Time falsification prevention method and apparatus for security of fod services
The time tampering prevention device and method address the issue of illegal FoD service use by verifying time accuracy and certificate validity, ensuring secure and cost-effective FoD service activation.
Patent Information
- Application Number
- PCT/KR2025/002813
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-28
- Filing Date
- 2025-02-28
- Publication Date
- 2025-09-04
AI Technical Summary
The challenge of preventing time tampering in Feature on Demand (FoD) services in vehicles, which can lead to illegal use after the expiration of the usage period, and the need to avoid the costs and burdens of using a Network Time Protocol (NTP) server for time synchronization.
A time tampering prevention device and method that includes a certificate receiving unit, time obtaining unit, time error obtaining unit, and service determining unit to verify the authenticity and time accuracy of FoD services, preventing illegal use by comparing time errors and determining service activation based on these verifications.
Prevents illegal use of FoD services by ensuring time accuracy and certificate validity, eliminating the need for an NTP server and reducing communication costs.
Smart Images

Figure KR2025002813_04092025_PF_FP_ABST
Abstract
Description
Method and device for preventing time tampering for securing FOD services
[0001] The present disclosure relates to a method and device for preventing time tampering for securing FoD services.
[0002] The content described below merely provides background information related to the present embodiment and does not constitute prior art.
[0003] The electric vehicle market is steadily growing, driven by advancements in battery technology and the development of charging infrastructure. Furthermore, advancements in technologies like artificial intelligence, mobile / wireless communications, cloud computing, sensors, and precision positioning are advancing the level of autonomous driving applied to automobiles.
[0004] In this environment, many vehicles are equipped with electrified or electronic devices or components driven by electronic control units (ECUs) to perform various functions and services such as driving safety, driver assistance, and autonomous driving.
[0005] Recently, Feature on Demand (FoD) services have been provided as a means to selectively activate or deactivate equipment already installed in a vehicle, or to activate or deactivate installed software functions.
[0006] When using a certificate to apply FoD service to a vehicle, the integrity and authenticity of the contents of the service package delivered by the server can be guaranteed using the certificate's electronic signature.
[0007] However, since the FoD service has a usage period and this usage period is applied based on the time in the vehicle, even after the usage period has expired, an attacker can attempt to illegally use the FoD service by tampering with the vehicle time, etc.
[0008] Additionally, to synchronize the time between two systems, a Network Time Protocol (NTP) server can most commonly be used, but in this case, separate costs may be incurred for setting up an NTP server, or additional burdens may arise from separate communication with an external NTP server for time synchronization.
[0009] The main purpose of the present disclosure is to provide a method and device for preventing time tampering for securing FoD services.
[0010] The problems to be solved by the present invention are not limited to the problems mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art from the description below.
[0011] According to one aspect of the present disclosure, a time tampering prevention device is provided, including: a certificate receiving unit that receives a certificate for an FoD service in a vehicle from a server; a time obtaining unit that obtains a first current time of the vehicle and a clock time related to activation of the FoD service; a time error obtaining unit that obtains a first time error which is a difference between the first current time and the clock time; a time information comparing unit that compares information related to the first time error with previous time error information previously stored in a storage related to the certificate and generates a comparison result; and a service determining unit that determines whether to apply the FoD service based on the comparison result.
[0012] According to another aspect of the present disclosure, a method for preventing time tampering is provided, including: a certificate receiving process for receiving a certificate for an FoD service in a vehicle from a server; a time obtaining process for obtaining a first current time of the vehicle and a clock time related to activation of the FoD service; a time error obtaining process for obtaining a first time error which is a difference between the first current time and the clock time; a time information comparing process for generating a comparison result by comparing information related to the first time error with previous time error information previously stored in a storage related to the certificate; and a service determination process for determining whether to apply the FoD service based on the comparison result.
[0013] According to an embodiment of the present disclosure, there is an effect of preventing illegal use of FoD services.
[0014] Additionally, it can prevent the reuse of certificates by tampering with the time in the vehicle using expired certificates.
[0015] Since the use of an NTP server for time verification can be omitted, there is no need to set up an additional NTP server or communicate with an NTP server.
[0016] The effects of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.
[0017] Figure 1 conceptually illustrates how a vehicle system is connected to a server via a network.
[0018] Figure 2 illustrates the functional blocks that constitute a vehicle connected to an external network.
[0019] Figure 3 illustrates the functional blocks that constitute the gateway (110).
[0020] Figure 4 illustrates the functions performed by the CCU (111).
[0021] Figure 5 illustrates the functional blocks that constitute the server.
[0022] FIG. 6 is a block diagram illustrating a time tamper prevention device (600) according to one embodiment of the present disclosure.
[0023] FIG. 7 is a flowchart illustrating a time tamper prevention method according to one embodiment of the present disclosure.
[0024] Figure 8 is a flowchart illustrating a time information comparison method.
[0025] FIG. 9 is a block diagram schematically illustrating an exemplary computing device that may be used to implement a method or device according to the present disclosure.
[0026] Hereinafter, some embodiments of the present disclosure will be described in detail using exemplary drawings. When designating components in each drawing, it should be noted that, where possible, identical components are given the same reference numerals, even if they appear in different drawings. Furthermore, when describing the present disclosure, detailed descriptions of related known structures or functions will be omitted if they are deemed to obscure the gist of the present disclosure.
[0027] In describing components of embodiments according to the present disclosure, symbols such as first, second, i), ii), a), b) may be used. These symbols are only for distinguishing the components from other components, and the nature, order, or sequence of the components are not limited by the symbols. When a part in the specification is said to "include" or "have" a component, this does not mean that other components are excluded, but rather that other components may be included, unless explicitly stated otherwise.
[0028] The detailed description set forth below, together with the accompanying drawings, is intended to explain exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the present disclosure may be practiced.
[0029] Figure 1 conceptually illustrates how a vehicle system is connected to a server via a network.
[0030] The vehicle system (100) can be connected to a server (200) that provides vehicle-related functions or services through a wireless network (300) such as LTE, 5G, or Wi-Fi.
[0031] Figure 2 illustrates the functional blocks that constitute a vehicle connected to an external network.
[0032] A vehicle system (100) may be configured to include a gateway (110) connected to an external network and an internal network, and subsystems connected to the internal network. The subsystems may include, for example, a powertrain subsystem (120), a body subsystem (130), a chassis subsystem (140), an infotainment subsystem (150), etc.
[0033] Each subsystem (120, 130, 140, 150) includes one or more electrical components with similar functions connected by the same type of internal bus, and each electrical component can be controlled and driven by a corresponding ECU.
[0034] The powertrain subsystem (120) is a collection of components that generate the driving force of a vehicle, and may include components such as an engine, motor, transmission, battery, generator, etc., and an ECU (121, 122, 123) for controlling each component.
[0035] The body subsystem (130) is a collection of components for enhancing the convenience and safety of passengers, and may include components such as seats, heating / ventilation / air conditioning (HVAC), lighting, doors, windows, indoor / outdoor lighting, and an ECU (131, 132, 133) for controlling each component.
[0036] The chassis subsystem (140) is a set of parts required for driving a vehicle excluding the body, and may include parts related to steering, brakes, suspension, tire pressure measurement, etc., and an ECU (141, 142, 143) for controlling each part.
[0037] The infotainment subsystem (150) is a collection of components related to driving guidance or multimedia, and may include components such as a navigation system, a multimedia system, a head-up display, and an ECU (151, 152, 153) for controlling each component.
[0038] The internal network connecting the gateway (110) and the electrical components that constitute the subsystem can use communication protocols such as LIN (Local Interconnect Network), CAN (Control Area Network), CAN-FD, FlexRay, MOST (Media Oriented Systems Transport), and Ethernet.
[0039] Electrical components of different subsystems using different communication protocols can exchange data with each other through the gateway (110).
[0040] Figure 3 illustrates the functional blocks that constitute the gateway (110).
[0041] The gateway (110) may be configured to include a central control unit (111, CCU (Central Control Unit)), a storage unit (113, Storage), an external communication unit (115), and an internal communication unit (117).
[0042] The central control unit (111) has the function of controlling the overall operation of the vehicle system (100).
[0043] The storage unit (113) stores data received from an external network or an internal network and data or information related to the operation of the vehicle system (100).
[0044] The external communication unit (115) functions to connect to the server (200) via an external network.
[0045] The internal communication unit (117) functions to connect to the electrical components (ECU) of each subsystem (120, 130, 140, 150) through the internal network.
[0046] The central control unit (111), internal communication unit (117) and separate storage unit may be configured as separate devices separated from the gateway (110).
[0047] Figure 4 illustrates the functions performed by the CCU (111).
[0048] The central control unit (111) can control various operations of the vehicle system (100) by controlling the ECU of at least one electric component included in at least one subsystem (120, 130, 140, 150) according to a request from a passenger, a need due to a driving situation, etc.
[0049] The functions performed by the central control unit (111), particularly those performed based on data transmitted through an external network and / or an internal network, may include functions such as driving / parking management, remote diagnosis / control, subscription service (FoD) management, software update, and security management.
[0050] The driving / parking management function (411) comprehensively controls the vehicle's speed, steering, braking, and sensor data when driving and parking the vehicle, thereby improving safety and convenience.
[0051] The remote diagnosis / control function (412) transmits status information collected while the vehicle is in operation to the server (200) to enable real-time diagnosis, and changes the control conditions of the vehicle or supports remote control in an emergency situation based on the diagnosis results received from the server (200).
[0052] The subscription service (FoD) management function (413) manages FoD (Feature On Demand), a type of subscription service, which enables new features to be downloaded and activated through the server (200) or the customer's terminal, or features that are already installed but deactivated to be activated and used.
[0053] The central control unit (111) performs the setting or cancellation operation of the subscription service, and checks whether the service requested by the customer is a service activated by the customer by selecting a subscription or whether the activation of the driving service is by an illegal method, and may perform or not perform the service based on this.
[0054] The software update function (414) is a service that the central control unit (111) performs on its own when a software update condition is satisfied in a vehicle system (100) to which OTA is applied, and may include not only the update of the software (operation system of the central control unit (111)) that manages the operation of the entire vehicle system (100) but also the update of the firmware installed in the ECU of each electrical component.
[0055] The security management function (415) may include functions or services related to the security of the vehicle system (100) or authentication of a connecting external device.
[0056] Security threats related to the vehicle system (100) may include firmware tampering, vehicle remote control hacking, CAN tampering, vehicle illegal operation, and denial of service. Additionally, security threats related to external network communications may include communication eavesdropping and message tampering.
[0057] The security management function (415) can perform, for example, a function to detect and respond to intrusions into the vehicle's internal network through an external network (IDS: Intrusion Detection System), a service to record data related to security events (data immediately before a security accident) (EDR: Event Data Recorder), etc.
[0058] Figure 5 illustrates the functional blocks that constitute the server.
[0059] The server (200) may be configured to include a management unit (210, Manager), a database (220, Database), a storage unit (230, Storage), and a communication unit (240).
[0060] The management unit (210) performs a function of managing operations according to a request of the vehicle system (100), such as software update, data transmission related to FoD, vehicle security / authentication, etc.
[0061] The database (220) manages information related to each vehicle, such as the software version installed in each vehicle, activated subscription services, and authentication-related information.
[0062] The storage unit (230) stores multiple versions of software, data related to driving of multiple vehicles, etc.
[0063] The communication unit (240) performs a function for exchanging data by connecting to the vehicle system (100) through an external network.
[0064] The server (200) may be composed of multiple different systems, each of which is divided according to the function or service performed by the central control unit (111) of the vehicle system (100).
[0065] The database (220) may be installed separately from the server (200).
[0066] FIG. 6 is a block diagram illustrating a time tamper prevention device (600) according to one embodiment of the present disclosure.
[0067] A time tampering prevention device (600) according to one embodiment of the present disclosure includes a certificate receiving unit (610), a user verifying unit (620), a validity verifying unit (630), a time obtaining unit (640), a time difference obtaining unit (650), a time information comparing unit (660), a certificate information recording unit (670), and a service deciding unit (680). Not all blocks illustrated in FIG. 6 are essential components, and some blocks included in the time tampering prevention device (600) may be added, changed, or deleted in other embodiments. Meanwhile, the components illustrated in FIG. 6 represent functionally distinct elements, and at least one of the components may be implemented in a form in which they are integrated with each other in an actual physical environment.
[0068] The certificate receiving unit (610) receives a certificate for the FoD service in the vehicle from the server (200).
[0069] The certificate receiving unit (610) can be implemented as a function of the central control unit (111).
[0070] The certificate includes user identification information for a user of at least one subscribed FoD service, identification information for at least one subscribed FoD service, information on whether each subscribed FoD service is activated, the creation time of the certificate, the period of use of the certificate, and electronic signature information.
[0071] Information regarding the activation status of each subscribed FoD service may indicate whether the FoD service is activated or deactivated. Additionally, the certificate's usage period may be the same as the FoD service's validity period, and the usage period may include at least one of the certificate's start time and expiration time.
[0072] The user verification unit (620) verifies the user of the subscribed FoD service using user identification information.
[0073] The user verification unit (620) verifies the user of the FoD service by checking whether the user identification information stored in the storage is identical to the user identification information included in the certificate.
[0074] The user verification unit (620) may be implemented as a function of the central control unit (111), but depending on the embodiment, it may also be implemented as a function of one target ECU (e.g., the corresponding ECU (151) within the infotainment subsystem (150)) related to the FoD service associated with the received certificate.
[0075] In the following description, it is assumed that one target ECU corresponding to a specific FoD service related to a certificate received from a server (200) is an ECU (151) within an infotainment subsystem (150).
[0076] The validation unit (630) verifies the validity of the certificate using the electronic signature information in the received certificate.
[0077] The validation unit (630) verifies the validity of the electronic signature of the certificate using a public key stored in a storage (not shown). Here, the public key may be stored in the storage (not shown) or transmitted from the server (200). In addition, the storage (not shown) may be included in the target ECU (151) or the gateway (110).
[0078] The functions of the time acquisition unit (640), time error acquisition unit (650), time information comparison unit (660), certificate information recording unit (670), and service determination unit (680) described below may be implemented within the corresponding ECU (151), but the present invention is not limited thereto, and at least one of these functions may be implemented within the gateway (110) or other various devices.
[0079] The time acquisition unit (640) acquires the first current time of the vehicle and acquires the clock time related to the activation of the FoD service.
[0080] The time acquisition unit (640) acquires the first current time from a gateway (110) related to multiple controllers in the vehicle, and acquires it from the corresponding controller (151) that determines activation or deactivation of the FoD service corresponding to the certificate.
[0081] The first current time may be information indicating the year, month, day, hour, minute, and second of the current point in time, and may be time information converted to epoch time (EPM: Epoch Time-based Parameter).
[0082] Additionally, the clock time can be obtained from the RTC (real time clock) in the controller (151), and the data form of the clock time can be in the form of a clock counter.
[0083] In this embodiment, the data type of the first current time and the data type of the clock time are not limited to specific data types, and the two can be data types that are comparable to each other.
[0084] The time error acquisition unit (650) acquires a first time error, which is the difference between the first current time and the clock time.
[0085] Here, the first time error can be a value obtained by subtracting the clock time from the first current time, a value obtained by subtracting the first current time from the clock time, or an absolute value of the difference between the first current time and the clock time.
[0086] The time information comparison unit (660) compares information related to the first time error with previous time error information stored in a storage (not shown) related to the certificate to generate a comparison result.
[0087] If previously stored time error information related to the certificate does not exist in the storage (not shown), the certificate information recorder (670) stores information about the first time error as previous time error information related to the certificate in the storage (not shown).
[0088] The time information comparison unit (660) generates a first unique code for the first time error, and determines the generated first unique code as information related to the first time error (i.e., first time error related information).
[0089] The time information comparison unit (660) compares the determined first time error related information with the previous time error information stored in a storage (not shown) to generate a comparison result.
[0090] The time information comparison unit (660) generates a first unique code related to the first time error using a unique code generation key stored in a storage (not shown).
[0091] The first unique code may be a MAC (Message Authentication Code), which is a message authentication code generated using a unique code generation key and has a cryptographic hash value that ensures that specific data has not been tampered with.
[0092] Methods for implementing MAC include CMAC (Cipher-based Message Authentication Code), HMAC (Hash-based Message Authentication Code), and GMAC (Galois Message Authentication Code).
[0093] If the first unique code related to the first time error is implemented to be generated as information about the first time error, the previous time error information is stored in the form of a unique code in the storage (not shown).
[0094] The time information comparison unit (660) checks whether, among the plurality of first unique codes sequentially generated for the plurality of error values, there is one that matches the previous time error information stored in the storage (not shown).
[0095] The time information comparison unit (660) sequentially generates a first unique code for a plurality of error values within a certain range based on the first time error and determines the generated first unique code as information on the first time error. The time information comparison unit (660) compares the information on the first time error generated in this way with previous time error information.
[0096] The time information comparison unit (660) sequentially generates a first unique code for a plurality of error values (i.e., generates information on the first time error) and compares the information on the first time error with the previous time error information. When information on the first time error that matches the previous time error information is generated, the generation of information on the first time error for any more error values among the plurality of error values is stopped and the comparison result is determined to be normal.
[0097] The service judgment unit (680) determines whether to apply the FoD service included in the certificate based on the comparison result.
[0098] When the time information comparison unit (660) sequentially generates a first unique code for a plurality of error values within a certain range, and compares each generated first unique code with the previous time error information, if no matching comparison result is generated, i.e., if the comparison result is determined to be abnormal for the certificate, the service judgment unit (680) determines that the certificate has been used illegally and terminates the process.
[0099] If the comparison result of the time information comparison unit (660) means that the first time error information and the previously stored time error information are identical, the service judgment unit (680) activates or deactivates the corresponding FoD service according to the activation information for the FoD service in the certificate.
[0100] If the comparison result is determined to be normal by the time information comparison unit (660), the service judgment unit (680) obtains the identification information of the FoD service, information on whether the FoD service is activated, and the validity period from the certificate. At this time, the service judgment unit (680) determines whether to activate or deactivate the corresponding FoD service based on the validity period and the information on whether the corresponding FoD service is activated.
[0101] The service judgment unit (680) determines that the corresponding FoD service has ended if the first current time has passed the validity period even if the comparison result of the time information comparison unit (660) is normal.
[0102] If the comparison result of the time information comparison unit (660) is normal and the first current time has not expired, the service judgment unit (680) determines whether to activate or deactivate the FoD service based on information regarding whether the FoD service is activated. The information regarding whether the FoD service is activated may be information indicating the activation of the FoD service or information indicating the deactivation of the FoD service.
[0103] The certificate information recorder (670) updates the information on the first time error as previous time error information related to the certificate based on the comparison result of the time information comparison unit (660) and stores the updated information in a storage (not shown). Here, the information on the first time error updated in the storage (not shown) means that the first time error has been converted into a first unique code.
[0104] That is, if the comparison result of the time information comparison unit (660) is normal, the certificate information recording unit (670) updates the first unique code corresponding to the first time error as the previous time error information related to the certificate, replacing the previous time error information already stored in the storage (not shown).
[0105] FIG. 7 is a flowchart illustrating a time tamper prevention method according to one embodiment of the present disclosure.
[0106] A time tamper prevention method according to one embodiment of the present disclosure is performed by a time tamper prevention device (600).
[0107] The certificate receiving unit (610) receives a certificate for a FoD service in a vehicle from the server (200), the user verification unit (620) verifies the user of the subscribed FoD service using user identification information, and the validity verification unit (630) verifies the validity of the certificate using the electronic signature information in the received certificate (S710).
[0108] For reference, the process of the validation unit (630) verifying the validity of the certificate using the electronic signature information in the received certificate may not be performed in S710, but may be performed in the S770 process described later.
[0109] The time acquisition unit (640) acquires the first current time (GWT, Gateway Time) of the vehicle and acquires the clock time (RTC_ECU) related to the activation of the FoD service (S720).
[0110] The time error acquisition unit (650) acquires the first time error (DT, Delta (Time Difference)), which is the difference between the first current time and the clock time (S730).
[0111] The time information comparison unit (660) compares the information on the first time error with the previous time error information (MDM', MAC Delta in Minute') previously stored in the storage (701) in relation to the certificate, and generates a comparison result (S740).
[0112] Figure 8 is a drawing illustrating in detail the time information comparison process (S740) by the time information comparison unit (660).
[0113] The time information comparison unit (660) converts the first time error (DT) into a comparison time unit (S810). That is, in the S810 process, DT is divided by TW (Time Window) through the DM=round(DT / TW) operation, and then the decimal point is discarded from the divided value to obtain a time unit conversion value (DM, Delta in Minute). Here, DT means time in seconds, and TW is a coefficient for indicating the comparison time unit compared to the time unit of DT. When DT is in seconds, TW can have a value of 60 corresponding to a minute unit, or a value of 3600 corresponding to a time unit, for example.
[0114] The time information comparison unit (660) assigns a preset value TWS (Time Window Size) to variable i (S820).
[0115] Here, TWS is a value representing the preset error range for the first time error.
[0116] The time information comparison unit (660) obtains the previous unique code (MDM') stored in the storage (701) in relation to the certificate (or in relation to the corresponding FoD service) (S830).
[0117] The time information comparison unit (660) adds the DM value to the value obtained by multiplying the variable i by TWS and stores it as DMi (S840).
[0118] The time information comparison unit (660) stores the first unique code for DMi as MDMi (S850). The first unique code MDMi for DMi is also generated using the same unique code generation key (K) as that used to generate the previous unique code (MDM').
[0119] The time information comparison unit (660) compares whether MDMi and MDM' are identical (S860). If this comparison results in MDMi and MDM' being identical, the time error verification by the time information comparison unit (660) is deemed successful.
[0120] If the time error verification by the time information comparison unit (660) is successful (i.e., if the comparison result is determined to be normal by the time information comparison unit (660), the certificate information recording unit (670) updates the information on the first time error as previous time error information related to the certificate and stores it in the storage (701) (S760). Here, the information on the first time error updated in the storage (not shown) means that the first time error has been converted into a first unique code.
[0121] The validation unit (630) verifies the validity of the certificate using the electronic signature information within the received certificate (S770). If the verification at step S770 fails, the process ends.
[0122] If the verification at step S770 is successful, the service judgment unit (680) extracts data including the identification information of the FoD service, information on whether the FoD service is activated, and the validity period from the received certificate (S780).
[0123] At this time, the service judgment unit (680) determines whether to activate or deactivate the corresponding FoD service based on the information on the validity period and whether the corresponding FoD service is activated (S790).
[0124] At step S790, the service judgment unit (680) determines that the corresponding FoD service has ended if the first current time has passed the validity period even if the comparison result of the time information comparison unit (660) is normal.
[0125] The service judgment unit (680) determines whether to activate or deactivate the FoD service based on information on whether the FoD service is activated, if the comparison result of the time information comparison unit (660) is normal and the first current time has not passed the validity period.
[0126] If, in step S860, the comparison result MDMi and MDM' are not the same, the time information comparison unit (660) checks whether the i value is the same as TWS (S870).
[0127] If, as a result of the verification at step S870, the i value is equal to TWS, all comparisons have been made for the preset error range for the first time error, and therefore the time information comparison unit (660) outputs a result of verification failure. In other words, the comparison result by the time information comparison unit (660) is determined to be abnormal.
[0128] As a result of the verification at step S870, if the i value is not equal to TWS, the time information comparison unit (660) increases the i value by 1 (S880) and proceeds to step S840 again.
[0129] FIG. 9 is a block diagram schematically illustrating an exemplary computing device that may be used to implement a method or device according to the present disclosure.
[0130] The computing device (9) may include some or all of a memory (900), a processor (920), storage (940), an input / output interface (960), and a communication interface (980). The computing device (9) may be a stationary computing device such as a desktop computer, a server, etc., as well as a mobile computing device such as a laptop computer, a smart phone, an automotive electronics unit, etc. The computing device (9) may be implemented with any specialized hardware accelerator capable of efficiently processing operations for an artificial intelligence model. For example, the computing device (9) may include a graphic processing unit (GPU), a tensor processing unit (TPU), or a neural processing unit (NPU).
[0131] The memory (900) may store a program that causes the processor (920) to perform a method or operation according to various embodiments of the present disclosure. For example, the program may include a plurality of instructions executable by the processor (920), and the methods illustrated in FIGS. 7 and 8 may be performed by executing the plurality of instructions by the processor (920). The memory (900) may be a single memory or a plurality of memories. In this case, information required to perform the method or operation according to various embodiments of the present disclosure may be stored in a single memory or may be divided and stored in a plurality of memories. When the memory (900) is composed of a plurality of memories, the plurality of memories may be physically separated. The memory (900) may include at least one of a volatile memory and a nonvolatile memory. The volatile memory includes a static random access memory (SRAM) or a dynamic random access memory (DRAM), and the nonvolatile memory includes a flash memory.
[0132] The processor (920) may include at least one core capable of executing at least one instruction. The processor (920) may execute instructions stored in the memory (900). The processor (920) may be a single processor or multiple processors.
[0133] Storage (940) maintains stored data even when power supplied to the computing device (9) is cut off. For example, storage (940) may include non-volatile memory, or may include storage media such as magnetic tape, optical disk, or magnetic disk. A program stored in storage (940) may be loaded into memory (900) before being executed by processor (920). Storage (940) may store a file written in a programming language, and a program generated from the file by a compiler or the like may be loaded into memory (900). Storage (940) may store data to be processed by processor (920) and / or data processed by processor (920).
[0134] The input / output interface (960) may include input devices such as a keyboard, mouse, touch display, microphone, etc., and may include output devices such as a display, speaker, etc. A user may trigger execution of a program by the processor (920) and / or check the processing result of the processor (920) through the input / output interface (960).
[0135] The communication interface (980) may provide access to an external network. The computing device (9) may communicate with other devices via the communication interface (980).
[0136] Each component of the device or method according to the present invention may be implemented in hardware, software, or a combination of hardware and software. Furthermore, the functions of each component may be implemented in software, with a microprocessor executing the software functions corresponding to each component.
[0137] Various implementations of the systems and techniques described herein may be implemented as digital electronic circuits, integrated circuits, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations of one or more computer programs executable on a programmable system. The programmable system includes at least one programmable processor (which may be a special purpose processor or a general purpose processor) coupled to receive data and instructions from and transmit data and instructions to a storage system, at least one input device, and at least one output device. Computer programs (also known as programs, software, software applications, or code) include instructions for the programmable processor and are stored on a "computer-readable recording medium."
[0138] A computer-readable recording medium includes any type of recording device that stores data that can be read by a computer system. Such a computer-readable recording medium may be a non-volatile or non-transitory medium such as a ROM, CD-ROM, magnetic tape, floppy disk, memory card, hard disk, magneto-optical disk, storage device, and may further include a transitory medium such as a data transmission medium. Furthermore, the computer-readable recording medium may be distributed across network-connected computer systems, so that computer-readable code can be stored and executed in a distributed manner.
[0139] Although the flowchart / timing diagram of this specification describes each process as being executed sequentially, this is merely an illustrative description of the technical idea of one embodiment of the present disclosure. In other words, a person of ordinary skill in the art to which one embodiment of the present disclosure belongs may modify and apply various modifications and variations by changing the order described in the flowchart / timing diagram without departing from the essential characteristics of one embodiment of the present disclosure, or by executing one or more of the processes in parallel. Therefore, the flowchart / timing diagram is not limited to a chronological order.
[0140] The above description is merely an example of the technical idea of the present embodiment, and those skilled in the art will appreciate that various modifications and variations can be made without departing from the essential characteristics of the present embodiment. Therefore, the present embodiments are not intended to limit the technical idea of the present embodiment, but rather to explain it, and the scope of the technical idea of the present embodiment is not limited by these embodiments. The scope of protection of the present embodiment should be interpreted by the claims below, and all technical ideas within a scope equivalent thereto should be interpreted as being included in the scope of rights of the present embodiment.
[0141] [Explanation of symbols]
[0142] 100: Vehicle system 110: Gateway
[0143] 111: CCU 113: Storage Unit
[0144] 115: External Communications Department 117: Internal Communications Department
[0145] 120: Powertrain subsystem 130: Body subsystem
[0146] 140: Chassis subsystem 150: Infotainment subsystem
[0147] 200: Server 210: Administration
[0148] 220: Database 230: Storage
[0149] 240: Communications Department 300: Wireless Network
[0150] 411: Driving / Parking Management 412: Remote Diagnosis / Control
[0151] 413: Subscription Services (FoD) Management 414: Software Renewal
[0152] 415: Security Management 600: Time Tamper Protection Device
[0153] 610: Certificate receiving unit 620: User verification unit
[0154] 630: Validation Unit 640: Time Acquisition Unit
[0155] 650: Time error acquisition unit 660: Time information comparison unit
[0156] 670: Certificate Information Record 680: Service Decision Record
[0157] 701: Storage
[0158] 9: Computing device 900: Memory
[0159] 920: Processor 940: Storage
[0160] 960: Input / Output Interface 980: Communication Interface
[0161]
[0162] CROSS-REFERENCE TO RELATED APPLICATION
[0163] This patent application claims priority to Korean Patent Application No. 10-2024-0029244, filed on February 28, 2024, which is incorporated herein by reference in its entirety.
Claims
1. A certificate receiving unit that receives a certificate for a FoD service within a vehicle from a server; A time acquisition unit that acquires the first current time of the vehicle and acquires a clock time related to activation of the FoD service; A time error acquisition unit that acquires a first time error, which is the difference between the first current time and the clock time; A time information comparison unit that compares information related to the first time error with information previously stored in a storage in relation to the certificate to generate a comparison result; and A service judgment unit that determines whether to apply the FoD service based on the above comparison results. A time tamper prevention device including:
2. In paragraph 1, The above time acquisition part is, A time tamper prevention device characterized in that it obtains the first current time from a gateway associated with a plurality of controllers within the vehicle and obtains it from a controller that determines activation or deactivation of the FoD service.
3. In paragraph 1, A time tampering prevention device characterized in that it further includes a certificate information recording unit that stores information about the first time error in the storage as previous time error information related to the certificate when there is no previously stored previous time error information related to the certificate.
4. In paragraph 3, The above certificate information record section is: A time tamper prevention device characterized in that, based on the comparison result, information about the first time error is updated as previous time error information related to the certificate and stored in the storage.
5. In paragraph 3, The above certificate information record section is: A time tamper prevention device characterized in that the first unique code for the first time error is stored in the storage as previous time error information related to the certificate.
6. In paragraph 3, The above time information comparison section is, A time tamper prevention device characterized in that it generates a first unique code related to the first time error as information on the first time error, and compares the information on the first time error and the previously stored time error information to generate the comparison result.
7. In paragraph 6, The above time information comparison section is, A time tamper prevention device characterized in that the first unique code is generated using a unique code generation key stored in the above storage.
8. In paragraph 6, The above time information comparison section is, A time tamper prevention device characterized in that it sequentially generates the first unique code for a plurality of error values within a preset error range based on the first time error.
9. In paragraph 8, The above time information comparison section is, A time tamper prevention device characterized in that it is checked whether there is one among the plurality of first unique codes sequentially generated for the plurality of error values that matches the previously stored time error information.
10. In paragraph 1, The above service judgment department, A time tamper prevention device characterized in that, based on the comparison result, identification information of the FoD service, information on whether the FoD service is activated, and a validity period are obtained from the certificate, and activation or deactivation of the FoD service is determined based on the validity period and the information on whether the FoD service is activated.
11. In paragraph 1, The above service judgment department, A time tamper prevention device characterized in that, if the comparison result means that the first time error information and the previously stored time error information are identical to each other, the FoD service is activated or deactivated according to the information on whether the FOD service is activated in the certificate.
12. Certificate receiving process for receiving a certificate for FoD service in the vehicle from the server; A time acquisition process for acquiring the first current time of the vehicle and acquiring a clock time related to activation of the FoD service; A time error acquisition process for acquiring a first time error, which is the difference between the first current time and the clock time; A time information comparison process for generating a comparison result by comparing information related to the first time error with information previously stored in a storage related to the certificate; and A service judgment process that determines whether to apply the FoD service based on the above comparison results. A method for preventing time tampering, including:
13. In paragraph 12, The above time acquisition process is, A time tamper prevention method characterized in that the first current time is obtained from a gateway associated with a plurality of controllers within the vehicle, and is obtained from a controller that determines activation or deactivation of the FoD service.
14. In paragraph 12, A time tampering prevention method characterized by further including a certificate information recording process for storing information about the first time error in the storage as previous time error information related to the certificate when there is no previously stored previous time error information related to the certificate.
15. In paragraph 14, The above certificate information recording process is: A time tampering prevention method characterized in that, based on the comparison result, information about the first time error is updated as previous time error information related to the certificate and stored in the storage.
16. In paragraph 13, The above time information comparison process is: A time tampering prevention method characterized in that a first unique code related to the first time error is generated as information on the first time error, and the information on the first time error and the previously stored time error information are compared with each other to generate the comparison result.
17. In paragraph 16, The above time information comparison process is: A time modulation prevention method characterized in that the first unique code is sequentially generated for a plurality of error values within a preset error range based on the first time error.
18. In paragraph 17, The above time information comparison process is: A time tampering prevention method characterized by checking whether, among the plurality of first unique codes sequentially generated for the plurality of error values, there is one that matches the previously stored time error information.
19. In paragraph 12, The above service judgment process is: A time tamper prevention method characterized in that, based on the comparison result, identification information of the FoD service, information on whether the FoD service is activated, and a validity period are obtained from the certificate, and activation or deactivation of the FoD service is determined based on the validity period and the information on whether the FoD service is activated.
20. In paragraph 12, The above service judgment process is: A time tamper prevention method characterized in that, if the comparison result means that the first time error information and the previously stored time error information are identical to each other, the FoD service is activated or deactivated according to the activation information for the FOD service in the certificate.
Citation Information
Patent Citations
Global automobile safety system
JP2015136107A
V2x communication apparatus for verifying reliability of v2x data, system having the same and method thereof
KR1020180042034A
Illumination device
KR1020200091375A
Metadata management system
KR102498062B1
Method for detecting cellular senescence biomarkers using primers from isolated cells
KR102657188B1