Information management device and information management method
The information management device addresses the risk of unauthorized use and leakage of encryption keys by controlling encryption key transmission based on user consent, ensuring secure and compliant use of vehicle information outside the vehicle.
Patent Information
- Application Number
- PCT/JP2024/027688
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-02
- Publication Date
- 2026-02-05
AI Technical Summary
Existing vehicle information transmission systems face risks of unauthorized use and leakage of encryption keys, leading to misuse of personal information without user consent, which is not adequately addressed by current measures.
An information management device with a receiving unit, transmitting unit, storage unit, and determining unit that controls the transmission of encryption keys based on user permission, ensuring secure and authorized use of vehicle information outside the vehicle.
Enables secure and controlled transmission of vehicle information by dynamically generating or changing encryption keys based on user consent, preventing unauthorized access and misuse, thus ensuring compliance with personal information protection regulations.
Smart Images

Figure JP2024027688_05022026_PF_FP_ABST
Abstract
Description
Information management device and information management method
[0001] The present invention relates to an information management device that transmits information collected from inside a vehicle to the outside of the vehicle.
[0002] In recent years, efforts have been made to expand and improve vehicle services by uploading information collected inside the vehicle to a server outside the vehicle and analyzing it there. However, in order to comply with personal information protection regulations in each country, the handling of personal information requires the vehicle user's consent. Therefore, if personal information is sent to a server without the user's consent, measures must be taken to prevent the personal information from being used on the server side until consent is obtained.
[0003] The following prior art exists as background art in this technical field. For example, Patent Document 1 (JP 2017-63381 A) discloses an in-vehicle information transmission device that is mounted on a vehicle and includes a vehicle information acquisition unit that acquires vehicle information related to the vehicle, a first key information storage unit that stores key information, an encryption unit that encrypts the vehicle information acquired by the vehicle information acquisition unit using the key information stored in the first key information storage unit, and a first vehicle information transmission unit that transmits the vehicle information encrypted by the encryption unit to a server device; a vehicle information reception unit that receives the vehicle information transmitted by the in-vehicle information transmission device, a vehicle information storage unit that stores the vehicle information received by the vehicle information reception unit, a vehicle information acquisition request reception unit that receives, from the vehicle information reception device, a request to acquire the vehicle information stored in the vehicle information storage unit, and a vehicle information acquisition request reception unit that receives the acquisition information received by the vehicle information acquisition request reception unit. A vehicle information transmission system is disclosed that comprises a server device having a second vehicle information transmission unit that transmits vehicle information stored in the vehicle information storage unit to the vehicle information receiving device in response to a request, a vehicle information acquisition request unit that transmits a request to acquire vehicle information to the server device, a vehicle information receiving unit that receives the vehicle information sent by the server device in response to the acquisition request, a key information acquisition request unit that transmits to another device a request to acquire key information necessary for decrypting the vehicle information received by the vehicle information receiving unit, a key information receiving unit that receives the key information sent by the other device in response to the acquisition request, and the vehicle information receiving device having a decryption unit that decrypts the vehicle information received by the vehicle information receiving unit using the key information received by the key information receiving unit.
[0004] JP 2017-63381 A
[0005] In the vehicle information transmission system described in Patent Document 1, a measure is taken such that the vehicle information receiving device cannot use the vehicle information until the user's permission is obtained in response to an inquiry about whether or not to transmit the encryption key to the user. On the other hand, after the user's permission is obtained and the encryption key is acquired, the vehicle information becomes available in the vehicle information receiving device. If the user's permission is revoked from this state, the vehicle information receiving device must be made unavailable. However, this is not desirable because there is a risk of the encryption key being leaked or misused in the vehicle information receiving device, which could lead to the vehicle information being misused.
[0006] In order to solve the above-mentioned problems, the present invention aims to provide an information management device that can appropriately control whether vehicle information can be used outside the vehicle from inside the vehicle when information collected inside the vehicle is transmitted outside the vehicle.
[0007] A representative example of the invention disclosed in the present application is as follows: That is, an information management device connected to an in-vehicle device via a network includes a receiving unit that receives information encrypted by the in-vehicle device, a transmitting unit that transmits the information received from the in-vehicle device to a server, a storage unit that stores the information received from the in-vehicle device and a key used to decrypt the information, and a determining unit that determines whether to transmit the key used to decrypt the information to the server based on user usage permission information for the information.
[0008] According to one aspect of the present invention, it is possible to appropriately control whether vehicle information is available outside the vehicle from inside the vehicle. Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments.
[0009] FIG. 1 is a block diagram showing an example of the functional configuration of an in-vehicle system equipped with an information management device according to Examples 1 to 4 of the present invention. FIG. 2 is a flowchart of an encryption key transmission determination process according to Example 1 of the present invention. FIG. 3 is a flowchart of an encryption key transmission determination process according to Example 2 of the present invention. FIG. 4 is a flowchart of an encryption key transmission determination process according to Example 3 of the present invention. FIG. 5 is a diagram showing an example of the configuration of a key management table according to Example 4 of the present invention. FIG. 6 is a block diagram showing an example of the functional configuration of an in-vehicle system equipped with an information management device according to Example 5 of the present invention. FIG. 7 is a flowchart of an encryption key transmission determination process according to Example 5 of the present invention.
[0010] Hereinafter, embodiments of the present invention will be described with reference to the drawings. Note that components with the same reference numerals in each embodiment have the same functions in each embodiment unless otherwise specified, and the description thereof will be omitted.
[0011] 1 is a block diagram showing an example of the functional configuration of an in-vehicle system 1001 equipped with an information management device according to any one of Examples 1 to 4 of the present invention. In this example, a gateway device 1010 equipped in the in-vehicle system 1001 collects information inside the vehicle from an information transmission device 1020 and transmits the collected information to a server 1002.
[0012] The in-vehicle system 1001 includes a gateway device 1010 and an information transmission device 1020. The gateway device 1010 is an example of an information management device that controls the transmission of information collected by the in-vehicle system 1001 to the server 1002. The information transmission device 1020 is an example of an in-vehicle device that transmits information to the gateway device 1010. The number of gateway devices 1010 and information transmission devices 1020 included in the in-vehicle system 1001 may be more than one, as long as each is one or more.
[0013] The in-vehicle system 1001 and the server 1002 are connected to each other via a communication network 1031. The communication network 1031 is used for data communication between the gateway device 1010 and the server 1002. The communication standard of the communication network 1031 may be Ethernet, but other communication standards may also be used. Furthermore, the server 1002 may be provided on a cloud or may be an external device outside the vehicle, such as a diagnostic machine.
[0014] The gateway device 1010 and the information transmission device 1020 are connected to each other by a communication bus 1030. The communication bus 1030 is used for data communication by a receiving unit 1011 and a transmitting unit 1021, which will be described later. The communication standard of the communication bus 1030 may be CAN, Ethernet, SPI, MII, LIN, or the like, but other communication standards may also be used.
[0015] The gateway device 1010 and the information transmission device 1020 are configured with a SoC (System On Chip) or a microcomputer, and include a processor that executes programs, memory accessible by the processor, a communication device connected to the processor, etc. They may also include a security chip such as an HSM (Hardware Security Module) to safely execute security-related processes.
[0016] The gateway device 1010 includes a receiving unit 1011 , a transmitting unit 1012 , a storage unit 1013 , a determining unit 1014 , and a key generating unit 1015 .
[0017] The receiving unit 1011 is a functional unit that receives information transmitted from the information transmitting device 1020 via the communication bus 1030. The information transmitted from the information transmitting device 1020 is encrypted with an encryption key generated by key generating units 1015 and 1022 (described later), thereby ensuring confidentiality.
[0018] The transmitting unit 1012 transmits information acquired from the information transmitting device 1020 and stored in the memory unit 1013 to the server 1002 via the communication network 1031. The communication protocol may be HTTP, MQTT, FTP, or the like, but other communication standards may also be used. However, from a security standpoint, it is preferable to encrypt communications and perform server authentication using TLS or the like, and a certificate and encryption key for server communications may be stored in advance. The timing of information transmission by the transmitting unit 1012 may be linked to the reception timing of the receiving unit 1011, or the transmission may be repeated at predetermined timings. Furthermore, the transmitting unit 1012 transmits the encryption key stored in the memory unit 1013 to the server 1002 via the communication network 1031. Specifically, the encryption key is transmitted in accordance with permission from the determining unit 1014, which will be described later. For example, the encryption key may be transmitted only once when the determination unit 1014 permits transmission, or the encryption key may be transmitted repeatedly during the period when the determination unit 1014 permits transmission.
[0019] The storage unit 1013 stores information transmitted from the information transmission device 1020 and an encryption key generated by the key generation unit 1015 (described later). The storage medium may be a RAM or a ROM, or may be another type of storage medium.
[0020] The determination unit 1014 determines whether to transmit the encryption key stored in the storage unit 1013 to the server 1002 based on the user's license information for the information received by the receiving unit 1011. For example, if the user's license information is changed to "agree," the determination unit 1014 permits transmission of the encryption key to the server 1002. As a result, if the user's license information indicates "agree," the server 1002 decrypts the information using the received encryption key, making the received information usable. The user's license information may be acquired from the information transmission device 1020 or from another device. For example, when the license information is changed by a user operation on a device such as a navigation system, the changed license information may be transmitted to the gateway device 1010.
[0021] The key generation unit 1015 generates an encryption key (common key) that can encrypt and decrypt information acquired by the receiving unit 1011. For example, the key generation unit 1015 generates a common session key with the information transmission device 1020 via the communication bus 1030. The session key can be generated using a known key sharing algorithm such as DH (Diffie-Hellman) or ECDH (Elliptic curve Diffie-Hellman).
[0022] Key generation unit 1015 of gateway device 1010 needs to use a common algorithm with key generation unit 1022 of information transmission device 1020, and the algorithm may be exchanged at the time of design, or the algorithm may be determined by exchanging information between gateway device 1010 and information transmission device 1020 before the timing of key generation. Furthermore, key generation may be any time before information transmission by information transmission device 1020 begins. By dynamically generating encryption keys in this way, it is possible to reduce the management costs and operation costs of encryption keys.
[0023] The information transmitting device 1020 includes a transmitting unit 1021 , a key generating unit 1022 , a storage unit 1023 , and an encryption unit 1024 .
[0024] The transmission unit 1021 transmits information such as logs collected from sensors and peripherals connected to the information transmission device 1020 to the gateway device 1010 via the communication bus 1030. In addition, the information transmitted by the transmission unit 1021 may be encrypted by an encryption unit 1024 (described later) to ensure confidentiality.
[0025] Similar to the key generation unit 1015 , the key generation unit 1022 generates an encryption key (session key) that is shared with the gateway device 1010 .
[0026] The storage unit 1023 stores the encryption key generated by the key generation unit 1022. It may also be used as a storage area for information transmitted by the transmission unit 1021. The storage medium may be a RAM or a ROM, or may be another type of storage medium.
[0027] Encryption unit 1027 encrypts information transmitted from transmission unit 1021 using the encryption key stored in storage unit 1023. A known encryption algorithm such as AES can be used for encryption. The encryption algorithm used must be a common algorithm between information transmission device 1020 and server 1002, and the algorithm may be exchanged at the time of design, or information indicating the encryption algorithm may be added to the encrypted information.
[0028] An example of encryption key transmission processing executed by the information management device according to this embodiment will be described below with reference to FIG.
[0029] FIG. 2 is a flowchart of the encryption key transmission determination process according to the first embodiment.
[0030] First, the determination unit 1014 of the gateway device 1010 determines whether an encryption key has been generated (S131). For example, whether an encryption key has been generated can be determined based on whether an encryption key is stored in the storage unit 1013. If an encryption key has not been generated (NO in S131), the key generation unit 1015 generates an encryption key between the gateway device 1010 and the information transmission device 1020 and stores the generated encryption key in the storage unit 1013 (S132). Thereafter, information transmitted from the information transmission device 1020 is encrypted using the generated encryption key. If an encryption key has been generated (YES in S131), an encryption key is not generated and the process proceeds to step S133.
[0031] Next, the determination unit 1014 of the gateway device 1010 determines whether the user's license information has been changed to consent. If the license information has been changed from the previous non-consent state to consent (YES in S133), the encryption key is transmitted from the transmission unit 1012 to the server 1002. If the license information has not been changed to consent (NO in S133), the encryption key is not transmitted to the server 1002. As a result, the server 1002 can use the information encrypted by the information transmission device 1020 only if the license information has been changed to consent.
[0032] As described above, according to the first embodiment of the present invention, when information collected inside a vehicle is transmitted to the outside of the vehicle, whether or not the vehicle information can be used outside the vehicle can be appropriately controlled from inside the vehicle.
[0033] Next, an information management device according to Example 2 will be described. The functional configurations of an in-vehicle system 1001 and a server 1002 according to Example 2 differ from those of Example 1 in some functions, but are the same as those of Example 1 except for those described below. In Example 2, illustration and description of functions common to Example 1 will be omitted, and functional differences will be mainly described.
[0034] Fig. 3 is a flowchart of encryption key transmission determination processing according to Example 2. Note that the processing shown in Fig. 3 is the same as the processing shown in Fig. 2 except that branch processing for when the usage permission information is changed to non-consent is added to the processing shown in Fig. 2. Therefore, the following mainly describes the differences from Fig. 2.
[0035] Steps S131 to S134 in FIG. 3 are the same as steps S101 to S104 in FIG. 2 . After step S134, the determination unit 1014 of the gateway device 1010 determines whether the user's license information has been changed to non-consent. If the license information has been changed to non-consent ("YES" in S135), the key generation unit 1015 regenerates an encryption key between the information transmission device 1020 and the information transmission device 1020 and stores the regenerated encryption key in the storage unit 1013 (S136). Thereafter, information transmitted from the information transmission device 1020 is encrypted using the regenerated encryption key. As a result, after the user's license information has been changed to non-consent, the information transmitted from the transmission unit 1012 cannot be decrypted by the server 1002, and the information becomes unusable by the server 1002. Furthermore, by regenerating the encryption key and changing to the regenerated encryption key, it is possible to prevent leakage of the encryption key on the server 1002 side and misuse of information due to unauthorized use of the encryption key after the user's license has been changed to non-consent. Furthermore, the encryption key used before regeneration can be discarded from the storage unit 1013 of the gateway device 1010 and the storage unit 1023 of the information transmission device 1020, thereby reducing the amount of data to be stored. If the usage permission information has not been changed to non-consent ("NO" in S135), the encryption key is not regenerated and the process ends.
[0036] <Embodiment 3> Fig. 4 is a flowchart of encryption key transmission determination processing according to embodiment 3. Note that the processing shown in Fig. 4 is the same as the processing shown in Fig. 3 except that branch processing when a predetermined period of time has elapsed since encryption key generation has been added to the processing shown in Fig. 3. Therefore, the following mainly describes the differences from Fig. 3.
[0037] Steps S131 to S136 are the same as those of the second embodiment shown in FIG. 3 . After step S136, the gateway device 1010 determines whether a predetermined time has elapsed since the encryption key was generated (S137). The predetermined time elapses when the timer activated in step S132 or step S136 expires and the predetermined time has elapsed since the encryption key was generated ("YES" in S137). If this occurs, the key generation unit 1015 regenerates the encryption key with the information transmission device 1020 and stores the regenerated encryption key in the storage unit 1013 (S138). Subsequently, information transmitted from the information transmission device 1020 is encrypted using the regenerated encryption key. By dividing the life cycle of the encryption key into predetermined time periods, security risks associated with encryption key leaks can be reduced. The predetermined time period may be stored as a parameter set in advance in the information transmission device 1020. Although not shown in the drawings, when the key is generated in step S138, if the user's license information indicates consent, the transmitting unit 1012 transmits the regenerated encryption key to the server 1002. If a predetermined time has not elapsed since the encryption key was generated (NO in S137), the encryption key is not regenerated and the process ends.
[0038] In the above-described third embodiment, an example has been described in which steps S137 and S138 are added to the encryption key transmission determination process (FIG. 3) of the second embodiment, but steps S137 and S138 may be added after step S134 of the encryption key transmission determination process (FIG. 2) of the first embodiment.
[0039] <Fourth Embodiment> Fig. 5 is a flowchart of an encryption key transmission determination process according to a fourth embodiment, and Fig. 6 is a diagram showing an example of the configuration of a key management table. The process shown in Fig. 5 differs from the process shown in Fig. 2 in that consent to use permission is provided for each type of information. Therefore, use permission information is provided for each type of information, an encryption key is generated for each type of information, and information is encrypted for each type. The other processes are the same as those shown in Fig. 2. Therefore, the following mainly describes the differences from Fig. 2.
[0040] First, the determination unit 1014 of the gateway device 1010 determines whether an encryption key has already been generated for each information type. For example, as shown in FIG. 6 , the gateway device 1010 maintains a key management table that associates and stores information type 1, key ID 2, and usage permission information 3, and determines the generation status of an encryption key for each information type 1. The key management table illustrated in FIG. 6 records the generation status of three types of encryption keys (A, B, and C), and determines whether an encryption key ID has been recorded for each of the three information types A, B, and C. If some encryption keys have not been generated (NO in S139), the gateway device 1010 generates encryption keys that have not been generated, associates the key ID of the generated encryption key with the information type, and records it in the key management table (S132). If encryption keys for all information types have already been generated (YES in S139), no new encryption keys are generated, and the process proceeds to step S140.
[0041] Next, the determination unit 1014 of the gateway device 1010 determines whether the license information for each information type has been changed to "Agree." If the license information for each information type has been changed to "Agree" ("YES" in S139), the encryption key for the information type for which the license information is "Agree" is transmitted from the transmission unit 1012 to the server 1002 (S141). In the key management table illustrated in FIG. 6, the license information for information types A and C indicates "Agree." Therefore, the transmission unit 1012 transmits to the server 1002 an encryption key with key ID A and an encryption key with key ID C. As a result, the server 1002 can use information encrypted by the information transmission device 1020 only for information of the information type for which the user has given permission. If the license information for each information type has not been changed to "Agree" ("NO" in S139), the encryption key is not transmitted to the server 1002. As a result, the server 1002 cannot use information of an information type for which the user has not given permission.
[0042] 7 is a block diagram showing an example of the functional configuration of an in-vehicle system 1001 equipped with an information management device according to Example 5. Note that the in-vehicle system 1001 according to Example 5 is obtained by deleting the key generation units 1015 and 1022 from the in-vehicle system 1001 according to Example 1 ( FIG. 1 ) and adding a key change unit 1016. Therefore, in Example 7, descriptions of the same configurations and functions as those of the in-vehicle system 1001 according to Example 1 will be omitted, and differences from the in-vehicle system 1001 according to Example 1 will be mainly described.
[0043] An in-vehicle system 1001 according to the fifth embodiment includes a gateway device 1010 and an information transmission device 1020. The gateway device 1010 includes a receiving unit 1011, a transmitting unit 1012, a storage unit 1013, a determining unit 1014, and a key changing unit 1016. The information transmission device 1020 includes a transmitting unit 1021, a storage unit 1023, and an encryption unit 1024.
[0044] That is, as shown in FIG. 7 , an in-vehicle system 1001 according to the fifth embodiment has a key generation unit 1015 removed from a gateway device 1010 and a key generation unit 1022 removed from an information transmission device 1020. In this embodiment, the key generation units 1015 and 1022 do not dynamically generate encryption keys, but statically store multiple encryption keys in advance in storage units 1013 and 1023. The encryption keys are preferably stored in a secure ROM built into a hardware security module (HSM) or the like. The encryption keys of each device may be stored at the time of production, or keys pre-stored in the SoC may be used.
[0045] Of the encryption keys statically stored in storage units 1013 and 1023, the encryption key to be used may be determined in advance between gateway device 1010 and information transmission device 1020, or may be determined by exchanging information between gateway device 1010 and information transmission device 1020 each time an encryption key is selected. Key change unit 1016 changes the encryption key to be used by gateway device 1010 and information transmission device 1020 when the user's usage consent is changed from consent to denial. As a result, when the user's usage consent is changed to denial, information transmitted from transmission unit 1012 cannot be decrypted by server 1002, and the information cannot be used by server 1002. Furthermore, changing the encryption key can prevent leakage of the encryption key on the server 1002 side or misuse of information due to unauthorized use after the user's usage consent is changed to denial.
[0046] Furthermore, since the encryption key needs to be changed every time the user's license information changes from consent to non-consent, it is advisable to store a sufficient number of encryption keys in the storage units 1013 and 1023 .
[0047] Fig. 8 is a flowchart of the encryption key transmission determination process according to the fifth embodiment. The process shown in Fig. 8 is the same as the process shown in Fig. 3 except that the process for checking the encryption key generation status is deleted and the process when the license information is changed to non-consent is changed. Therefore, the following mainly describes the differences from Fig. 8.
[0048] Steps S133 to S134 in FIG. 8 are the same as steps S133 to S134 in FIG. 3 . After step S134, the determination unit 1014 of the gateway device 1010 determines whether the user's license information has been changed to non-consent (S135). If the license information has been changed to non-consent ("YES" in S135), the key change unit 1016 works with the information transmission device 1020 to change the encryption key to be used (S142). After the encryption key is changed, the information transmitted from the information transmission device 1020 is encrypted using the changed encryption key. As a result, after the user's license information has been changed to non-consent, the information transmitted from the transmission unit 1012 cannot be decrypted by the server 1002, and the information becomes unusable by the server 1002. Furthermore, after the user's license has been changed to non-consent, the change of the encryption key can prevent the server 1002 from leaking the encryption key or misusing the information through unauthorized use of the encryption key. If the license information has not been changed to non-consent ("NO" in S135), the encryption key is not changed and the process ends.
[0049] The present invention is not limited to the above-described embodiments, but includes various modifications. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those including all of the described configurations. Furthermore, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of each embodiment with other configurations.
[0050] Furthermore, the above-described configurations, functions, processing units, processing means, etc. may be partially or entirely realized by hardware, for example, by designing them as integrated circuits. Furthermore, the above-described configurations, functions, etc. may be realized by software, in which a processor interprets and executes a program that realizes each function. Information such as programs, tapes, and files that realize each function can be stored in a memory, a recording device such as a hard disk or SSD (solid state drive), or a recording medium such as an IC card, SD card, or DVD.
[0051] In addition, the control lines and information lines shown are those that are considered necessary for the explanation, and do not necessarily show all the control lines and information lines in the product. In reality, it can be assumed that almost all components are interconnected.
Claims
1. An information management device connected to an in-vehicle device via a network, comprising: a receiving unit that receives information encrypted by the in-vehicle device; a transmitting unit that transmits the information received from the in-vehicle device to a server; a memory unit that stores the information received from the in-vehicle device and a key used to decrypt the information; and a determining unit that determines whether or not to send the key used to decrypt the information to the server based on the user's usage permission information for the information.
2. An information management device according to claim 1, comprising a key generation unit that generates the key between the information management device and the in-vehicle device.
3. An information management device according to claim 2, wherein the key generation unit regenerates the key between the information management device and the in-vehicle device after the usage permission information is changed from consent to non-consent.
4. An information management device according to claim 2 or 3, wherein the key generation unit regenerates the key between the information management device and the in-vehicle device after a predetermined period has elapsed since the generation of the key.
5. An information management device according to claim 2, wherein the key generation unit generates the key for each type of information between the information management device and the in-vehicle device.
6. An information management device according to claim 1, wherein the storage unit stores a plurality of keys, and the information management device is provided with a key change unit that changes the key used to decrypt the information after the license information is changed from consent to non-consent.
7. An information management device according to claim 1, wherein the transmitting unit transmits the key to the server based on the determination result of the determining unit.
8. An information management method executed by an information management device connected to an in-vehicle device via a network, the information management device having a calculation device that executes a program and a storage device accessible by the calculation device, the information management method comprising: a receiving procedure in which the calculation device receives information encrypted by the in-vehicle device; a transmitting procedure in which the calculation device transmits the information received from the in-vehicle device to a server; a storing procedure in which the calculation device stores the information received from the in-vehicle device and a key used to decrypt the information in the storage device; and a determining procedure in which the calculation device determines whether to transmit the key used to decrypt the information to the server based on user usage permission information for the information.
Citation Information
Patent Citations
Receiver for limited audio visual broadcasting
JP2001054092A
Vehicle information transmission system and on-vehicle information transmitter
JP2017063381A
System and method for vehicle data management
JP2019161434A