Method and apparatus for providing fod service by using certificate

A certificate-based system secures FoD services in vehicles by electronically signing and encrypting certificates, addressing cyberattack vulnerabilities and ensuring secure authentication and data integrity.

WO2025220887A1PCT designated stage Publication Date: 2025-10-23HYUNDAI MOTOR CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/003514
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-16
Filing Date
2025-03-18
Publication Date
2025-10-23

AI Technical Summary

Technical Problem

FoD services in vehicles are vulnerable to cyberattacks, allowing attackers to exploit subscription services without authorization, necessitating enhanced cybersecurity measures.

Method used

A certificate-based system where a certificate root server electronically signs and encrypts certificates, which are verified by an electronic control device using a public key infrastructure (PKI) to ensure authenticity and integrity, preventing unauthorized access and data theft.

Benefits of technology

Prevents attackers from hijacking FoD functions and ensures confidentiality, integrity, and two-way authentication, thereby securing the FoD service.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025003514_23102025_PF_FP_ABST
    Figure KR2025003514_23102025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a method and apparatus for providing a feature on demand (FoD) service by using a certificate. According to an embodiment of the present disclosure, the method performed by an electronic control unit may comprise the operations of: receiving an FoD certificate from a certificate root server, by using a certificate distribution server and a gateway, and verifying a digital signature of the FoD certificate; when the digital signature of the FoD certificate has been verified, verifying fields of the FoD certificate other than the digital signature; when the fields of the FoD certificate other than the digital signature have been verified, re-verifying the digital signature of the FoD certificate and storing the FoD certificate; and applying a digital signature to a challenge of the FoD certificate, and transmitting the FoD certificate to the certificate root server by using the gateway and the certificate distribution server.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for providing FOD service using certificate

[0001] The present invention relates to a method and device for providing a Feature of Demand (FoD) service using a certificate. More specifically, the present invention relates to a method and device for providing a FoD service by verifying an electronically signed certificate.

[0002] The content described below merely provides background information related to the present embodiment and does not constitute prior art.

[0003] FoD (Feature on Demand) is a subscription-based service that allows vehicle users to selectively download and install required features. FoD allows users to download and install features online or offline through a vehicle-connected system.

[0004] Previously, when purchasing a vehicle, the customer would select the features they would like to use and pre-install them in the vehicle before delivery. However, with the FoD service, customers can selectively purchase and add the features they want even after delivery.

[0005] For example, vehicle users can purchase specific features such as Adaptive Cruise Control (ACC), Autonomous Emergency Braking (AEB), Lane Support System (LSS), Around View Monitor (AVM), and Parking Assist System (PAS) from the manufacturer and then download and install those features remotely, regardless of time and location.

[0006] However, FoD services require users to communicate with the FoD server via their smartphone or vehicle's infotainment system when subscribing, and this process can expose users to various cyberattacks. For example, attackers could sniff or steal data transmitted and received between the vehicle and the FoD server, allowing them to use the feature in their own vehicle without paying the subscription fee. To ensure the safety of subscription services from these various cyberattacks, the application of cybersecurity technology is essential.

[0007] The purpose of this disclosure is to enable a certificate root server to electronically sign and encrypt a certificate and transmit it to an electronic control device.

[0008] Additionally, according to one embodiment, the electronic control unit is intended to verify a certificate and activate a Feature of Demand (FoD) function.

[0009] The problems to be solved by the present invention are not limited to the problems mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art from the description below.

[0010] According to the present disclosure, a method performed by a certificate root server may include, when receiving FoD (Feature of Demand) certificate issuance request information from a certificate distribution server, a process of issuing a FoD certificate using the FoD certificate issuance request information, a process of applying an electronic signature to the FoD certificate and encrypting the FoD certificate, a process of transmitting the FoD certificate to the certificate distribution server, and, when the electronic control device verifies the FoD certificate and applies an electronic signature to a challenge of the FoD certificate, a process of receiving the FoD certificate from the electronic control device using a gateway and the certificate distribution server and verifying an electronic signature of a challenge of the FoD certificate.

[0011] According to the present disclosure, a method performed by an electronic control device may include a process of receiving a FoD certificate from a certificate root server using a gateway and a certificate distribution server, verifying an electronic signature of the FoD certificate, if the electronic signature of the FoD certificate is verified, verifying fields of the FoD certificate excluding the electronic signature, if the fields of the FoD certificate excluding the electronic signature are verified, re-verifying the electronic signature of the FoD certificate and storing the FoD certificate, and applying an electronic signature to a challenge of the FoD certificate and transmitting the FoD certificate to the certificate root server using the gateway and the certificate distribution server.

[0012] According to the present disclosure, a method performed by an electronic control device may include a process of loading a FoD certificate when the vehicle is turned on, a process of verifying an electronic signature of the FoD certificate, a process of verifying fields excluding the electronic signature of the FoD certificate when the electronic signature of the FoD certificate is verified, and a process of activating a FoD function when fields excluding the electronic signature of the FoD certificate are verified.

[0013] According to the present disclosure, an electronic control device includes a memory and a plurality of processors, and at least one processor among the plurality of processors can receive a FoD certificate from a certificate root server using a gateway and a certificate distribution server, verify an electronic signature of the FoD certificate, and if the electronic signature of the FoD certificate is verified, verify fields excluding the electronic signature of the FoD certificate, and if fields excluding the electronic signature of the FoD certificate are verified, re-verify the electronic signature of the FoD certificate and store the FoD certificate, apply an electronic signature to a challenge of the FoD certificate, and transmit the FoD certificate to the certificate root server using the gateway and the certificate distribution server.

[0014] According to the present disclosure, there is an effect that can prevent an attacker from hijacking or using the FoD function without authorization.

[0015] Additionally, according to one embodiment, there is an effect that can prevent an attacker from transmitting a certificate containing malicious code to a vehicle.

[0016] Additionally, according to one embodiment, there is an effect that can ensure confidentiality, integrity, and two-way authentication of the certificate.

[0017] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned will be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.

[0018] FIG. 1 is a diagram for explaining a process of using a functional subscription service according to one embodiment of the present disclosure.

[0019] FIG. 2 is a diagram for explaining a certificate-based FoD (Feature of Demand) service ecosystem using a public key structure according to one embodiment of the present disclosure.

[0020] FIG. 3 is a diagram illustrating a vehicle connected to a server via a network according to one embodiment of the present disclosure.

[0021] FIG. 4 is a block diagram illustrating a vehicle connected to an external network according to one embodiment of the present disclosure.

[0022] FIG. 5 is a block diagram illustrating a gateway according to one embodiment of the present disclosure.

[0023] FIG. 6 is a block diagram illustrating a server according to one embodiment of the present disclosure.

[0024] FIG. 7 is a diagram for explaining a process of transmitting and receiving a FoD certificate according to one embodiment of the present disclosure.

[0025] FIG. 8 is a flowchart illustrating a process in which an electronic control device activates a FoD function according to an embodiment of the present disclosure.

[0026] FIG. 9 is a flowchart illustrating a process in which a certificate root server transmits and receives a FoD certificate according to one embodiment of the present disclosure.

[0027] FIG. 10 is a flowchart illustrating a process in which an electronic control device transmits and receives a FoD certificate according to one embodiment of the present disclosure.

[0028] FIG. 11 is a block diagram schematically illustrating an exemplary computing device that can be used to implement a method according to the present disclosure.

[0029] Hereinafter, some embodiments of the present disclosure will be described in detail using exemplary drawings. When designating components in each drawing, it should be noted that, where possible, identical components are given the same reference numerals, even if they appear in different drawings. Furthermore, when describing the present disclosure, detailed descriptions of related known structures or functions will be omitted if they are deemed to obscure the gist of the present disclosure.

[0030] In describing components of embodiments according to the present disclosure, symbols such as first, second, i), ii), a), b) may be used. These symbols are only for distinguishing the components from other components, and the nature, order, or sequence of the components are not limited by the symbols. When a part in the specification is said to "include" or "have" a component, this does not mean that other components are excluded, but rather that other components may be included, unless explicitly stated otherwise.

[0031] The detailed description set forth below, together with the accompanying drawings, is intended to explain exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the present disclosure may be practiced.

[0032] FIG. 1 is a diagram for explaining a process of using a functional subscription service according to one embodiment of the present disclosure.

[0033] Referring to FIG. 1, in the FoD (Feature of Demand) ecosystem, a driver (110) can subscribe to or cancel a necessary feature of a vehicle, and when a feature expires, the feature can no longer be used. If the driver (110) no longer needs the feature, the driver (110) can transfer the feature to another driver. The driver (110) checks a list of features available for subscription in the vehicle (120) and requests a subscription to a new feature using the driver's (110) Personally Identifying Information (PII), the vehicle identification number (VIN) of the vehicle (120), and payment information (1).

[0034] The vehicle (120) transmits subscription request data to the FoD server (130) to check for new functions (2).

[0035] The FoD server (130) verifies the driver's (110) PII, the vehicle identification number (120) and payment information (3).

[0036] The FoD server (130) installs new features into the vehicle (120) using OTA (Over The Air) updates (4).

[0037] The central control unit (CCU) of the vehicle (120) receives installation data for a new function and then verifies the format of the installation data using the Unified Diagnostic Services (UDS) protocol. Here, the UDS protocol is a standard protocol for vehicle diagnosis.

[0038] The central control unit of the vehicle (120) routes installation data to the electronic control device using the ID of the electronic control device (5).

[0039] The electronic control unit activates and operates new functions through this routing (6). For example, the electronic control unit can activate the Lane Support System (LSS) function.

[0040] Assets of a FoD service may include software, cryptographic data, communication data, personal information, and log data. Software is required to operate the FoD service. Cryptographic data includes public keys, private keys, certificates, passwords, seeds, and salts for encryption, decryption, and hash calculation. Communication data may include data between the vehicle, central control unit, electronic control unit, and FoD server for installing features in the vehicle. Personal information may include PII for driver and vehicle identification, vehicle identification number, payment information, and the driver's FoD service subscription list. Log data may include data regarding CCU / ECU status, feature ON / OFF events, and feature subscription timestamps.

[0041] In the FoD ecosystem, various security threats may exist, such as DDoS replay, attacker attacks, and impersonation against the assets of these FoD services.

[0042] For example, an attacker may exploit the payment information of the driver (110) when the driver (110) requests a subscription to a new feature in the vehicle (120). Accordingly, the driver (110) may subscribe to the feature requested by the attacker. The attacker may exploit the vehicle identification number (VIN) when the FoD server (130) installs a new feature in the vehicle (120) to prevent the installation. The attacker may eavesdrop on the feature installation data transmitted by the FoD server (130) to the vehicle (120) and exploit the feature installation data to subscribe to the feature without paying the subscription fee. The attacker may attack the FoD server (130) and the central control unit to manipulate the feature installation data, thereby causing a malfunction of the electronic control unit or triggering a function that the driver (110) does not want. An attacker can disrupt the installation by performing a DDoS attack on the FoD server (130), the central control unit, or the electronic control unit when the FoD server (130) installs a new feature in the vehicle (120).

[0043] There are various methods to prevent security attacks by these attackers.

[0044] The first method encrypts payment information, stores PII and vehicle identification numbers separately from other personal information, and destroys payment information that is no longer needed so that it cannot be recovered.

[0045] The second method is to use an encrypted VIN or a value that replaces the VIN in the FoD service.

[0046] The third method is to encrypt the function installation data using an encryption mechanism that uses a symmetric key or asymmetric key.

[0047] The fourth method is to maintain the integrity of the function installation data by using a digital signature or hash function.

[0048] The fifth method is to defend against DDoS attacks by using firewalls, traffic monitoring, etc.

[0049] FIG. 2 is a diagram for explaining a certificate-based FoD (Feature of Demand) service ecosystem using a public key structure according to one embodiment of the present disclosure.

[0050] Referring to FIG. 2, the integrity and confidentiality of the functional installation data transmitted by the FoD server (210) to the vehicle (220) are guaranteed based on a certificate using a public key infrastructure (PKI). The certificate-based FoD service ecosystem using a public key structure includes two major processes: certificate issuance and certificate use.

[0051] Certificate issuance

[0052] When a driver subscribes to a new feature, the vehicle (220) transmits subscription request data to the FoD server (210). The subscription request data may include information about the feature type, PII, vehicle identification number, and payment. The FoD server (210) receives the subscription request data, stores the feature type, and then transmits the subscription request data to a CA server (Certificate Authority server, 230). The CA server (230) verifies the subscription request data and issues a certificate. The fields of the certificate may include a version, a serial number, a tag, a vehicle identification number, an electronic control unit ID, a function flag, a challenge, an issuer, an order ID, an issuance date, an effective date, an expiration date, a reservation, and a signature.

[0053] The CA server (230) issues a certificate and then signs the certificate based on a digital signature technology using a private key. The CA server (230) encrypts the certificate using a symmetric key-based encryption mechanism. Here, the symmetric key can be safely distributed in advance. The CA server (230) transmits the encrypted data to the FoD server (210). The FoD server (210) searches for the ID of the corresponding electronic control device using the type of the pre-stored function and adds the ID of the corresponding electronic control device to the encrypted data. The FoD server (210) transmits the encrypted data with the ID of the corresponding electronic control device added to the vehicle (220). The central control unit of the vehicle (220) routes the encrypted data to the corresponding electronic control device using the ID of the corresponding electronic control device.

[0054] The electronic control unit may be composed of a host and an HSM (Hardware Security Module). The host receives encrypted data and transmits it to the HSM. The HSM decrypts the encrypted data using a pre-shared symmetric key and verifies the signature using the public key of the CA server (230). The HSM shares the verification result with the host. If the verification result is correct, the general fields such as the vehicle identification number, electronic control unit ID, and function flags are verified to be correct. If all fields are correct, the HSM re-verifies the signature, encrypts both the general fields and the signature using the pre-shared symmetric key, and stores the encrypted data in a storage. The electronic control unit signs the challenge field of the certificate and returns both the field and the signature to the CA server (230). The CA server (230) verifies the signature using the public key of the electronic control unit. Accordingly, mutual authentication between the CA server (230) and the electronic control unit is guaranteed.

[0055] Use of certificates

[0056] When the vehicle (220) is turned on, the central control unit of the vehicle (220) identifies the list of pre-installed functions and the ID of the corresponding electronic control unit. The electronic control unit obtains encrypted data from the storage and verifies the signature in the HSM. The host verifies general fields such as the vehicle identification number, function flag, and expiration date. If the verification result is correct, the electronic control unit activates the function.

[0057] FIG. 3 is a diagram illustrating a vehicle connected to a server via a network according to one embodiment of the present disclosure.

[0058] Referring to FIG. 3, a vehicle (310) may be connected to a server (320) that provides functions or services related to the vehicle (310) through a mobile network or wireless network such as LTE, 5G, or Wi-Fi.

[0059] FIG. 4 is a block diagram illustrating a vehicle connected to an external network according to one embodiment of the present disclosure.

[0060] Referring to FIG. 4, the vehicle (310) includes all or part of a gateway (410) connected to an external network and an internal network, and subsystems connected to the internal network. The vehicle (310) and each of its components may be implemented in hardware or software, or a combination of hardware and software. Furthermore, the functions of each component may be implemented in software, and one or more processors may be implemented to execute the functions of the software corresponding to each component.

[0061] The gateway (410) is a system that controls communication and has the function of safely transmitting data within the vehicle (310). The subsystems may include a power train subsystem, a body subsystem, a chassis subsystem, an infotainment subsystem, etc. A subsystem includes one or more components that perform similar functions and are connected by the same type of internal bus. Each component is controlled and driven by one or more ECUs (420).

[0062] The powertrain subsystem is a collection of components that generate the driving force of the vehicle (310). The powertrain subsystem may include components such as an engine, motor, transmission, battery, and generator. The body subsystem is a collection of components that enhance driver convenience and safety. The body subsystem may include components such as seats, heating / ventilation / air conditioning, lighting, doors, and windows. The chassis subsystem is a collection of components necessary for driving the vehicle (310). The chassis subsystem may include components related to steering, brakes, and tires. The infotainment subsystem is a collection of components related to driving guidance or multimedia of the vehicle (310). The infotainment subsystem may include components such as a navigation system, a multimedia system, and a head-up display.

[0063] The internal network connecting the gateway (410) and the components constituting the subsystems may be a communication protocol such as LIN (Local Interconnect Network), CAN (Control Area Network), CAN-FD, FlexRay, MOST (Media Oriented Systems Transport), Ethernet, etc. The components within the subsystems transmit and receive data to each other through the gateway (410). The gateway (410) may transmit an encrypted vehicle identification number received from the server (320) to one or more ECUs (420). The gateway (410) may transmit vehicle identification number reception confirmation data received from one or more ECUs (420) to the server (320).

[0064] FIG. 5 is a block diagram illustrating a gateway according to one embodiment of the present disclosure.

[0065] Referring to FIG. 5, the gateway (410) may include all or part of a central control unit (510), a communication unit (520), an ECU list storage unit (530), and a storage unit (540). The gateway (410) and each of its components may be implemented in hardware or software, or a combination of hardware and software. In addition, the functions of each component may be implemented in software, and one or more processors may be implemented to execute the functions of the software corresponding to each component.

[0066] The central control unit (510) controls the overall operation of the vehicle (310). The central control unit (510) can control the operation of the vehicle (310) by controlling the electronic control device included in at least one subsystem according to the driver's request, driving conditions, etc. The functions performed by the central control unit (510) may include driving management, parking management, remote diagnosis, remote control, FoD management, software update, and security management. FoD management is a type of subscription service management, such as downloading and activating a new function from a server or activating a deactivated function. The central control unit (510) performs the setup or cancellation of the subscription service. The central control unit (510) can check whether the activated function is a function selected by the customer or whether the activation of the function is due to an illegal method, and can activate or deactivate the function based on the results.

[0067] Software update is a service performed by the central control unit (510) when software update conditions are met in a vehicle to which OTA is applied. Software update may include updating the software that manages the overall operation of the vehicle as well as the firmware installed in the electronic control unit of each component.

[0068] Security management may include functions or services related to vehicle security or the authentication of external devices accessing the in-vehicle network. Security threats related to vehicles may include firmware tampering, remote control hacking, CAN tampering, illegal vehicle operation, and denial of service. Security threats related to external networks may also include communication eavesdropping and message tampering. Security management may include functions for detecting and responding to intrusions into the vehicle's internal network via external networks (Intrusion Detection System (IDS)) and services for recording data related to security events (Event Data Recorder (EDR).

[0069] The communication unit (520) transmits and receives data with the server (320) through an external network, and transmits and receives data with the subsystem components and electronic control devices through an internal network.

[0070] The ECU list storage unit (530) stores a list of ECUs and determines an electronic control device matching the ID of the electronic control device within the list of ECUs.

[0071] The storage unit (540) stores data received from an external network and an internal network or data related to the operation of the vehicle (310).

[0072] FIG. 6 is a block diagram illustrating a server according to one embodiment of the present disclosure.

[0073] Referring to FIG. 6, the server (320) may include all or part of a management unit (610), a communication unit (620), a storage unit (630), and an encryption unit (640). The server (320) and each of its components may be implemented in hardware or software, or a combination of hardware and software. In addition, the functions of each component may be implemented in software, and one or more processors may be implemented to execute the functions of the software corresponding to each component. The server (320) may be a general back-end server capable of communicating with the vehicle (310).

[0074] The management unit (610) manages operations according to the request of the vehicle (310). For example, the management unit (610) can manage operations such as software updates, transmission of data related to FoD, and security / authentication of the vehicle.

[0075] The communication unit (620) connects to the vehicle (310) through an external network and transmits and receives data.

[0076] The storage unit (630) stores data related to driving of the vehicle (310) and manages the version of software installed in each vehicle, activated functions, and authentication-related information.

[0077] The encryption unit (640) manages a symmetric key and a key for electronic signatures, and encrypts the vehicle identification number using the symmetric key. The encryption unit (640) generates data composed of parameters including the encrypted vehicle identification number. The encryption unit (640) verifies the values ​​obtained by electronically signing the parameters, hashes the vehicle identification number, and generates and stores the hashed vehicle identification number.

[0078] FIG. 7 is a diagram for explaining a process of transmitting and receiving a FoD certificate according to one embodiment of the present disclosure.

[0079] Referring to FIG. 7, when a driver applies for a subscription to a FoD function required for a vehicle, the gateway (410) transmits FoD function subscription application information to the certificate distribution server (720) (1). The FoD function subscription application information may include information on the type of FoD function, PII, VIN, payment, etc. Here, the FoD function subscription service may be a term service or a permanent service. The certificate distribution server (720) may be the FoD server (210) of FIG. 2. The certificate distribution server (720) may use the FoD function subscription application information to check the FoD function required for the vehicle. The certificate distribution server (720) transmits FoD certificate issuance request information to the certificate root server (710) (2). The FoD certificate issuance request information may include information on the FoD function required for the vehicle, VIN, PII, payment, etc.

[0080] The certificate root server (710) can issue a FoD certificate based on the FoD function required for the vehicle using the FoD certificate issuance request information. Here, there may be multiple FoD certificates depending on the FoD function. The fields of the FoD certificate may include a version, a serial number, a tag, a VIN, an ECU ID, a feature flag, a challenge, an issuer, an order number, an issuance time, a function start time, a function end time, and a reserve space. The certificate root server (710) may be the CA server (230) of FIG. 2. The certificate root server (710) may apply an electronic signature to the issued FoD certificate and encrypt both the certificate and the electronic signature using a symmetric key. Here, the electronic signature method may be RSA (Rivest-Shamir-Adleman), Elgamal, and ECDSA (Elliptic Curve Digital Signature Algorithm). The encryption method may be AES (Advanced Encryption Standard)-128, AES-192, and AES-256, etc. The certificate root server (710) transmits the FoD certificate to the certificate distribution server (720) (3).

[0081] The certificate distribution server (720) transmits the FoD certificate to the gateway (410) (4). Here, the certificate distribution server (720) can transmit information about the electronic control unit ID related to the FoD function required for the vehicle to the gateway (410) together with the FoD certificate. The certificate distribution server (720) may pre-store information about the electronic control unit ID or may receive it from an external control server, etc. The certificate distribution server (720) and the gateway (410) may wirelessly transmit and receive information based on OTA (Over The Air) or wiredly transmit and receive information based on OBD (On-Board Diagnostic)-II. The gateway (410) can determine the electronic control unit (420) having the corresponding ID using the information about the electronic control unit ID related to the FoD function required for the vehicle. The gateway (410) transmits the FoD certificate to the determined electronic control unit (420) (5).

[0082] The electronic control unit (420) includes a host, an HSM, etc. The host of the electronic control unit (420) receives the FoD certificate and transmits it to the HSM. The HSM decrypts the FoD certificate and verifies the electronic signature of the decrypted certificate. Here, the decryption method may be AES (Advanced Encryption Standard)-128, AES-192, AES-256, etc. The HSM transmits information about the verification result of the electronic signature of the FoD certificate to the host. If the verification result of the electronic signature of the FoD certificate is normal, the host verifies all fields except the electronic signature of the FoD certificate. Here, the host can verify the electronic control unit ID of the FoD certificate by comparing the electronic control unit ID of the FoD certificate with information about the electronic control unit ID related to the FoD function required for the vehicle transmitted by the certificate distribution server (720). The remaining fields except the electronic signature of the FoD certificate can be verified based on information received from an external source.

[0083] The host transmits information about the verification results of the remaining fields except for the electronic signature of the FoD certificate to the HSM. If the verification results of the remaining fields except for the electronic signature of the FoD certificate are normal, the HSM can re-verify the electronic signature of the FoD certificate and encrypt both the FoD certificate and the electronic signature and store them in an internal secure storage. Here, the encrypted FoD certificate at the time of receipt from the certificate distribution server (720) can be stored in the internal secure storage without re-verifying and re-encrypting the electronic signature of the FoD certificate. The electronic control device (420) electronically signs the challenge of the FoD certificate and transmits the FoD certificate to the gateway (410) (6).

[0084] The gateway (410) transmits the FoD certificate to the certificate distribution server (720) (7). The certificate distribution server (720) transmits the FoD certificate to the certificate root server (710) (8). The certificate root server (710) can verify the electronic signature of the received FoD certificate to confirm whether the electronic control device (420) has received the FoD certificate. The electronic control device (420) stores the FoD certificate and then transmits information about its own electronic control device ID to the gateway (410) (9). The gateway (410) can list and store information about the electronic control device ID.

[0085] FIG. 8 is a flowchart illustrating a process in which an electronic control device activates a FoD function according to an embodiment of the present disclosure.

[0086] FIG. 8 shows that when the vehicle is turned on, the electronic control unit (420) loads the FoD certificate stored in the internal secure storage (S810). Here, the electronic control unit (420) may be an electronic control unit of an ECU list based on the FoD function stored in the gateway (410). The host of the electronic control unit (420) may transmit the FoD certificate to the HSM of the electronic control unit (420). The HSM decrypts the FoD certificate and verifies the electronic signature of the FoD certificate (S820). The HSM may transmit information on the verification result of the electronic signature of the FoD certificate to the host.

[0087] If there is no problem in the verification result of the electronic signature of the FoD certificate, the host verifies the remaining fields of the FoD certificate except for the electronic signature (S830). The host can verify the remaining fields of the FoD certificate except for the electronic signature by comparing the information about the remaining fields of the FoD certificate except for the electronic signature with the fields received from an external source. Here, the external source may be a vehicle, a driver's terminal, a certificate distribution server (720), etc. If there is no problem in the verification result of the remaining fields of the FoD certificate except for the electronic signature, the electronic control unit (420) activates the FoD function (S840).

[0088] The host of the electronic control device (420) can compare the function termination time and the current time among the remaining fields except the electronic signature of the FoD certificate. The current time can be received from an external source. If the current time is after the function termination time, the electronic control device (420) can determine that the FoD certificate has expired and can deactivate the FoD function. If the FoD certificate is determined to have expired, the electronic control device (420) can revoke the FoD certificate and transmit FoD certificate revocation request information to the gateway (410). The gateway (410) can transmit the FoD certificate revocation request information to the certificate distribution server (720). The certificate distribution server (720) can transmit the FoD certificate revocation request information to the certificate root server (710). The certificate root server (710) can receive the FoD certificate revocation request information and revoke the FoD certificate.

[0089] FIG. 9 is a flowchart illustrating a process in which a certificate root server transmits and receives a FoD certificate according to one embodiment of the present disclosure.

[0090] Referring to FIG. 9, when the certificate root server (710) receives FoD certificate issuance request information from the certificate distribution server (720), the certificate root server (710) issues a FoD certificate using the FoD certificate issuance request information (S910). The FoD certificate issuance request information may include information on FoD functions required for the vehicle, information on VIN, information on PII, and information on payment. The certificate root server (710) applies an electronic signature to the FoD certificate and encrypts the FoD certificate (S920). The certificate root server (710) transmits the FoD certificate to the certificate distribution server (720) (S930).

[0091] When the electronic control device (420) verifies the FoD certificate and applies an electronic signature to the challenge of the FoD certificate, the certificate root server (710) receives the FoD certificate from the electronic control device (420) using the gateway (410) and the certificate distribution server (720) and verifies the electronic signature of the challenge of the FoD certificate (S940). When the certificate root server (710) receives FoD certificate revocation request information from the electronic control device (420) using the gateway (410) and the certificate distribution server (720), the FoD certificate can be revoked.

[0092] FIG. 10 is a flowchart illustrating a process in which an electronic control device transmits and receives a FoD certificate according to one embodiment of the present disclosure.

[0093] Referring to FIG. 10, the electronic control device (420) receives a FoD certificate from the certificate root server (710) using the gateway (410) and the certificate distribution server (720), and verifies the electronic signature of the FoD certificate (S1010). If the electronic signature of the FoD certificate is verified, the electronic control device (420) verifies the fields excluding the electronic signature of the FoD certificate (S1020). The fields excluding the electronic signature of the FoD certificate can be verified using information about the fields received from an external source. The fields excluding the electronic signature of the FoD certificate can include the version of the FoD certificate, the serial number of the FoD certificate, a tag, a VIN, an electronic control device ID, a feature flag, a challenge, an issuer, an order number, an issuance time, a function start time, a function end time, and a reserve space.

[0094] The electronic control device (420) re-verifies the electronic signature of the FoD certificate and stores the FoD certificate when the fields other than the electronic signature of the FoD certificate are verified (S1030). The electronic control device (420) applies the electronic signature to the challenge of the FoD certificate and transmits the FoD certificate to the certificate root server (710) using the gateway (410) and the certificate distribution server (720) (S1040). The electronic control device (420) can transmit information about the electronic control device ID to the gateway.

[0095] FIG. 11 is a block diagram schematically illustrating an exemplary computing device that can be used to implement a method according to the present disclosure.

[0096] The computing device (1100) may include some or all of a memory (1110), a processor (1120), storage (1140), an input / output interface (1160), and a communication interface (1180). The computing device (1100) may structurally and / or functionally include at least a portion of an electronic control device (420), a certificate root server (710), a gateway (410), and a certificate distribution server (720). The computing device (1100) may be a stationary computing device such as a desktop computer, a server, an AI accelerator, etc., as well as a portable computing device such as a laptop computer, a smart phone, etc.

[0097] The memory (1110) may store a program that causes the processor (1120) to perform a method or operation according to various embodiments of the present disclosure. For example, the program may include a plurality of instructions executable by the processor (1120), and the methods illustrated in FIGS. 8, 9, and 10 may be performed by executing the plurality of instructions by the processor (1120).

[0098] Memory (1110) may be a single memory or multiple memories. In this case, information required to perform methods or operations according to various embodiments of the present disclosure may be stored in a single memory or divided and stored across multiple memories. If memory (1110) is comprised of multiple memories, the multiple memories may be physically separated.

[0099] The memory (1110) may include at least one of volatile memory and non-volatile memory. The volatile memory includes SRAM (Static Random Access Memory) or DRAM (Dynamic Random Access Memory), and the non-volatile memory includes flash memory.

[0100] The processor (1120) may include at least one core capable of executing at least one instruction. The processor (1120) may execute instructions stored in the memory (1110). The processor (1120) may be a single processor or multiple processors.

[0101] Storage (1140) maintains stored data even when power supplied to the computing device (1100) is cut off. For example, storage (1140) may include non-volatile memory or a storage medium such as magnetic tape, optical disk, or magnetic disk.

[0102] A program stored in storage (1140) may be loaded into memory (1110) before being executed by processor (1120). Storage (1140) may store a file written in a programming language, and a program generated from the file by a compiler or the like may be loaded into memory (1110). Storage (1140) may store data to be processed by processor (1120) and / or data processed by processor (1120).

[0103] The input / output interface (1160) may include an input device such as a keyboard, a mouse, etc., and a display device such as a display device, a printer, etc. A user may trigger the execution of a program by the processor (1120) and / or check the processing result of the processor (1120) through the input / output interface.

[0104] The communication interface (1180) may provide access to an external network. For example, the computing device (1100) may communicate with other devices via the communication interface (1180).

[0105] Each component of the device or method according to the present invention may be implemented in hardware, software, or a combination of hardware and software. Furthermore, the functions of each component may be implemented in software, with a microprocessor executing the software functions corresponding to each component.

[0106] Various implementations of the systems and techniques described herein may be implemented as digital electronic circuits, integrated circuits, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations of one or more computer programs executable on a programmable system. The programmable system includes at least one programmable processor (which may be a special purpose processor or a general purpose processor) coupled to receive data and instructions from and transmit data and instructions to a storage system, at least one input device, and at least one output device. Computer programs (also known as programs, software, software applications, or code) include instructions for the programmable processor and are stored on a "computer-readable recording medium."

[0107] A computer-readable recording medium includes any type of recording device that stores data that can be read by a computer system. Such a computer-readable recording medium may be a non-volatile or non-transitory medium such as a ROM, CD-ROM, magnetic tape, floppy disk, memory card, hard disk, magneto-optical disk, storage device, and may further include a transitory medium such as a data transmission medium. Furthermore, the computer-readable recording medium may be distributed across network-connected computer systems, so that computer-readable code can be stored and executed in a distributed manner.

[0108] Although the flowchart of this specification describes each process as being executed sequentially, this is merely an illustrative description of the technical idea of ​​one embodiment of the present disclosure. In other words, a person of ordinary skill in the art to which one embodiment of the present disclosure belongs can modify and apply various modifications and variations by changing the order described in the flowchart without departing from the essential characteristics of one embodiment of the present disclosure, or by executing one or more of the processes in parallel. Therefore, the flowchart is not limited to a chronological order.

[0109] The above description is merely an example of the technical idea of ​​the present embodiment, and those skilled in the art will appreciate that various modifications and variations can be made without departing from the essential characteristics of the present embodiment. Therefore, the present embodiments are not intended to limit the technical idea of ​​the present embodiment, but rather to explain it, and the scope of the technical idea of ​​the present embodiment is not limited by these embodiments. The scope of protection of the present embodiment should be interpreted by the claims below, and all technical ideas within a scope equivalent thereto should be interpreted as being included in the scope of rights of the present embodiment.

[0110]

[0111] CROSS-REFERENCE TO RELATED APPLICATION

[0112] This patent application claims priority to Korean Patent Application No. 10-2024-0050878, filed on April 16, 2024, the entire contents of which are incorporated herein by reference.

Claims

1. In a method performed by a certificate root server, When receiving FoD (Feature of Demand) certificate issuance request information from a certificate distribution server, a process of issuing a FoD certificate using the FoD certificate issuance request information; A process of applying an electronic signature to the above FoD certificate and encrypting the above FoD certificate; A process of transmitting the above FoD certificate to the above certificate distribution server; and A method comprising: receiving the FoD certificate from the electronic control device using a gateway and the certificate distribution server, and verifying the electronic signature of the challenge of the FoD certificate when the electronic control device verifies the FoD certificate and applies an electronic signature to the challenge of the FoD certificate.

2. In paragraph 1, A method further comprising a process of discarding the FoD certificate when FoD certificate discard request information is received from the electronic control device.

3. In paragraph 1, The above FoD certificate issuance request information includes information on the FoD function required for the vehicle, information on the VIN (Vehicle Identification Number), information on the PII (Personally Identifying Information), and information on payment.

4. In a method performed by an electronic control device, A process of receiving a FoD certificate from a certificate root server using a gateway and certificate distribution server and verifying the electronic signature of the FoD certificate; When the electronic signature of the above FoD certificate is verified, a process of verifying fields excluding the electronic signature of the above FoD certificate; A process of re-verifying the electronic signature of the FoD certificate and storing the FoD certificate when the fields other than the electronic signature of the FoD certificate are verified; and A method comprising the steps of applying an electronic signature to a challenge of the above FoD certificate and transmitting the FoD certificate to the certificate root server using the gateway and the certificate distribution server.

5. In paragraph 4, A method further comprising the step of transmitting information about an electronic control device ID to the gateway.

6. In paragraph 4, A method in which fields other than the electronic signature of the above FoD certificate are verified using information about fields received from an external source.

7. In paragraph 4, Method, in which the fields of the above FoD certificate, excluding the electronic signature, include the version of the FoD certificate, the serial number of the FoD certificate, the tag, the VIN, the electronic control unit ID, the feature flag, the challenge, the issuer, the order number, the issuance time, the function start time, the function end time, and the reserve space.

8. In a method performed by an electronic control device, Process of loading FoD certificate when vehicle ignition is turned on; A process for verifying the electronic signature of the above FoD certificate; When the electronic signature of the above FoD certificate is verified, a process of verifying fields excluding the electronic signature of the above FoD certificate; and A method comprising a process of activating the FoD function when fields other than the electronic signature of the above FoD certificate are verified.

9. In paragraph 8, A process of determining that the FoD certificate has expired if the function termination time of any of the fields other than the electronic signature of the FoD certificate is before the current time; The process of transmitting FoD certificate revocation request information to the certificate root server using the gateway and certificate distribution server; and A method further comprising a process for revoking the above FoD certificate.

10. In paragraph 8, A method in which fields other than the electronic signature of the above FoD certificate are verified using information about fields received from an external source.

11. Memory; and In an electronic control device including multiple processors, At least one processor among the plurality of processors, Receive FoD certificate from certificate root server using gateway and certificate distribution server, verify electronic signature of said FoD certificate, If the electronic signature of the above FoD certificate is verified, the fields excluding the electronic signature of the above FoD certificate are verified, If the fields other than the electronic signature of the above FoD certificate are verified, the electronic signature of the above FoD certificate is re-verified and the above FoD certificate is saved. An electronic control device that applies an electronic signature to a challenge of the above FoD certificate and transmits the FoD certificate to the certificate root server using the gateway and the certificate distribution server.

Citation Information

Patent Citations

  • Global automobile safety system

    JP2015136107A

  • Illumination device

    KR1020200091375A

  • Complex nanobubble system including ceramic membrane and oil skimmer, and industrial wastewater treatment method using the same

    KR1020240151048A

  • Metadata management system

    KR102498062B1

  • Method for detecting cellular senescence biomarkers using primers from isolated cells

    KR102657188B1