vehicle). For example, the in-vehicle system 100 presents driving assistance information to the driver of the host vehicle. If the host vehicle is capable of autonomous driving, the in-vehicle system 100 realizes autonomous driving.

[0028] The exterior communication unit 120 performs bidirectional communication between the in-vehicle system 100 and the outside (i.e., the external device 130). For example, the exterior communication unit 120 performs wide-area wireless communication (4G, 5G, etc.) and close-proximity wireless communication (Wi-Fi, Bluetooth (registered trademark), etc.).

[0029] The second relay device 104 includes a control unit 140 and a memory 142 and functions as a communication planning device. The control unit 140 includes a CPU (Central Processing Unit) and controls the memory 142. The memory 142 is, for example, a rewritable nonvolatile semiconductor memory and stores a computer program (hereinafter simply referred to as a program) executed by the control unit 140. The memory 142 provides a work area for the program executed by the control unit 140. The second relay device 104 also includes multiple input / output ports. In FIG. 1, input / output port 144 and input / output port 146 are shown as representatives. The input / output ports can be connected to devices for testing, adjusting, and the like of the in-vehicle system 100.

[0030] The second relay 104 coordinates data exchange between the exterior communication unit 120 and the E-ECUs 106, 108, 110, etc. That is, the second relay 104 transmits data received from the external device 130 via the exterior communication unit 120 to an E-ECU that requires the data via the bus 122. The second relay 104 also acquires E-ECU data (e.g., sensor data from an on-board sensor) via the bus 122 and transmits the data to the external device 130 that requires the data via the exterior communication unit 120. Note that communication between the second relay 104 and the E-ECUs 106, 108, 110, etc. may be performed via a wire harness instead of a bus.

[0031] The in-vehicle system 100 includes multiple E-ECUs, and FIG. 1 representatively shows E-ECUs 106, 108, and 110. Each E-ECU is a circuit for implementing the functions of the in-vehicle system 100 (such as vehicle driving control and on-board sensor control), and includes a control unit and memory. Examples of E-ECUs include an engine control ECU, a stop-start control ECU, a transmission control ECU, an airbag control ECU, a power steering control ECU, and a hybrid control ECU. An autonomously driven vehicle also includes an autonomous driving ECU. The autonomous driving ECU communicates with external devices as needed to obtain necessary information (traffic information and driving assistance information). Information received from an external device 130 via the external communication unit 120 is used, for example, by the autonomous driving ECU. The sensor data acquired by the E-ECU, which controls the on-board sensors, is transmitted to an external device 130 (e.g., a server or another vehicle) via the second relay device 104 and the external communication unit 120, and is used to generate driving assistance information, etc.

[0032] Like the second relay 104, the first relay 102 includes a control unit and a memory, and executes a program for realizing the functions of the in-vehicle system 100. Also, like the second relay 104, the first relay 102 may include a plurality of input / output ports.

[0033] For example, the external device 130 includes a vehicle electronic key (hereinafter simply referred to as the electronic key), the exterior communication unit 120 has a function for communicating with the electronic key, and the first relay 102 recognizes the electronic key. When the user has the electronic key and is within a predetermined range of the vehicle (including the interior of the vehicle), the user can lock and unlock the doors, turn on the vehicle's power, start the engine, and so on. In addition, the first relay 102 receives a code corresponding to the user's operation of the electronic key via the exterior communication unit 120, and locks and unlocks the vehicle's doors and automatically opens and closes the sliding door in accordance with the code.

[0034] The in-vehicle system 100 may manage confidential information. For example, to realize the above-described electronic key operation, it is necessary to properly recognize the electronic key for the vehicle. To achieve this, a unique ID (hereinafter referred to as an authentication ID) is exchanged between the electronic key and the in-vehicle system 100. Specifically, the electronic key transmits the authentication ID stored therein, and the in-vehicle system 100 determines whether the received authentication ID matches the authentication ID stored in the in-vehicle system 100. If the authentication ID matches, the user is able to perform the above-described operations on the vehicle. This authentication ID is confidential information, and the in-vehicle system 100 is responsible for securely managing the confidential information for a long period of time. When various functions are provided by registering biometric information (e.g., fingerprints and facial images) and personal information (e.g., name, address, telephone number, email address, etc.) in the in-vehicle system 100, such information is also confidential information and needs to be securely managed.

[0035] (Management of Secret Information) The function of the second relay 104 in managing secret information will now be described. Referring to FIG. 2 , the second relay 104 includes a data division and restoration unit 200, a communication destination determination unit 202, a communication monitoring unit 204, and a secret distribution control unit 206. Each unit is realized by the control unit 140 and memory 142 shown in FIG. 1 . The data division and restoration unit 200 receives a request from the first relay 102 and executes processing corresponding to the request. That is, upon receiving a code requesting confidentiality of information (hereinafter referred to as a confidentiality request), the data division and restoration unit 200 divides the input target data 210 (information to be kept confidential, e.g., secret information) into multiple pieces of fragmented information 212, as shown within the dashed-dotted line. Then, upon receiving an instruction from the secret distribution control unit 206 (described later), the data division and restoration unit 200 transmits the multiple pieces of fragmented information 212 to multiple E-ECUs (e.g., E-ECU 108 and E-ECU 110) and stores them in each E-ECU. The multiple (e.g., n) pieces of fragmented information 212 are transmitted one-to-one to multiple (n) E-ECUs, the number of pieces of fragmented information 212 being equal to the number of pieces of fragmented information 212, as determined by the communication destination determination unit 202. Since the target data 210 is restored from the fragmented information 212, the target data 210 is also referred to as the original data. Any method can be used to divide the target data 210 into pieces of fragmented information 212, such as a secret sharing scheme. Therefore, "division" does not simply mean dividing one piece of target data into multiple pieces of data, but also means generating multiple pieces of data by converting and adding data. The fragmented information 212 transmitted to the E-ECU is promptly erased from the data division and restoration unit 200 (memory 142 in FIG. 1 ) along with the original data.

[0036] Furthermore, when a code requesting the original data (hereinafter referred to as a restoration request) is input from the first relay 102, the data division and restoration unit 200 acquires the fragmentation information 212 from the E-ECU that stores the corresponding fragmentation information 212. Specifically, the data division and restoration unit 200 requests the E-ECU that stores the fragmentation information 212 to transmit the fragmentation information 212. The data division and restoration unit 200 restores the original data from the plurality of pieces of fragmentation information 212 received from the E-ECU. If the fragmentation information 212 has been generated using a secret sharing scheme (e.g., a (k, n) threshold scheme), the data division and restoration unit 200 can restore the original data if it can acquire from the E-ECU a number (k pieces) of fragmentation information that is less than the number (n pieces) of fragmentation information into which the original data was divided. After transmitting the restored original data to the first relay 102, the data division and restoration unit 200 promptly erases the original data and fragmentation information 212 from the data division and restoration unit 200 (memory 142 in FIG. 1).

[0037] When managing multiple pieces of secret information, the first relay 102 may transmit a confidentiality request accompanied by information (hereinafter referred to as original data identification information) that identifies the target data 210 to the data division and restoration unit 200. If the data division and restoration unit 200 stores a table that associates the original data identification information with information (hereinafter referred to as E-ECU identification information) that identifies the E-ECU that transmitted the corresponding fragmented information (shares in the secret sharing scheme) into which the target data 210 has been divided, the data division and restoration unit 200 can refer to the table to identify the E-ECU that will obtain the fragmented information.

[0038] In response to an instruction from the data dividing and restoring unit 200, the communication destination determination unit 202 determines an E-ECU in which to store each of the plurality of pieces of fragmented information 212 in a one-to-one correspondence. The communication destination determination unit 202 determines, as communication destination devices, the same number of E-ECUs as the plurality of pieces of fragmented information 212 from among the plurality of E-ECUs mounted on the vehicle and capable of communicating with the second relay 104. The communication destination determination unit 202 stores information identifying the determined communication destination devices (E-ECUs). Any method for determining a communication destination device may be used. The communication destination determination unit 202 may determine a communication destination device according to a predetermined rule or randomly. Furthermore, the communication destination determination unit 202 may determine a communication destination device taking into consideration the characteristics of each E-ECU (such as the real-time performance and memory capacity required for the function of each E-ECU).

[0039] The communication monitoring unit 204 monitors the communication state of the exterior communication unit 120, the state of any available ports among the multiple input / output ports (e.g., input / output port 144 and input / output port 146), and whether or not an unexpected communication device is connected. The communication monitoring unit 204 outputs information (hereinafter referred to as state identification information) indicating the detected communication state of the exterior communication unit 120, the state of any available ports, and the presence or absence of any unexpected communication device to the secret distribution control unit 206. The communication monitoring unit 204 can be said to be a unit that detects the communication state of the exterior communication unit 120, the state of any available ports, and the presence or absence of any unexpected communication device. The communication monitoring unit 204 may store the latest state identification information and output the state identification information to the secret distribution control unit 206 upon request from the secret distribution control unit 206. The communication state of the exterior communication unit 120 refers to whether or not the exterior communication unit 120 is communicating with the external device 130. The state of any available port basically refers to whether or not a device is connected. The communication status of the exterior communication unit 120 may include, when the exterior communication unit 120 is communicating, the type of communication (e.g., wide-area wireless communication, close-proximity wireless communication, and wired communication) and the communication speed (e.g., in Mbps). When a device is connected, the status of the available port may include the characteristics of the device. Furthermore, when the components constituting the in-vehicle system 100 (e.g., between the first relay 102 and the second relay 104) are connected by a wire harness, there is a possibility that the wire harness may be modified, resulting in the connection of an unexpected communication device. Therefore, the communication monitoring unit 204 monitors whether an unexpected communication device is connected, i.e., whether an unexpected communication device is connected to the communication path within the vehicle. This information is related to the possibility of information leakage.

[0040] The secret sharing control unit 206 controls the timing at which the data division and restoration unit 200 communicates fragmented information with the communication destination device (E-ECU) determined by the communication destination determination unit 202. The "communication of fragmented information" includes both communication in which the data division and restoration unit 200 transmits fragmented information 212 to the communication destination device and communication in which the data division and restoration unit 200 receives fragmented information 212 stored in the communication destination device. The secret sharing control unit 206 determines the current communication state of the exterior communication unit 120, the connection state of unused ports, and the presence or absence of connections of unexpected communication devices from the state identification information input from the communication monitoring unit 204, and accordingly determines whether or not to communicate fragmented information (plans communication). If the secret sharing control unit 206 determines to communicate fragmented information, it instructs the data division and restoration unit 200 to communicate, and the data division and restoration unit 200 communicates the fragmented information.

[0041] For example, if the exterior communication unit 120 is not communicating externally (communicating with the external device 130), no device is connected to an unused port among the input / output ports, and no unexpected communication device is connected, the risk of information leakage is low or nonexistent (hereinafter referred to as a safe state). Therefore, the data division and restoration unit 200 determines to communicate the fragmented information. If the exterior communication unit 120 is communicating externally (communicating with the external device 130), a device is connected to an unused port among the input / output ports, or an unexpected communication device is connected, the risk of information leakage is relatively high (hereinafter referred to as a dangerous state). Therefore, the data division and restoration unit 200 does not determine to communicate the fragmented information. If the dangerous state persists, it is not safe for the data division and restoration unit 200 to store multiple pieces of fragmented information. Furthermore, if the first relay 102 requests the ID of the electronic key as the original data, the fragmented information must be quickly acquired from the E-ECU, restored, and output to the first relay 102. Therefore, after waiting for a predetermined period of time, the data division and restoration unit 200 may decide to communicate the fragmented information even if the dangerous state continues. This predetermined period (first predetermined period) may be determined based on the characteristics (e.g., real-time performance) of the function of the first relay 102 that uses the original data requested by the first relay 102. If the required real-time performance is high, the predetermined period can be set relatively short. If the required real-time performance is low, the predetermined period can be set relatively long.

[0042] This allows the second relay 104 to communicate fragmentation information with the E-ECU in a safe state, preventing the fragmentation information from leaking outside the vehicle during the communication process. Even in a dangerous state, the second relay 104 can communicate fragmentation information with the E-ECU without impairing the real-time nature of the functions provided by the first relay 102, thereby preventing any disruption to the functions of the first relay 102.

[0043] (Operation of the Second Relay) The operation of the second relay 104 will be further described with reference to Fig. 3. The process shown in Fig. 3 is realized by the control unit 140 of the second relay 104 shown in Fig. 1 reading and executing a predetermined program from the memory 142. Note that the control unit 140 executes a program for realizing the function of the communication monitoring unit 204 shown in Fig. 2 in parallel with this program. That is, this program is for realizing the functions of the data division and restoration unit 200, communication destination determination unit 202, and secret sharing control unit 206 shown in Fig. 2. A secret sharing scheme is used to generate the fragmentation information.

[0044] In step 300, the control unit 140 determines whether a request has been received from the first relay 102. As described above, the first relay 102 outputs an encipherment request or a restoration request to the second relay 104. If it is determined that a request has been received, control proceeds to step 302. Otherwise, control proceeds to step 324. As a result, while this program is being executed, the control unit 140 waits for a request from the first relay 102. Note that, as described above, when the first relay 102 outputs an encipherment request, it also outputs data to be enciphered. Therefore, the control unit 140 receives the target data along with the encipherment request.

[0045] In step 302, the control unit 140 determines whether the request received in step 300 is a confidentiality request. If it is determined to be a confidentiality request, control proceeds to step 304. Otherwise (i.e., if a restoration request has been received), control proceeds to step 308.

[0046] In step 304, the control unit 140 determines, from among the plurality of E-ECUs, an E-ECU that will store the share (fragmentation information) generated in a step described later, as a communication destination device. Then, control proceeds to step 306.

[0047] In step 306, the control unit 140 divides the target data received in step 300 into multiple shares, as described above. The control unit 140 generates multiple shares from the target data using a secret sharing scheme. Then, control proceeds to step 310.

[0048] If the request received in step 300 is a restoration request, in step 308, the control unit 140 selects an E-ECU from among multiple E-ECUs that stores shares for restoring the requested original data as the collection destination device (the device from which the shares will be acquired). Control then proceeds to step 310. When handling one piece of secret information, the communication destination device and the collection destination device include the same E-ECU. When handling multiple pieces of secret information, the control unit 140 receives the restoration request along with original data identification information, as described above, and can determine the collection destination device by referencing a table that associates the original data identification information with the E-ECU identification information. When shares are generated using a secret sharing method (e.g., a (k, n) threshold method), the number of shares is n, while the number of shares to be collected may be k, where k is less than or equal to n.

[0049] In step 310, the control unit 140 acquires state identification information. Control then proceeds to step 312. As described above, the state identification information includes information indicating the exterior communication state, the port connection state, and whether or not an unexpected communication device is connected. The state identification information is information obtained through monitoring by the communication monitoring unit 204 shown in FIG. 2. As described above, the function of the communication monitoring unit 204 is realized by a program executed by the control unit 140 in parallel with this program. The state identification information is passed to this program, for example, via a predetermined area in the memory 142.

[0050] In step 312, the control unit 140 determines whether the vehicle exterior communication state, the state of the idle port, and the presence or absence of an unexpected communication device connection, which are represented by the state identification information acquired in step 310, are in the above-described safe state. If it is determined that the vehicle exterior communication state is in the safe state, control proceeds to step 316. If not, control proceeds to step 314.

[0051] In step 314, the control unit 140 determines whether the predetermined period has elapsed. If it is determined that the predetermined period has elapsed, control proceeds to step 316. If not, control returns to step 310, and steps 310 and 312 are repeated. As described above, the predetermined period may be determined based on the characteristics (e.g., real-time performance) of the function of the first relay 102 that uses the original data requested by the first relay 102.

[0052] In step 316, the control unit 140 executes the same process as in step 302. If it is determined that the request is a concealment request, control proceeds to step 318. Otherwise (i.e., if a restoration request is received), control proceeds to step 320.

[0053] In step 318, the control unit 140 transmits the multiple shares generated in step 306 to the communication destination device (E-ECU) determined in step 304. At this time, either one share or multiple shares may be transmitted to one communication destination device. However, care must be taken to prevent a single share from being transmitted to multiple communication destination devices in duplicate. Furthermore, when multiple shares are transmitted to one communication destination device, it is necessary to limit the number of shares transmitted to one communication destination device so that the original data is not restored by the multiple shares transmitted to one communication destination device. For example, when shares are generated using the (k, n) threshold method, a number of shares less than k is transmitted to one communication destination device. After transmission is complete, the control unit 140 erases all shares. Control then proceeds to step 324.

[0054] If the determination result in step 316 is NO (a restoration request has been received), in step 320, the control unit 140 acquires the share from the collection destination device (E-ECU) determined in step 308 and restores the original data. Thereafter, control proceeds to step 322.

[0055] In step 322, the control unit 140 transmits the original data restored in step 320 to the first relay 102. Thereafter, control proceeds to step 324. As a result, the first relay 102 can obtain the data requested from the second relay 104 and deliver the data to the application software (hereinafter simply referred to as application) that requires it.

[0056] In step 324, the control unit 140 determines whether an end instruction has been received. If it is determined that an end instruction has been received, the program ends. If not, control returns to step 300, and the above processing is repeated. The end instruction is issued, for example, by turning off the start button or the like of the vehicle in which the in-vehicle system 100 is installed.

[0057] As a result, in information management in which specific information (e.g., secret information) is divided into multiple pieces and stored in multiple E-ECUs, the second relay device 104 communicates multiple fragmented information (shares) in a safe state, thereby preventing leakage and tampering during communication.

[0058] Furthermore, if the dangerous state persists, the second relay 104 communicates fragmentation information with the E-ECU after a predetermined period of time has elapsed so as not to impair the real-time nature of the functions provided by the first relay 102. This prevents a situation in which multiple pieces of fragmentation information cannot be communicated from continuing indefinitely, thereby preventing any disruption to the functions of the first relay 102.

[0059] Furthermore, by setting the specified period based on the characteristics (e.g., real-time performance) of the function of the first relay device 102 that requires the original data restored using the fragmentation information, it is possible to avoid compromising the real-time performance required for the function of the first relay device 102.

[0060] As described above, the system includes a data division and restoration unit 200 that divides target data into multiple pieces of fragmented information, and the target data is input from the first relay 102 to the second relay 104, and the data division and restoration unit 200 generates the fragmented information using the secret sharing scheme. This makes it possible to further prevent information leakage and tampering.

[0061] As described above, the second relay 104 includes a communication destination determination unit 202 that determines, from among the plurality of E-ECUs, E-ECUs whose number is equal to or less than the number of pieces of fragmentation information as communication destination devices, and each piece of fragmentation information is communicated between the communication destination device and the second relay 104 based on a plan set by the secret distribution control unit 206. This makes it possible to further prevent information leakage and tampering.

[0062] Furthermore, in response to a request for predetermined information (restoration request) input from the first relay 102 to the second relay 104, the communication destination determination unit 202 determines, from among the plurality of communication destination devices (E-ECUs), a plurality of partner devices (E-ECUs) from which to acquire fragmented information, and the data division and restoration unit 200 has a restoration function for generating predetermined information from the fragmented information received from the plurality of partner devices. As a result, original data can be generated from the fragmented information stored in a distributed manner in the plurality of E-ECUs and provided to the first relay 102.

[0063] As described above, the second relay device 104 is mounted on a vehicle. This prevents leakage and tampering of fragmented information when communicating it in information management in which predetermined information (e.g., confidential information) in the vehicle is divided into multiple pieces and stored in multiple E-ECUs.

[0064] (Application Example) When using the electronic key to lock and unlock vehicle doors, if a third party learns the authentication ID, there is a risk that the third party may illegally unlock the doors while the user is absent. To address this risk, for example, when the vehicle is shipped, the authentication ID (confidential information) of the electronic key may be divided to generate multiple pieces of fragmented information, and each piece of fragmented information may be stored in multiple E-ECUs of the in-vehicle system 100. When a user operates the vehicle (e.g., unlocking or locking), for example, the first relay 102 of the in-vehicle system 100 performs authentication processing of the electronic key possessed by the user in advance. During the authentication process, the second relay 104 of the in-vehicle system 100 receives a restoration request from the first relay 102, obtains the fragmented information from the E-ECU storing the fragmented information, decodes the in-vehicle authentication ID, and outputs it to the first relay 102. The first relay 102 determines whether the authentication ID received from the electronic key matches the restored authentication ID. At this time, in a safe state, the second relay device 104 acquires the fragmentation information by communication from the E-ECU that stores the fragmentation information, thereby avoiding the risk that the fragmentation information will be acquired by a third party during the process of communicating the fragmentation information, and that the authentication ID will become known to the third party.

[0065] As described above, during the authentication process, unless the device is in a safe state, the fragmented information for restoring the authentication ID is not transmitted for a predetermined period of time. Since electronic key authentication must be performed quickly and requires a relatively high level of real-time accuracy, the predetermined period is set to be relatively short.

[0066] (First Modification) In the above, a case has been described in which fragmentation information is not communicated (i.e., a predetermined period of time is waited) if a dangerous state exists, but this is not limiting. In the first modification, communication of fragmentation information is executed depending on the degree of the dangerous state.

[0067] The in-vehicle system according to the first modification has the same configuration as the in-vehicle system 100 shown in FIG. 1 , while the configuration of the second relay according to the first modification is different from that shown in FIG. 2 . Referring to FIG. 4 , the second relay 104A according to the first modification includes a data division and restoration unit 200, a communication destination determination unit 202, a communication monitoring unit 204, a secret distribution control unit 206, and a security strength evaluation unit 220, and functions as a communication planning device. Each unit is realized by the control unit 140 and memory 142 shown in FIG. 1 . The second relay 104A shown in FIG. 4 is the second relay 104 shown in FIG. 2 to which the security strength evaluation unit 220 has been added. In FIG. 4 , components with the same reference numerals as those in FIG. 2 have the same functions as those in FIG. 2 . Therefore, the following description will not be repeated and will mainly focus on the differences. Furthermore, the second relay 104 in FIG. 1 will be read as the second relay 104A, and the reference numerals shown in FIG. 1 will be referenced as appropriate.

[0068] The security strength evaluation unit 220 evaluates the security strength based on the state identification information input from the communication monitoring unit 204, and outputs the evaluation result to the secret distribution control unit 206. As described above, the state identification information is information that represents the communication state of the exterior communication unit 120, the state of unused ports such as the input / output port 144 and the input / output port 146, and whether or not an unexpected communication device is connected, which are detection results by the communication monitoring unit 204. The security strength evaluation unit 220 stores evaluation tables such as those shown in FIGS. 5 and 6 in order to determine the security strength from the communication state of the exterior communication unit 120, the state of unused ports, and whether or not an unexpected communication device is connected.

[0069] Referring to FIG. 5 , the communication state of the exterior communication unit 120 is represented by a combination of a communication type and a communication speed. The security strength for each combination of a communication type and a communication speed is represented by three levels: “high,” “medium,” and “low.” In FIG. 5 , the communication types shown are physical communication (wired communication), close proximity wireless communication, and wide-area wireless communication. The communication speed is divided into three ranges: less than a (Mbps), a (Mbps) or more but less than b (Mbps), and b (Mbps) or more. a and b are real numbers satisfying 0<a<b. Regarding the setting of each level, for example, when the communication speed is high, the risk of information leakage due to unauthorized access increases, so the security strength is set relatively low. Regarding the communication type, when wide-area wireless communication is used, the security strength is set relatively low because unauthorized access is relatively easy.

[0070] FIG. 6 shows an example of setting security strength for a combination of the state of an empty port and the presence or absence of an unexpected communication device connected. Referring to FIG. 6, the state of an empty port is represented by the presence or absence of a connected device and, if a device is connected, whether the device is an expected device. An expected device refers to a device known to be safe, while an unexpected device refers to a device not known to be safe. The presence or absence of an unexpected communication device connected is represented by "connected" or "not connected." In FIG. 6, "lowest" is used to indicate a level lower than the three levels shown in FIG. 5. Regardless of whether a device is connected to an empty port, if an unexpected communication device is connected, the security strength is set to "lowest." A "-" is indicated for cases where no device is connected to an empty port and no unexpected communication device is connected. Since secret sharing is possible in such cases without calculating the security strength, a "-" is indicated to indicate that the security strength is not taken into consideration, i.e., the security strength is not calculated. Whether a device connected to an empty port is an expected device can be determined by storing information about expected devices (devices known to be safe) in advance.

[0071] As described above, the security strength evaluation unit 220 identifies the communication state of the exterior communication unit 120, the state of the available ports, and whether or not an unexpected communication device is connected, based on the state identification information received from the communication monitoring unit 204, and then refers to the evaluation table (see FIGS. 5 and 6 ) to identify the levels of each of the communication state and the state of the available ports of the exterior communication unit 120. Since two levels are identified, the security strength evaluation unit 220 determines the lower of the two levels as the security strength.

[0072] When the detection result of the communication monitoring unit 204 indicates a dangerous state and there is a risk of information leakage during the communication process by communicating fragmented information with each E-ECU, the secret sharing control unit 206 determines whether or not to communicate fragmented information with each E-ECU, depending on the security strength input from the security strength evaluation unit 220. Even when the detection result of the communication monitoring unit 204 indicates a dangerous state, the secret sharing control unit 206 determines to communicate fragmented information with each E-ECU if the security strength is at or above a predetermined level. This makes it possible to avoid unnecessary suppression of communication of multiple pieces of fragmented information, and to control communication of multiple pieces of fragmented information depending on the risk of information leakage.

[0073] In the above description, the security strength is evaluated based on the communication status of the exterior communication unit 120, the status of available ports, and whether or not an unexpected communication device is connected. However, the present invention is not limited to this. The security strength may be evaluated based on at least one of the communication status of the exterior communication unit 120, the status of available ports, and whether or not an unexpected communication device is connected. This allows the security strength to be appropriately evaluated.

[0074] In the above description, the security strength is determined based on the communication status of the exterior communication unit 120, the connection status of available ports, and whether or not an unexpected communication device is connected. However, this is not limiting. For example, the security strength may be determined according to the characteristics of the data to be concealed. For example, if the data is highly confidential or important, the security strength may be set low in consideration of the impact of information leakage.

[0075] (Operation of the Second Relay Device) The operation of the second relay device 104A will be further described with reference to FIG. 7. A secret sharing scheme is used to generate fragmentation information. The process shown in FIG. 7 is implemented by the control unit 140 reading and executing a predetermined program from the memory 142, similar to the second relay device 104 shown in FIG. 1. The control unit 140 executes a program for implementing the functions of the communication monitoring unit 204 shown in FIG. 2 in parallel with this program. That is, this program implements the functions of the data division and restoration unit 200, communication destination determination unit 202, secret sharing control unit 206, and security strength evaluation unit 220 shown in FIG. 4. The flowchart in FIG. 7 is the flowchart shown in FIG. 3 to which steps 340 and 342 have been added. In FIG. 7, steps with the same reference numerals as those in FIG. 3 execute the same processes as those in FIG. 3. Therefore, the following description will not be repeated and will focus primarily on the differences.

[0076] After step 310 is executed, in step 340, the control unit 140 evaluates the security strength S. Then, control proceeds to step 312. This corresponds to the function of the security strength evaluation unit 220 described above. The control unit 140 determines the security strength by referring to the evaluation table as described above. The security strength is expressed, for example, by one of four levels: "high," "medium," "low," and "lowest," as described above.

[0077] In step 312, the control unit 140 determines whether the external communication state, the state of the available port, and the presence or absence of an unexpected communication device connection are in a safe state, as described above. If the safe state is met, control proceeds to step 316; if not, control proceeds to step 342.

[0078] In step 342, the control unit 140 determines whether the security strength determined in step 340 is equal to or greater than a predetermined threshold value Th. If it is determined that S≧Th (the security strength is equal to or greater than the predetermined threshold value Th), control proceeds to step 316. Otherwise, control proceeds to step 314. As described above, the security strength is expressed by four levels: "high," "medium," "low," and "lowest," so the threshold value Th is set to one of "high," "medium," "low," and "lowest." For example, if the threshold value Th is set to "medium," and the security strength S is "high" or "medium," it is determined that S≧Th.

[0079] As described above, the second relay device 104A, like the second relay device 104, manages information by dividing specified information (e.g., secret information) into multiple pieces and storing them in multiple E-ECUs, and communicates multiple fragmented information (shares) in a safe state, thereby preventing leakage and tampering during communication.

[0080] Furthermore, if the external communication state, the available port state, and the presence or absence of an unexpected communication device are not in a safe state and there is a risk of information leakage during communication of the fragmented information with each E-ECU, the second relay 104A determines whether to communicate the fragmented information with each E-ECU according to the security strength (see step 342). Even if the safe state is not reached, the second relay 104A determines to communicate the fragmented information with each E-ECU if the security strength is equal to or higher than a predetermined level (the determination result in step 342 is YES). This prevents unnecessary suppression of communication of multiple pieces of fragmented information and allows communication of multiple pieces of fragmented information to be controlled according to the risk of information leakage.

[0081] (Specific Example of Security Strength) A specific example of security strength setting will be described. For example, referring to FIG. 8 , in an in-vehicle system 100A configured by adding a camera 160 to the in-vehicle system 100 shown in FIG. 1 , the first relay 102 executes an application for monitoring the interior of the vehicle. The camera 160 is, for example, a digital video camera. For example, the first relay 102 divides a large amount of in-vehicle monitoring video data captured by the camera 160 into fragmented information and stores the fragmented information in multiple E-ECUs via the second relay 104A. In this case, if the communication speed between the external device 130 via the external communication unit 120 is relatively slow, even if a large amount of fragmented information is communicated between the second relay 104A and the E-ECU, there is a low possibility that the fragmented information will be leaked outside the vehicle due to unauthorized access during the communication process. Therefore, the security strength can be set relatively high.

[0082] Furthermore, when a drive recorder is connected to an available port of the second relay 104A or the first relay 102, if the drive recorder is provided by a dealer, it falls within the expected range of devices, and therefore the security strength can be set relatively high. A dealer refers to, for example, a trusted sales company that has a contract with an automobile manufacturer or its affiliated sales company. Information for identifying a drive recorder provided by a dealer can be stored in advance in the memory of the second relay 104A. The second relay 104A can access the connected device and obtain information about the device (a function of the communication monitoring unit 204) to determine whether the drive recorder is a dealer's drive recorder. The security strength evaluation unit 220 can determine the security strength by referring to the evaluation table described above based on the determination result of the communication monitoring unit 204.

[0083] In the above, the case where security strength is expressed by four levels, "high," "medium," "low," and "lowest," has been described, but this is not limiting. Security strength may be expressed by multiple levels, and may be expressed by three or fewer levels, or five or more levels. Furthermore, security strength may be expressed by a numerical value (such as a positive integer). In this case, each level may be set within a predetermined numerical range.

[0084] (Second Modification) In the above, a case has been described in which fragmented information is not communicated (i.e., waiting for a predetermined period) if the state is at risk, and a case in which communication of fragmented information is executed according to the level of the risk state (security strength), but this is not limited to these. In the second modification, if communication can be cut off in a risk state, communication is temporarily cut off and communication of the fragmented information is executed.

[0085] The in-vehicle system according to the second modification has the same configuration as the in-vehicle system 100 shown in FIG. 1 , but the configuration of the second relay according to the second modification is different from that shown in FIG. 2 . Referring to FIG. 9 , the second relay 104B according to the second modification includes a data division and restoration unit 200, a communication destination determination unit 202, a communication monitoring unit 204, a secret distribution control unit 206, and a communication control unit 230, and functions as a communication planning device. Each unit is realized by the control unit 140 and memory 142 shown in FIG. 1 . The second relay 104B shown in FIG. 9 is the second relay 104 shown in FIG. 2 to which the communication control unit 230 has been added. In FIG. 9 , components with the same reference numerals as those in FIG. 2 have the same functions as those in FIG. 2 . Therefore, the following description will not be repeated and will mainly focus on the differences. Furthermore, the second relay 104 in FIG. 1 will be read as the second relay 104B, and the reference numerals shown in FIG. 1 will be referenced as appropriate.

[0086] The communication control unit 230 determines whether communication by the exterior communication unit 120 can be temporarily disconnected. The communication control unit 230 outputs the determination result to the secret sharing control unit 206. When the detection result of the communication monitoring unit 204 indicates a dangerous state and there is a risk of information leakage during communication by communicating fragmented information with each E-ECU, the secret sharing control unit 206 determines whether to communicate fragmented information with each E-ECU according to the determination result input from the communication control unit 230. If the determination result input from the communication control unit 230 indicates that communication can be disconnected, the secret sharing control unit 206 instructs the communication control unit 230 to disconnect communication by the exterior communication unit 120 and determines to communicate fragmented information with each E-ECU. Upon receiving the instruction to disconnect communication, the communication control unit 230 causes the exterior communication unit 120 to disconnect communication and maintain the disconnected state for a predetermined period (a second predetermined period). After the predetermined period has elapsed, the communication control unit 230 causes the exterior communication unit 120 to resume communication.

[0087] The predetermined period for disconnecting communication by exterior communication unit 120 is set to a period equal to or longer than the period for completing communication of the fragmented information between second relay device 104 and the E-ECU. By setting the period in this manner, communication by exterior communication unit 120 is maintained in a disconnected state while communication of the fragmented information is being carried out.

[0088] For example, when the communication state of the exterior communication unit 120 is related to a function being executed by the in-vehicle system 100 (e.g., an application being executed by the first relay 102), the communication control unit 230 determines whether communication by the exterior communication unit 120 can be temporarily disconnected. For example, when the host vehicle is using a service that communicates with an exterior device and disconnecting the communication would prevent the vehicle from traveling, the communication control unit 230 determines that communication by the exterior communication unit 120 cannot be disconnected. For example, when a function such as remote control or blind spot information sharing is being executed, the communication control unit 230 determines that communication by the exterior communication unit 120 cannot be disconnected. When the host vehicle is traveling autonomously, the communication control unit 230 determines that communication by the exterior communication unit 120 can be disconnected. When communication by the exterior communication unit 120 is related to a function that requires real-time performance, not limited to an autonomous traveling function, the communication control unit 230 determines that communication by the exterior communication unit 120 cannot be disconnected.

[0089] Furthermore, for example, when the first relay device 102 is running an application that plays back music data or video data, etc., downloaded from an external device 130 (e.g., a server), if a predetermined amount of data is stored in a buffer, the communication control unit 230 may determine that communication with the exterior-vehicle communication unit 120 can be disconnected. For example, if the second relay device 104 can complete communication of fragmentation information with each E-ECU during the period from when the data is stored in the buffer until the use (playback) of the data is completed (hereinafter referred to as the buffer period), the communication control unit 230 may determine that communication with the exterior-vehicle communication unit 120 can be disconnected. Furthermore, the communication control unit 230 may also determine that communication with the exterior-vehicle communication unit 120 can be disconnected when a block of music data or video data can be downloaded in bulk and then played back.

[0090] In this way, even if the detection result of the communication monitoring unit 204 indicates a dangerous state, the secret distribution control unit 206 determines to disconnect the communication of the exterior communication unit 120 and to communicate the fragmented information with each E-ECU. This makes it possible to avoid a state in which the fragmented information cannot be communicated continuing indefinitely. Note that, although the above describes a case in which the communication of the exterior communication unit 120 is disconnected, this is not limitative. It is sufficient if the communication of the exterior communication unit 120 can be restricted. By restricting the communication of the exterior communication unit 120, it is possible to suppress leakage of the fragmented information during the communication process of the fragmented information.

[0091] As described above, if communication by the exterior-vehicle communication unit 120 is not being performed for a function that requires real-time performance, the communication control unit 230 may determine that it is possible to block communication by the exterior-vehicle communication unit 120. This allows multiple pieces of fragmented information to be communicated while avoiding impairing the real-time performance required for the function.

[0092] As described above, if the buffer period for a predetermined amount of data in communication by the exterior communication unit 120 is longer than the period required to communicate the plurality of pieces of fragmented information, it may be determined that communication by the exterior communication unit 120 can be restricted. This allows the plurality of pieces of fragmented information to be communicated without affecting the function of executing external communication.

[0093] (Operation of the Second Relay Device) The operation of the second relay device 104B will be further described with reference to FIG. 10 . A secret sharing scheme is used to generate fragmentation information. The process shown in FIG. 10 is implemented by the control unit 140 reading and executing a predetermined program from the memory 142, similar to the second relay device 104 shown in FIG. 1 . The control unit 140 executes a program for implementing the functions of the communication monitoring unit 204 shown in FIG. 2 in parallel with this program. That is, this program implements the functions of the data division and restoration unit 200, communication destination determination unit 202, secret sharing control unit 206, and communication control unit 230 shown in FIG. 9 . The flowchart in FIG. 10 is the same as the flowchart in FIG. 3 , except that step 314 is replaced by step 350 and steps 352 and 354 are added. In FIG. 10 , steps with the same reference numerals as those in FIG. 3 execute the same process as in FIG. 3 . Therefore, the following description will not be repeated and will focus mainly on the differences.

[0094] In step 312, the control unit 140 determines whether the communication state of the exterior communication unit 120, the state of the available port, and the presence or absence of an unexpected communication device connection are in a safe state, as described above. If it is determined that the state is in a safe state, control proceeds to step 316. If not, control proceeds to step 350.

[0095] In step 350, the control unit 140 determines whether or not it is possible to disconnect the communication of the exterior-vehicle communication unit 120. If it is determined that it is possible to disconnect, the control proceeds to step 352. If it is not possible to disconnect, the control returns to step 310, and steps 310 and 312 are executed. As a result, if it is not a safe state (the determination result in step 312 is NO), the standby state is maintained and no sharing communication is performed until it is possible to disconnect the exterior-vehicle communication unit 120.

[0096] In step 352, the control unit 140 temporarily disconnects communication from the exterior communication unit 120. Thereafter, control proceeds to step 316. Steps 350 and 352 correspond to the functions of the communication control unit 230 described above.

[0097] If the process proceeds to step 316, the process according to the request from the first relay 102 is executed as described above. That is, the share is transmitted to the E-ECU (step 318), or the share is collected from the E-ECU and the original data is restored (steps 320 and 322). Then, the control proceeds to step 354.

[0098] In step 354, the control unit 140 causes the exterior communication unit 120 to resume the communication that was cut off in step 352. Thereafter, the control proceeds to step 324.

[0099] As a result of the above, even if the detection result of the communication monitoring unit 204 indicates a dangerous state, the second relay device 104B determines to disconnect communication with the exterior communication unit 120 and to communicate fragmentation information (share) with each E-ECU. This makes it possible to avoid a situation in which communication of fragmentation information cannot be continued for an extended period of time.

[0100] In the above description, the communication planning device is the second relay 104, the second relay 104A, and the second relay 104B mounted on a vehicle. However, the present invention is not limited to this. The communication planning device may be mounted on a device or system having a function of communicating with an external device. When confidential information needs to be stored in the device or system as fragmented information in a distributed manner, the communication planning device performs the above-described operation. This makes it possible to prevent information leakage during the communication process of the fragmented information within the device or system.

[0101] Each process (each function) in the above-described embodiments and variations may be realized by a processing circuit (circuitry) including one or more processors. The processing circuit may be configured by an integrated circuit or the like that combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each process. The one or more processors may execute each process according to the program read from the one or more memories, or may execute each process according to a logic circuit designed in advance to execute each process. The processor may be any of various processors suitable for computer control, such as a CPU, a GPU (Graphics Processing Unit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), or an ASIC (Application Specific Integrated Circuit). The physically separated processors may cooperate with each other to execute the processes. For example, the processors installed in the physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), or the Internet to execute the processes.

[0102] Although the present disclosure has been described above by explaining the embodiments, the above-described embodiments are merely examples, and the present disclosure is not limited to only the above-described embodiments. The scope of the present disclosure is defined by the claims in the scope of the claims, taking into consideration the description of the detailed description of the invention, and includes all modifications within the meaning and scope equivalent to the wording described therein.

[0103] 100, 100A In-vehicle system 102 First relay device 104, 104A, 104B Second relay device 106, 108, 110 E-ECU 120 Exterior communication unit 122 Bus 130 External device 140 Control unit 142 Memory 144, 146 Input / output port 160 Camera 200 Data division and restoration unit 202 Communication destination determination unit 204 Communication monitoring unit 206 Secret distribution control unit 210 Target data 212 Fragmentation information 220 Security strength evaluation unit 230 Communication control unit 300, 302, 304, 306, 308, 310, 312, 314, 316, 318, 320, 322, 324, 340, 342, 350, 352, 354 Step

Claims

1. A communication planning device mounted on a system including a first device, a second device, and a communication device, a planning unit that plans communication of predetermined information between the first device and the second device; a detection unit that detects state specifying information required for the planning unit to plan the communication; the planning unit plans communication of a plurality of pieces of fragmented information between the first device and the second device based on a detection result by the detection unit; The fragmented information is information generated by dividing the predetermined information.

2. The communication planning device of claim 1, wherein the status identification information includes information representing at least one of the following: the communication status of external communication, which is communication by the communication device with an outside of the system; the status of input / output ports possessed by each of the communication planning device and the first device; and whether or not an unexpected communication device is connected to a communication path within the system.

3. The communication planning device according to claim 1 or claim 2, wherein the planning unit, when it is determined based on the detection result that the plurality of fragmented information will not be communicated, plans to communicate the plurality of fragmented information after a first predetermined period has elapsed.

4. The communication planning device according to claim 3 , wherein the first predetermined period is determined based on real-time characteristics of a function that requires communication of the plurality of pieces of fragmented information.

5. a security strength evaluation unit that evaluates security strength regarding information leakage from the system; The communication planning device described in claim 1 or claim 2, wherein when the planning unit determines based on the detection result that the plurality of fragmented information will not be communicated, if the security strength evaluated by the security strength evaluation unit is at or above a predetermined level, the planning unit plans to communicate the plurality of fragmented information.

6. The communication planning device according to claim 5 , wherein the security strength evaluation unit evaluates the security strength based on the detection result.

7. a communication control unit that causes the communication device to restrict external communication, which is communication with an outside of the system, by the communication device; The planning unit If the external communication can be restricted, causing the communication control unit to restrict the external communication for a second predetermined period of time; The communication planning device according to claim 1 or 2, wherein the communication planning device plans to communicate the plurality of pieces of fragmented information during the second predetermined period.

8. The communication planning device according to claim 7 , wherein the planning unit determines that the external communication can be restricted if the external communication is not being executed for a function that requires real-time performance.

9. The communication planning device of claim 7, wherein the planning unit determines that the external communication can be restricted if the period from when a predetermined amount of data is stored in a buffer in the external communication to when the use of the data is completed is longer than the period required to communicate the multiple pieces of fragmented information.

10. further comprising an information processing unit that divides the predetermined information into the plurality of pieces of fragmented information; the predetermined information is transmitted from the first device to the second device via the communication planning device; The communication planning device according to claim 1 or 2, wherein the information processing unit generates the fragmented information using a secret sharing scheme.

11. a communication destination determination unit that determines, from among the plurality of second devices, communication destination devices whose number is equal to or less than the number of pieces of fragmentation information; The communication planning device according to claim 10 , wherein the plurality of pieces of fragmented information are communicated between the communication destination device and the communication planning device based on a plan by the planning unit.

12. the communication destination determination unit, upon receiving a request for the predetermined information from the first device to the communication planning device, determines a plurality of destination devices to receive the fragmented information from among the plurality of communication destination devices; The communication planning device according to claim 11 , further comprising a restoration unit that generates the predetermined information from the fragmented information received from a plurality of the partner devices.

13. The communication planning device according to claim 1 or 2, which is mounted on a vehicle.

14. 1. A method for controlling communication between a first device and a second device in a system including the first device, a second device, and a communication device, comprising: a planning step in which a control unit plans communication of predetermined information between the first device and the second device; a detection step in which the control unit detects state specifying information required for the communication to be planned by the planning step, the planning step includes a step of the control unit planning communication of a plurality of pieces of fragmented information between the first device and the second device based on a detection result of the detection step; A control method, wherein the fragmented information is information generated by dividing the specified information.

15. A computer installed in a system including a first device, a second device, and a communication device, a planning function for planning communication of predetermined information between the first device and the second device; a detection function for detecting state-specific information required for the communication to be planned by the planning function; the planning function includes a function of planning communication of a plurality of pieces of fragmented information between the first device and the second device based on a detection result by the detection function; A computer program, wherein the fragmented information is information generated by dividing the specified information.