Vehicle data certification method, vehicle-mounted electronic device, and vehicle data certification system
The vehicle data certification method employs a zero-knowledge proof protocol to validate vehicle data legitimacy, addressing key management complexity and security threats by using shared, disposable communication parameters, thus enhancing security and accuracy without increasing private keys.
Patent Information
- Application Number
- PCT/JP2024/030545
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-27
- Publication Date
- 2026-03-05
AI Technical Summary
Existing vehicle data certification systems face challenges in managing increasing numbers of private keys due to enhanced functionality and network connectivity, leading to complex key management and security threats such as device spoofing and software tampering.
A vehicle data certification method using a zero-knowledge proof protocol where onboard electronic devices share disposable and publicly available communication parameters with an off-vehicle management device, proving legitimacy without increasing stored private keys, by generating and verifying proof values through shared parameters.
This approach reduces the need for additional private keys, enhances security by preventing spoofing attacks, and improves proof accuracy based on the importance of the proof content, while maintaining system integrity.
Smart Images

Figure JP2024030545_05032026_PF_FP_ABST
Abstract
Description
Vehicle data certification method, vehicle-mounted electronic device, and vehicle data certification system
[0001] The present invention relates to an on-board electronic device and a vehicle data certification system that certify the validity of vehicle data, and is suitable for use in proving the validity of vehicle data between on-board electronic devices connected via a network or between an on-board electronic device and a management device.
[0002] Vehicles such as automobiles are equipped with multiple on-board electronic devices called ECUs (Electronic Control Units), which perform functions such as engine control, brake control, and safety control. These functions are realized by software running on the on-board electronic devices. In recent years, in order to realize autonomous driving and incident response, the on-board electronic devices have become increasingly connected to external server devices via networks, and the on-board electronic devices have become more multifunctional. However, connecting to external devices via networks has increased security threats, such as the spoofing of legitimate devices and tampering with the software that realizes the functions.
[0003] The following prior art exists as background technology for addressing such security threats: Patent Document 1 (JP 2007-214696 A) describes a network between vehicle control devices in which a plurality of control devices each having a communication means participates, in which authentication is performed between the control devices on the network to guarantee their legitimacy, and unauthorized control devices are identified within the network through the mutual authentication between the control devices.
[0004] Japanese Patent Application Laid-Open No. 2007-214696
[0005] In the network described in the aforementioned Patent Document 1, the in-vehicle electronic device shares a key, which is secret information, with the device with which it is communicating, and then encrypts and transmits device identification information, program identification information, etc., and confirms that the information can be correctly decrypted, thereby preventing device spoofing and program tampering.
[0006] On the other hand, in order to ensure security, it is important not to use one key for multiple purposes. Therefore, as the functionality of in-vehicle electronic devices increases, the number of keys stored in in-vehicle electronic devices and external server devices increases, making key management more complicated and putting a strain on the secure memory for storing keys in the in-vehicle electronic devices.
[0007] The present invention has been made in consideration of the above-mentioned circumstances, and provides an on-board electronic device and a vehicle data certification system that can prove its own legitimacy to an off-board server device without increasing the number of private keys stored in the on-board electronic device.
[0008] A representative example of the invention disclosed in the present application is as follows: That is, a vehicle data certification method executed by a vehicle data certification system, the vehicle data certification system having an on-board electronic device and an off-vehicle management device connected to the on-board electronic device via a network, the vehicle data certification method comprising the steps of: the on-board electronic device transmitting to the off-vehicle management device a conversion method for converting secret information held by the on-board electronic device into other information, communication parameters used in the conversion method, and second generated information generated using first generated information generated by the on-board electronic device; the on-board electronic device acquiring third generated information generated by the off-vehicle management device; the on-board electronic device generating a proof value using the first generated information, the third generated information, and the communication parameters in accordance with the conversion method; and transmitting proof information required for a zero-knowledge proof protocol, including the generated proof value, to the off-vehicle management device.
[0009] According to one aspect of the present invention, it is possible to suppress an increase in the amount of secret information stored for verifying legitimacy. Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments.
[0010] FIG. 1 is a configuration diagram of a vehicle data certification system according to an embodiment of the present invention. FIG. 2 is a diagram illustrating an example of the hardware configuration of a vehicle according to an embodiment of the present invention. FIG. 3 is a diagram illustrating an example of the hardware configuration of an on-board electronic device according to an embodiment of the present invention. FIG. 4 is a diagram illustrating an example of the hardware configuration of a management device according to an embodiment of the present invention. FIG. 5 is a flowchart illustrating an example of processing executed by an on-board electronic device and a management device according to an embodiment of the present invention. FIG. 6 is a flowchart illustrating an example of certification processing according to an embodiment of the present invention. FIG. 7 is a flowchart illustrating an example of verification processing according to an embodiment of the present invention. FIG. 8 is a diagram illustrating an example of a vehicle data selection screen according to an embodiment of the present invention. FIG. 9 is a diagram illustrating an example of the configuration of certification count rule information according to an embodiment of the present invention. FIG. 10 is a diagram illustrating an example of the configuration of certification content importance information according to an embodiment of the present invention. FIG. 11 is a diagram illustrating an example of the configuration of certification content importance information according to an embodiment of the present invention. FIG. 12 is a flowchart illustrating an example of certification processing according to an embodiment of the present invention.
[0011] Examples of the present invention will be described below, but the present invention is not limited to the examples described below.
[0012] FIG. 1 is a diagram showing the configuration of a vehicle data certification system according to an embodiment of the present invention.
[0013] The vehicle data certification system includes vehicles 10-1 and 10-2, a management center 20, and a network 30. While two vehicles 10-1 and 10-2 are shown in FIG. 1, the number of vehicles may be one, or three or more. When there is no need to distinguish between the vehicles 10-1 and 10-2, the subscripts may be omitted and the vehicle may simply be referred to as vehicle 10.
[0014] The vehicle 10 is equipped with an on-board electronic device 11. While one on-board electronic device 11 is illustrated in Fig. 1, two or more on-board electronic devices 11 may be provided. The on-board electronic device 11 includes a communication unit 101 that communicates with the network 30, a certification object selection unit 102 that selects an object to be certified to the management center 20, a communication parameter generation unit 103 that generates communication parameters to be used for the certification, a random number generation unit 104 that generates a random number to be used for the certification, a certification-required value generation unit 105 that generates a certification-required value to be used for the certification, a certification value generation unit 106 that generates a certification value to be used for the certification, an on-board memory unit 107 that stores vehicle data held by the vehicle 10 and the on-board electronic device 11, and a conversion method memory unit 108 that stores a conversion method for converting the representation of the vehicle data to be certified.
[0015] The management center 20 has a management device 21 that verifies the vehicle data and determines whether re-certification is necessary. The management device 21 has a communication unit 201 that communicates with the network 30, a random number generation unit 202 that generates random numbers to be used for certification, a verification unit 203 that verifies the certification value, a verification result determination unit 204 that determines whether re-certification is necessary based on the verification result, a notification unit 205 that notifies the user of the verification result, a vehicle information storage unit 206 that stores vehicle information, a conversion method storage unit 207 that stores a conversion method for converting the expression of the vehicle data to be certified, an importance storage unit 208 that stores the importance of the vehicle data, a certification number rule storage unit 209 that stores rules for the number of times the vehicle data is certified, and a verification result storage unit 210 that stores the verification result of the certification.
[0016] The network 30 may be a wireless communication such as LTE (Long Term Evolution), 4G, 5G, Wi-Fi (Wireless Fidelity), or Bluetooth, or may be a wired LAN (Local Area Network) or CAN.
[0017] The management center 20 may be provided with a security monitoring device 28 that monitors security information. The security monitoring device 28 accumulates notifications of attacks determined to have occurred through verification of vehicle data, and analyzes security threats.
[0018] FIG. 2 is a diagram illustrating an example of the hardware configuration of the vehicle 10 according to the embodiment of the present invention.
[0019] The vehicle 10 has on-board electronic devices 11-1, 11-2, 11-3, and 11-4. The on-board electronic devices 11-1, 11-2, 11-3, and 11-4 are communicatively connected via an on-board network 12. While FIG. 2 illustrates four on-board electronic devices 11-1, 11-2, 11-3, and 11-4, the number of on-board electronic devices 11 may be one or any number of on-board electronic devices 11 equal to or greater than one. The on-board electronic devices 11-1, 11-2, 11-3, and 11-4 may be master devices that transmit instructions for controlling on-board electronic devices 11 other than themselves, slave devices that operate in accordance with instructions received from on-board electronic devices 11 other than themselves, or proxy devices or gateway devices that mediate and convert communications between two or more different on-board electronic devices 11 other than themselves. When there is no need to distinguish between the on-board electronic devices 11-1, 11-2, 11-3, and 11-4, the subscripts are omitted and they are simply referred to as the on-board electronic devices 11. The on-board network 12 can use, for example, a control area network (CAN) or Ethernet, and there may be multiple on-board networks 12, and a protocol other than the above-mentioned protocol may also be used.
[0020] FIG. 3 is a diagram showing an example of the hardware configuration of the in-vehicle electronic device 11 according to the embodiment of the present invention.
[0021] The on-board electronic device 11 is an electronic control unit (ECU) having a communication device 13, an input / output device 14, a CPU (Central Processing Unit) 15, a memory 16, a storage device 17, and a secure device 18. The communication device 13, the input / output device 14, the CPU 15, the memory 16, the storage device 17, and the secure device 18 are communicatively connected via an internal signal line 19 such as a bus.
[0022] The communication device 13 connects to other on-board electronic devices via the on-board network 12. The input / output device 14 is an HMI (Human Machine Interface) such as a panel or display. The CPU 15 is a computing device that executes programs stored in the memory 16. The CPU 15 operates as a functional block that provides various functions of the on-board electronic device 11 by executing predetermined computational processes. The memory 16 has a volatile storage area that temporarily stores data used by the CPU 15 when executing a program. The storage device 17 has a non-volatile storage area that is accessible by the CPU 15 and includes a program area that stores programs executed by the CPU 15 and a data area that stores data used by the CPU 15 when executing a program.
[0023] The secure device 18 can use, for example, a physically unrewritable storage area, a write-only storage area, or a storage area in which access control such as user or process authentication is set. The secure device 18 may store keys for encryption and decryption, digital signatures for verifying software, electronic certificates, setting values, verification values, identification information, etc., such as an HSM (Hardware Security Module). Furthermore, the secure device 18 may perform encryption / decryption processing, verification processing, signature addition, random number generation, etc.
[0024] FIG. 4 is a diagram illustrating an example of the hardware configuration of the management device 21 according to the embodiment of the present invention.
[0025] The management device 21 includes a communication device 22, an input / output device 23, a CPU 24, a memory 25, and a storage device 26. The communication device 22, the input / output device 23, the CPU 24, the memory 25, and the storage device 26 are communicatively connected via an internal signal line 27.
[0026] The communication device 22 is a network interface device that controls communication with other devices according to a predetermined protocol. The input / output device 23 includes input devices such as a keyboard, mouse, touch panel, numeric keypad, scanner, microphone, and sensor, and is an interface that receives input from an operator or other devices. The input / output device 23 also includes output devices such as a display, printer, and speaker, and is an interface that outputs program execution results in a format that can be viewed by an operator. The CPU 24 is a computing device that executes programs stored in the memory 25. By executing various programs, the CPU 24 operates as a functional block that provides various functions of the management device 21. Note that some of the processing performed by the CPU 24 by executing the programs may be executed by another computing device (e.g., hardware such as an ASIC or FPGA, or a GPU). The memory 25 includes a ROM, which is a non-volatile storage element, and a RAM, which is a volatile storage element. The ROM stores immutable programs (e.g., BIOS) and the like. The RAM is a high-speed, volatile storage element such as a dynamic random access memory (DRAM), and temporarily stores programs executed by the CPU 24 and data used when the programs are executed. The storage device 26 is a large-capacity, non-volatile storage device, such as a magnetic storage device (HDD) or flash memory (SSD). The storage device 26 also stores data used by the CPU 24 when executing the programs and the programs executed by the CPU 24. In other words, the programs are read from the storage device 26, loaded into the memory 25, and executed by the CPU 24, thereby realizing the various functions of the management device 21.
[0027] The programs executed by the CPU 24 are provided to the management device 21 from removable media (CD-ROM, flash memory, etc.) or via a network, and are stored in a non-volatile storage device 26, which is a non-transitory storage medium. For this reason, the management device 21 should preferably have an interface for reading data from removable media.
[0028] The management device 21 is a computer system configured on one physical computer or on multiple logically or physically configured computers, and may operate on a virtual computer constructed on multiple physical computer resources. For example, each functional unit may operate on a separate physical or logical computer, or multiple functional units may be combined to operate on a single physical or logical computer.
[0029] The hardware configuration of the management device 21 has been described with reference to FIG. 4, but the security monitoring device 28 may have the same hardware configuration.
[0030] Next, the processing flow in the vehicle data certification system of this embodiment will be described. The processing flow described below is executed by each processing unit embodied in the device that constitutes the vehicle data certification system, by loading programs stored in the storage devices 26 and 17 of the management device 21 and the on-board electronic device 11 into the memories 25 and 16 and executing them by the CPUs 24 and 15. Furthermore, each program may be introduced as needed via another storage medium or communication medium (a network or a transmission wave propagating through a network).
[0031] FIG. 5 is a flowchart showing an example of processing executed by the in-vehicle electronic device 11 and the management device 21 in the vehicle data certification system according to the embodiment of the present invention.
[0032] First, the on-board electronic device 11 and the management device 21 execute a certification process (S501). Details of the certification process (S501) will be described with reference to FIG. 6. Next, the on-board electronic device 11 and the management device 21 execute a verification process (S502). Here, the number of on-board electronic devices 11 may be one or more. Details of the verification process (S502) will be described with reference to FIG. 7.
[0033] 5 is repeatedly executed when a predetermined condition is satisfied, that is, after the verification process S502 is completed, if a predetermined condition is satisfied, the proof process S501 and the verification process S502 are executed again.
[0034] FIG. 6 is a flowchart showing an example of the certification process S501 executed by the on-board electronic device 11 and the management device 21 in the vehicle data certification system according to the embodiment of the present invention.
[0035] First, the on-board electronic device 11 starts the certification process (S601). Next, the on-board electronic device 11 acquires the certification target (S602). For example, the on-board electronic device 11 acquires information to be certified to the management device 21 from the on-board storage unit 107. The information to be certified may be, for example, an ECU ID, an ECU serial number, a software ID, a software identifier, or a software version, but may also be other information or any combination of these pieces of information.
[0036] Next, the certification target selection unit 102 of the in-vehicle electronic device 11 obtains a conversion method for the information to be certified from the conversion method storage unit 108 (S603). The conversion method is a method for converting the information to be certified into a mathematical expression. For example, there is a method in which the information to be certified, such as an ECU ID, is expressed in decimal x and the answer x to the discrete logarithm problem y = g^x mod p is known. g^x indicates multiplication by an integer g x times, and mod p indicates calculation of the remainder when divided by the integer p. Note that the conversion method is not limited to the exemplified method, and other methods may be used.
[0037] Next, the communication parameter generation unit 103 of the in-vehicle electronic device 11 generates communication parameters (S604). The communication parameters are disposable, publicly available, and used in the zero-knowledge proof protocol for the conversion method acquired in step S603. For example, when the discrete logarithm problem is used as the conversion method, the communication parameters are a prime number p and positive integers g, y, and q, where g, y, and q satisfy y = g^x mod p and g^q = 1 mod p. Furthermore, for example, the communication parameters may be generated by inputting a random number generated by a random number generation function of the secure device 18 into a prime number determination algorithm and using the value determined to be prime as the prime number p, or by using the calculation results output by a modular multiplication calculation function of the secure device 18 as the integers y and q, or by a combination of multiple methods.
[0038] Next, the random number generation unit 104 of the on-board electronic device 11 generates a random number r as first generation information (S605). For example, the random number may be generated using the random number generation function of the secure device 18, or other methods may be used. Next, the proof-needed value generation unit 105 of the on-board electronic device 11 generates a proof-needed value c as second generation information (S606). The proof-needed value c is a value calculated using the communication parameters g and p generated in step S604 and the random number r generated in S605, depending on the conversion method selected in step S603. For example, when the discrete logarithm problem is used, the proof-needed value is calculated as c = g^r mod p.
[0039] Then, the communication unit 101 of the in-vehicle electronic device 11 transmits the conversion method acquired in step S603, the communication parameters created in step S604, and the proof required value generated in step S606 to the management device 21 via the network 30.
[0040] Next, the communication unit 201 of the management device 21 acquires the conversion method, communication parameters, and proof-required value from the on-board electronic device 11 (S607). Next, the random number generation unit 202 of the management device 21 generates a random number e as third generation information (S608). For example, the method of generating the random number e may use the random number generation function of the CPU 24 or a hardware random number generator connected via the input / output device 23, or may use another method or a combination of multiple methods. Then, the communication unit 201 of the management device 21 transmits the random number generated in step S608 to the on-board electronic device 11 via the network 30.
[0041] Next, the communication unit 101 of the on-board electronic device 11 obtains the random number e from the management device 21 (S609). Next, the proof value generation unit 106 of the on-board electronic device 11 generates the proof value z (S610). The proof value z is a value calculated using the communication parameter p generated in step S604, the random number r generated in step S605, and the random number e received in step S609, depending on the conversion method selected in step S603. For example, when using a discrete logarithm problem, the proof value may be calculated as z = r + ex mod p. Then, the communication unit 101 of the on-board electronic device 11 transmits the proof value z generated in step S610 to the management device 21 via the network 30.
[0042] Thereafter, the communication unit 201 of the management device 21 acquires the certification value z (S611). Next, the in-vehicle electronic device 11 ends the certification process (S612).
[0043] FIG. 7 is a flowchart showing an example of the verification process S502 performed by the on-board electronic device 11 and the management device 21 in the vehicle data certification system according to the embodiment of the present invention.
[0044] First, the management device 21 starts the verification process (S701). Next, the verification unit 203 of the management device 21 acquires the conversion method, communication parameters, proof-needed value, and proof value received from the on-board electronic device 11 (S702). Next, the verification unit 203 of the management device 21 acquires the random number e generated in step S608 (S703). Note that the processing order of steps S702 and S703 may be arbitrary.
[0045] Next, the verification unit 203 of the management device 21 generates a verification reference value (S704). The verification reference value is a value calculated using the communication parameters and the proof value according to the conversion method. For example, when the discrete logarithm problem is used, the verification reference value is calculated by g^z mod p using the proof value z and the communication parameters g and p.
[0046] Next, the verification unit 203 of the management device 21 generates a verification value (S705). The verification value is a value calculated using the communication parameters, the proof-to-proof value, and the generated random number depending on the conversion method. For example, when the discrete logarithm problem is used, the verification value is calculated by cy^e mod p using the proof-to-proof value c, the communication parameters y and p, and the generated random number e. Note that the processing order of steps S704 and S705 may be arbitrary.
[0047] Next, the verification result determination unit 204 of the management device 21 determines whether the verification reference value matches the verification value and the verification is successful, i.e., whether the verification formula g^z mod p = cy^e mod p holds (S706). If it is determined that the verification reference value matches the verification value, the verification result determination unit 204 of the management device 21 increments the pass counter by 1 (S707). The pass counter is initially set to zero and is reset to zero after the verification is confirmed. Next, the verification unit 203 of the management device 21 obtains the certification content importance from the importance storage unit 208 (S708). For example, the verification unit 203 searches the certification content importance in the certification information included in the conversion method received from the on-board electronic device 11, and obtains the category and rank to which the certification information corresponds as the certification content importance. Next, the verification unit 203 of the management device 21 obtains the certification count rule for the certification content from the certification count rule storage unit 209 (S709). For example, the certification count rule is searched for using the category and rank acquired in step S708, and the certification count corresponding to the certification content is acquired. The processing order of steps S708 and S709 may be arbitrary.
[0048] Next, the verification unit 203 of the management device 21 determines whether the value of the pass counter acquired in step S707 is equal to or greater than the number of certifications acquired in step S709 (S710). If it is determined that the value of the pass counter is equal to or greater than the number of certifications, it determines that the certification content is correct and confirms the certification content (S711). Next, the management device 21 ends the verification process (S712). The management device 21 may store the confirmed certification content in the storage device 26, notify the security monitoring device 28 of the certification content, or notify the on-board electronic device 11 of the certification content. In particular, if the verification result indicates that the certification content has been attacked from the outside, the verification unit 203 of the management device 21 notifies the security monitoring device 28 of the certification content. The security monitoring device 28 analyzes security threats based on the notification that an attack has been determined through vehicle data verification.
[0049] On the other hand, if it is determined in step S710 that the value of the pass counter is less than the number of certifications, the verification unit 203 of the management device 21 generates a re-certification request (S713). Then, the communication unit 201 of the management device 21 transmits the re-certification request to the on-board electronic device 11 via the network 30. Thereafter, the communication unit 101 of the on-board electronic device 11 receives the re-certification request (S718).
[0050] On the other hand, if it is determined in step S706 that the verification reference value and the verification value do not match, the verification unit 203 of the management device 21 increments the failure counter by one (S714). The failure counter is initialized to zero and is initialized again after the verification is confirmed. Next, the verification unit 203 of the management device 21 determines whether the value of the failure counter is equal to or greater than a predetermined threshold (S715). Here, the predetermined threshold may be a specific fixed value, or may be a value that varies depending on the proof content (e.g., the importance of the proof content or the proof count rule).
[0051] If it is determined that the value of the failure counter is equal to or greater than the predetermined threshold, the management device 21 outputs a notification (S716). The notification may be, for example, via the input / output device 23, to the user of the management device 21 by displaying a message on a display screen, to a Vehicle Security Operation Center (VSOC) department that monitors the security of the vehicle 10, to the on-board electronic device 11, or to the driver by displaying or sounding a message after notifying the on-board electronic device 11. Other methods may also be used, or a combination of multiple methods may also be used. Next, the management device 21 ends the verification process (S712).
[0052] On the other hand, if it is determined in step S715 that the value of the failure counter is less than the threshold, the verification unit 203 of the management device 21 generates a re-certification request (S717). Then, the communication unit 201 of the management device 21 transmits the re-certification request to the on-board electronic device 11 via the network 30. Thereafter, the on-board electronic device 11 receives the re-certification request (S718).
[0053] When the in-vehicle electronic device 11 receives the re-certification request, it executes the process again from step S601. At this time, it may skip steps S603 and S604 and use the same parameters and method as the previous time, or it may execute steps S603 and S604 again and use different parameters and method.
[0054] FIG. 8 is a diagram showing an example of a vehicle data selection screen 800 according to an embodiment of the present invention.
[0055] As described above, the necessity of re-certification is determined by the management device 21, but the user may also determine the necessity of re-certification. In the vehicle data certification system of this embodiment, the vehicle data selection screen 800 is used when the user selects vehicle data for which re-certification is requested at the management center 20.
[0056] The vehicle data selection screen 800 includes a user selection field 801, identification information 802, certification content 803, reception time 804, verification result 805, cumulative verification result 806, re-certification request button 807, verification result notification button 808, and update button 809.
[0057] The user can enter a check mark in the user selection field 801, select the recertification field, and select the certification content to be requested for recertification. Similarly, the notification field can be selected to select the cumulative verification results to be notified to the security officer or security department. The identification information 802 is information for identifying the sender of the certification content, such as a vehicle identification number (VIN) or the serial number of the on-board electronic device 11, but other identification information may also be used. The certification content 803 is information that the on-board electronic device 11 certifies to the management device 21, such as an ECU ID, an ECU identifier, a program ID, a program identifier, or a program version, but may also be other certification content or a combination of multiple certification content. The reception time 804 is information about the time the certification content was received from the on-board electronic device 11. For example, the reception time may be expressed in ISO 8601 format or another format. The verification result 805 indicates the verification result in step S706. For example, if the verification reference value in step S706 matches the verification value, OK is displayed, and if they do not match, NG is displayed. The cumulative verification result 806 displays the determination result in steps S710 and S715 as to whether the counter value is equal to or greater than the proof count rule or a threshold value. For example, if the pass counter is equal to or greater than the proof count rule, OK is displayed; if it is equal to or greater than the threshold value, NG is displayed; if it is less than the proof count rule or the fail counter is less than the threshold value, "Determining" is displayed; however, other display modes may also be used.
[0058] The re-certification request button 807 is a button that is operated, upon receiving a user operation, to issue a re-certification request to the in-vehicle electronic device 11 for the certification content that has a check mark in the re-certification column of the user selection column 801. The verification result notification button 808 is a button that is operated, upon receiving a user operation, to notify a security officer or security department of the verification result or cumulative verification result for the certification content that has a check mark in the notification column of the user selection column 801. The update button 809 is a button that is operated to add and display the verification result or cumulative verification result on the vehicle data selection screen 800 when the certification content has been received from the in-vehicle electronic device 11 or when the verification result or cumulative verification result has been obtained. Note that the display on the vehicle data selection screen 800 may be updated when the update button 809 is operated, or may be updated automatically on a regular basis, or a combination of these methods.
[0059] The configuration of the vehicle data selection screen 800 is not limited to the above, and other display items and other buttons may be added, or some display items or buttons may be omitted. Furthermore, the display items may be displayed in an order other than that described above.
[0060] 9A and 9B are diagrams showing an example of the configuration of certification count rule information stored in the management device 21 in the vehicle data certification system according to the embodiment of the present invention.
[0061] In the certification count rule 900 shown in Figure 9A, the certification count is determined by a matrix in which categories are defined in the column direction and ranks are defined in the row direction. For example, the categories are Safety 902, Financial 903, Operation 904, and Privacy 905, and there are four ranks, but other items and other ranks may be defined, and some items or ranks may be omitted. In the certification count rule 900 shown in Figure 9A, the certification count for vehicle data belonging to Rank 3 of the category Operation 904 is determined to be five times.
[0062] In the proof count rule 906 shown in Fig. 9B, the proof count is determined corresponding to the category in the column direction. For example, the categories are QM 907, ASIL A 908, ASIL B 909, ASIL C 910, and ASIL D 911. In the proof count rule 906 shown in Fig. 9B, the proof count for vehicle data belonging to ASIL B is determined to be three times.
[0063] The proof count rule may have a configuration other than those described above, or a combination of these. Also, the components of the proof count rule may be determined in an order other than that described above.
[0064] 10A and 10B are diagrams showing examples of the configuration of certification content importance information stored in the management device 21 in the vehicle data certification system according to the embodiment of the present invention.
[0065] The certification content importance information 1000 shown in FIG. 10A includes certification information 1001, a category 1002, and a rank 1003. The certification information 1001 describes information assets held by the in-vehicle electronic device 11. For example, the information assets may be an ECU ID, identification information of the in-vehicle electronic device, a software ID, a software version, a software identifier, a hardware ID, a hardware version, or a hardware identifier, or other information may be described. The category 1002 is category information indicating the attributes of the certification information 1001. For example, the category may be Safety, Financial, Operation, Privacy, or other category information may be described. The rank 1003 is rank information for the category 1002 to which the certification information 1001 belongs. For example, the rank may be four levels or any number of levels.
[0066] As another example of a category, there is a category including a rank, such as QM, ASIL A, ASIL B, ASIL C, and ASIL D shown in Fig. 10B. In the case of a category including a rank, the rank 1003 may be left blank, or, like certification content importance information 1004 shown in Fig. 10B, the category may include certification information 1001 and category 1002 without including a rank.
[0067] The certification content importance information may have a configuration other than that described above, and the components may be listed in an order other than that described above.
[0068] 11 is a flowchart showing an example of the certification process S501 executed by the on-board electronic device 11 and the management device 21 in the vehicle data certification system according to the embodiment of the present invention. The process shown in FIG. 11 is the certification process S501 executed when the vehicle 10 is temporarily unable to connect to the network 30, for example, when the vehicle 10 is underground or in a tunnel, and is therefore unable to receive a random number from the management device 21.
[0069] First, the on-board electronic device 11 starts the certification process (S1101). Next, the on-board electronic device 11 acquires the certification target (S1102). For example, the on-board electronic device 11 acquires information to be certified to the management device 21 from the on-board storage unit 107. The information to be certified may be, for example, an ECU ID, an ECU serial number, a software ID, a software identifier, or a software version, but may also be other information or any combination of these pieces of information.
[0070] Next, the certification target selection unit 102 of the in-vehicle electronic device 11 obtains a conversion method for the information to be certified from the conversion method storage unit 108 (S1103). The conversion method is a method for converting the information to be certified into a mathematical expression. For example, there is a method in which the information to be certified, such as an ECU ID, is expressed in decimal x and the answer x to the discrete logarithm problem y = g^x mod p is known. g^x indicates multiplication by an integer g x times, and mod p indicates calculation of the remainder when divided by the integer p. Note that the conversion method is not limited to the exemplified method, and other methods may be used.
[0071] Next, the communication parameter generation unit 103 of the in-vehicle electronic device 11 generates communication parameters (S1104). The communication parameters are parameters used for the conversion method selected in step S1103. For example, when the discrete logarithm problem is used as the conversion method, the communication parameters are a prime number p and positive integers g, y, and q, where g, y, and q satisfy y = g^x mod p and g^q = 1 mod p. Furthermore, for example, the communication parameters may be generated by inputting a random number generated by a random number generation function of the secure device 18 to a prime number determination algorithm and using a value determined to be prime as the prime number p, or by using calculation results output by a modular multiplication calculation function of the secure device 18 as the integers y and q, or by a combination of multiple methods.
[0072] Next, the random number generation unit 104 of the on-board electronic device 11 generates a random number r (S1105). For example, the random number generation method may use the random number generation function of the secure device 18, but other methods may also be used. Next, the proof-needed value generation unit 105 of the on-board electronic device 11 generates a proof-needed value (S1106). The proof-needed value is a value calculated using the communication parameters g and p generated in step S1104 and the random number r generated in S1105, depending on the conversion method selected in step S1103. For example, when the discrete logarithm problem is used, the proof-needed value is calculated as c = g^r mod p.
[0073] Next, the communication unit 101 of the in-vehicle electronic device 11 acquires a random number from the management device 21 (S1107).
[0074] Next, the on-board electronic device 11 acquires a random number e (S1107). The random number e acquired in step S1107 is a different value from the random number r generated in step S1105. Alternative information not generated by the management device 21 may be used for the random number r. For example, the random number e may be acquired using location information, sensor information, or a counter value included in a communication packet that the on-board electronic device 11 receives from another on-board electronic device via the on-board network 12, or a value obtained by compressing or converting the value generated in steps S1102 to S1107 using a hash function or the like. However, the random number e may be generated by other methods, or by a combination of these methods.
[0075] Next, the proof value generation unit 106 of the in-vehicle electronic device 11 generates a proof value z (S1108). The proof value is a value calculated using the communication parameter p generated in step S1104, the random number r generated in step S1105, and the random number e generated in step S1107 in accordance with the conversion method selected in step S1103. For example, when a discrete logarithm problem is used, the proof value may be calculated as z = r + ex mod p.
[0076] Then, the in-vehicle electronic device 11 waits until it is able to communicate with the management device 21 via the network 30, and after it is able to communicate, it transmits the conversion method acquired in step S1103, the communication parameters created in step S1104, the proof-required value generated in step S1106, the random number acquired in step S1107, and the proof value generated in step S1108 from the communication unit 101 to the management device 21 via the network 30.
[0077] Next, the communication unit 201 of the management device 21 acquires the conversion method, the communication parameters, the certification-required value, the random number, and the certification value (S1109). Next, the on-board electronic device 11 ends the certification process (S1110).
[0078] These configurations, procedures, and data structures make it possible to provide a vehicle data attestation system that proves its own legitimacy to the management device 21 installed outside the vehicle, without increasing the number of private keys stored in the onboard electronic device 11. The onboard electronic device 11 and the management device 21 share disposable and publicly available communication parameters, and the onboard electronic device 11 can prove to the management device 21 that it holds legitimate devices and programs using a zero-knowledge proof protocol, without having a key or transmitting identification information in plain text. Furthermore, the management device 21 can improve the proof accuracy according to the importance of the proof content by performing a re-proof determination process regardless of whether the proof result is successful, and can determine the possibility of a spoofing attack.
[0079] The present invention is not limited to the above-described embodiments, and includes various modifications and equivalent configurations within the spirit and scope of the appended claims. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to configurations including all of the described configurations. Furthermore, part of the configuration of one embodiment may be replaced with the configuration of another embodiment. Furthermore, the configuration of another embodiment may be added to the configuration of one embodiment. Furthermore, part of the configuration of each embodiment may be added, deleted, or replaced with other configurations.
[0080] Specifically, the management device 21 may be configured from a plurality of computers connected via a network within the management center 20 .
[0081] Furthermore, when a plurality of on-board electronic devices are hierarchically structured in a vehicle, the on-board electronic device in the highest layer may receive certification data from an on-board electronic device in a lower layer, execute certification processing, and transmit the result of the certification processing S501 (certification value z) from the communication unit 101 to the management device 21. Alternatively, the on-board electronic device 11 may execute the certification processing, and the communication unit 101 of the on-board electronic device 11 in the highest layer may transmit the result of the certification processing S501 (certification value z) to the management device 21.
[0082] Furthermore, the vehicle 10 and the management device 21 may be connected via a wireless communication network, or may be connected via a wired communication network in a maintenance yard or factory.
[0083] The on-board electronic device 11 may perform certification and verification processes on each piece of information to be certified, such as an ECU ID, an ECU serial number, a software ID, a software version, a software identifier, a hardware ID, a hardware version, or a hardware identifier, or may link multiple pieces of information to be certified and perform certification and verification processes on the linked pieces of information as a single piece of certification information. Furthermore, multiple pieces of information from different on-board electronic devices may be linked and treated as a single piece of certification information for certification and verification processes. These methods may also be combined.
[0084] Furthermore, when the management device 21 receives multiple proof-need values c, steps S607 and S608 may be repeated multiple times, or step S607 may be repeated multiple times followed by step S608. Furthermore, these methods may be combined.
[0085] The trigger for the on-board electronic device 11 to execute the certification process may be when power supply starts by turning on the IG, or after a certain time has elapsed since the previous certification process and verification process were completed, or before or after the software update process is executed, or when a request for re-certification is received from the management device 21. These methods may also be combined.
[0086] In addition, the in-vehicle electronic device may use a cryptographic accelerator other than an HSM to create communication parameters, random numbers, proof-required values, and proof values used in the certification process, or may create these values in combination with an HSM.
[0087] As described above, according to the embodiment of the present invention, the on-board electronic device 11 and the management device 21 outside the vehicle share disposable and publicly accessible communication parameters, and the on-board electronic device 11 can prove to the management device 21 that it possesses a legitimate device or program using a zero-knowledge proof protocol without having a key or transmitting identification information in plaintext. This prevents the on-board electronic device 11 from increasing its secret information storage capacity, thereby minimizing the strain on the storage capacity of the secure memory used to store the secret information. Furthermore, even if the on-board electronic device 11 becomes more multifunctional, the key management load on the management device 21 does not increase. Furthermore, the management device 21 can request re-certification regardless of whether the certification result is successful, thereby improving the certification accuracy according to the importance of the certification content and making it possible to determine the possibility of a spoofing attack.
[0088] Furthermore, the aforementioned configurations, functions, processing units, processing means, etc. may be realized in part or in whole in hardware, for example by designing them as integrated circuits, or may be realized in software by having a processor interpret and execute a program that realizes each function.
[0089] Information such as programs, tables, and files that realize each function can be stored in a storage device such as a memory, hard disk, or SSD (Solid State Drive), or in a recording medium such as an IC card, SD card, or DVD.
[0090] In addition, the control lines and information lines shown are those that are considered necessary for explanation, and do not necessarily represent all the control lines and information lines that are necessary for implementation. In reality, it can be assumed that almost all components are interconnected.
Claims
1. A vehicle data certification method executed by a vehicle data certification system, the vehicle data certification system having an on-board electronic device and an off-vehicle management device connected to the on-board electronic device via a network, the vehicle data certification method comprising: the on-board electronic device transmitting to the off-vehicle management device a conversion method for converting secret information held by the on-board electronic device into other information, communication parameters used in the conversion method, and second generated information generated using first generated information generated by the on-board electronic device; the on-board electronic device acquiring third generated information generated by the off-vehicle management device; the on-board electronic device generating a proof value using the first generated information, the third generated information, and the communication parameters in accordance with the conversion method; and transmitting proof information required for a zero-knowledge proof protocol, including the generated proof value, to the off-vehicle management device.
2. A vehicle data certification method as described in claim 1, wherein, when the on-board electronic device is unable to acquire the third generated information, it acquires alternative information not generated by the off-vehicle management device, and generates a certification value using the first generated information, the acquired alternative information, and the communication parameters in accordance with the conversion method.
3. A vehicle data certification method according to claim 1 or 2, wherein the external management device executes a verification process using the received certification information to verify whether a verification formula based on the conversion method holds.
4. A vehicle data certification method according to claim 3, wherein the external management device determines whether to request recertification after the verification process depending on the importance of the certification content or the number of successful verifications.
5. A vehicle data certification method according to claim 3, wherein the external management device notifies a security monitoring device when it determines that an attack has occurred in the verification process.
6. An on-vehicle electronic device connected to an off-vehicle management device via a network, comprising: a conversion method for converting secret information held by the on-vehicle electronic device into other information; and a communication unit for transmitting to the off-vehicle management device communication parameters used in the conversion method and second generated information generated using first generated information generated by the on-vehicle electronic device, and acquiring third generated information generated by the off-vehicle management device, wherein the communication unit transmits to the off-vehicle management device proof information required for a zero-knowledge proof protocol, the proof value being generated using the first generated information, the third generated information, and the communication parameters in accordance with the conversion method.
7. An on-board electronic device as described in claim 6, wherein, if the third generated information cannot be acquired, the on-board electronic device acquires alternative information not generated by the off-vehicle management device, and generates a certification value using the first generated information, the acquired alternative information, and the communication parameters in accordance with the conversion method.
8. A vehicle data certification system comprising an on-board electronic device according to claim 6 or 7 and an off-vehicle management device connected to the on-board electronic device via a network, wherein the off-vehicle management device executes a verification process using received certification information to verify whether a verification formula based on the conversion method holds.
9. A vehicle data certification system according to claim 8, wherein the external management device determines whether to request recertification after the verification process depending on the importance of the certification content or the number of successful verifications.
10. A vehicle data certification system according to claim 8, wherein the external management device notifies a security monitoring device when it determines that an attack has occurred in the verification process.
11. A vehicle data certification system as described in claim 8, wherein the communication unit, when triggered by satisfaction of a predetermined condition, repeatedly executes a process of transmitting to the external management device proof information required for a zero-knowledge proof protocol, the proof information including a proof value generated using the first generation information, the third generation information, and the communication parameters in accordance with the conversion method.
Citation Information
Patent Citations
Authentication method and system based on elliptic curve
JP1996160857A
User authenticating method, storage medium, device and system
JP2001308851A