On-vehicle device, relay device, on-vehicle communication system, encrypted communication program, and relay program
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- AUTONETWORKS TECH LTD
- Filing Date
- 2026-01-08
- Publication Date
- 2026-08-06
Smart Images

Figure JP2026000392_06082026_PF_FP_ABST
Abstract
Description
Vehicle-mounted device, relay device, vehicle-mounted communication system, encryption communication program, and relay program
[0001] The present disclosure relates to a vehicle-mounted device, a relay device, a vehicle-mounted communication system, an encryption communication program, and a relay program. This application claims priority based on Japanese Patent Application No. 2025-12359 filed on January 28, 2025, and incorporates all of the disclosures thereof herein.
[0002] Patent Document 1 (Japanese Unexamined Patent Application Publication No. 2018-64142) discloses the following technology. That is, an edge server is an edge server disposed between a cloud and a terminal that requests services from the cloud, and when encryption key information generated prior to the request for a terminal that requests connection to the edge server is included in shared information shared by the cloud and at least one other edge server, a control unit that starts encrypted communication with the terminal using the encryption key information is included.
[0003] Japanese Unexamined Patent Application Publication No. 2018-64142
[0004] The vehicle-mounted device of the present disclosure is a vehicle-mounted device that is mounted on a vehicle and performs a key generation process for generating and distributing key information used in encrypted communication, including a key generation unit that generates first key information, which is the key information used by the vehicle-mounted device itself in the encrypted communication, an acquisition unit that acquires key generation information used by another device, which is another vehicle-mounted device that performs the key generation process, in the key generation process, a monitoring unit that monitors the state of the other device, and a determination unit that determines the state monitored by the monitoring unit. When the determination unit determines that the state is abnormal, the key generation unit performs a key complementation process for generating second key information, which is the key information used by the other device in the encrypted communication, based on the key generation information acquired by the acquisition unit, and the key generation unit distributes the generated second key information to the other device.
[0005] One aspect of this disclosure can be realized not only as an in-vehicle device equipped with such characteristic processing units, but also as a semiconductor integrated circuit that realizes part or all of the in-vehicle device, or as a system including the in-vehicle device.
[0006] Figure 1 is a diagram showing an example of the configuration of an in-vehicle communication system according to an embodiment of the present disclosure. Figure 2 is a diagram illustrating an example of encrypted communication in an in-vehicle communication system according to an embodiment of the present disclosure. Figure 3 is a diagram illustrating another example of encrypted communication in an in-vehicle communication system according to an embodiment of the present disclosure. Figure 4 is a diagram showing an example of the sequence of encrypted communication in an in-vehicle communication system according to an embodiment of the present disclosure. Figure 5 is a diagram illustrating key completion processing in an in-vehicle communication system according to an embodiment of the present disclosure. Figure 6 is a diagram showing an example of the configuration of an in-vehicle relay device according to an embodiment of the present disclosure. Figure 7 is a diagram showing an example of the configuration of a central device according to an embodiment of the present disclosure. Figure 8 is a diagram showing another example of the configuration of an in-vehicle relay device according to an embodiment of the present disclosure. Figure 9 is a flowchart defining an example of the operation procedure when an in-vehicle relay device according to an embodiment of the present disclosure performs state information transmission processing. Figure 10 is a flowchart defining an example of the operation procedure when a central device according to an embodiment of the present disclosure performs relay processing. Figure 11 is a flowchart defining an example of the operation procedure when an in-vehicle relay device according to an embodiment of the present disclosure performs key completion processing. Figure 12 shows an example of the processing sequence of an in-vehicle relay device, a central device, and an end ECU in an in-vehicle communication system according to an embodiment of the present disclosure. Figure 13 shows an example of the processing sequence of an in-vehicle relay device, a central device, and an end ECU in an in-vehicle communication system according to an embodiment of the present disclosure.
[0007] Traditionally, technologies have been developed to shorten the time it takes for a client to initiate encrypted communication with a server.
[0008] [Problems this disclosure aims to solve] In an in-vehicle network, an in-vehicle device acting as a client may perform encrypted communication with an in-vehicle device acting as a server. In this case, the in-vehicle device acting as a server distributes key information used for encrypted communication to the in-vehicle device acting as a client. If an abnormality occurs in the operation related to encrypted communication in the in-vehicle device acting as a server, the encrypted communication may fail.
[0009] This disclosure was made to solve the above-mentioned problems, and its purpose is to provide an in-vehicle device, a relay device, an in-vehicle communication system, an encrypted communication program, and a relay program that can prevent failures in encrypted communication between in-vehicle devices.
[0010] [Effects of this disclosure] According to this disclosure, it is possible to prevent failures in encrypted communication between in-vehicle devices.
[0011] [Description of Embodiments of the Disclosure] First, the contents of the embodiments of the Disclosure will be listed and described. (1) An in-vehicle device according to an embodiment of the Disclosure is an in-vehicle device mounted in a vehicle that performs key generation processing to generate and distribute key information used in encrypted communication, comprising: a key generation unit that generates first key information which is the key information used in encrypted communication by the device itself, which is the in-vehicle device; an acquisition unit that acquires key generation information used by the other device in the key generation processing from another device which is another in-vehicle device that performs the key generation processing; a monitoring unit that monitors the state of the other device; and a determination unit that determines the state monitored by the monitoring unit, wherein if the determination unit determines that the state is abnormal, the key generation unit performs key completion processing to generate second key information which is the key information used by the other device in encrypted communication based on the key generation information acquired by the acquisition unit, and the key generation unit distributes the generated second key information to the other device.
[0012] With this configuration, if the state of another in-vehicle device performing key generation processing is abnormal, the system can generate and distribute the key information used by that other in-vehicle device in encrypted communication on its behalf. Therefore, it is possible to prevent failures in encrypted communication between in-vehicle devices.
[0013] (2) In (1) above, the in-vehicle device may further include a storage unit for storing a third key information in accordance with the MACsec standard, which is used to generate the second key information, and the key generation unit may perform the key completion processing based on the third key information stored in the storage unit.
[0014] For example, the MACsec (Media Access Control Security) standard stipulates that key information used in encrypted communication is generated using a pre-shared key that is shared in advance between in-vehicle devices performing encrypted communication. If the in-vehicle device that is sending the key generation information is in an abnormal state, it may not be possible to generate a common key using the pre-shared key. With the above configuration, the in-vehicle device that is sending the key generation information can more reliably generate the key information used in encrypted communication using the pre-shared key that it holds.
[0015] (3) In (1) or (2) above, the in-vehicle network of the vehicle may be configured with a first group including the own device and the in-vehicle device to which the first key information is distributed, and a second group including the other device and the in-vehicle device to which the second key information is distributed, and the key generation information may include a first identification information for identifying the other device and a second identification information for identifying the in-vehicle device to which the second key information is distributed, which is included in the second group.
[0016] With this configuration, the recipient of the key information generated in place of other in-vehicle devices that are in an abnormal state can be easily identified using the identification information contained in the acquired key generation information.
[0017] (4) In any of (1) to (3) above, a plurality of key completion devices, which are in-vehicle devices capable of performing the key completion process, may be provided in the vehicle's in-vehicle network, and each of the plurality of key completion devices may be assigned a priority for the key completion process, and the key generation unit may perform the key completion process if the priority of its own device is higher than the priority of each of the other key completion devices.
[0018] With this configuration, if there are multiple key completion devices capable of performing key completion processing in an in-vehicle network, it is possible to easily determine whether or not to perform key completion processing in the device itself by comparing the priority for key completion processing set in the device with the priority set in each of the other key completion devices.
[0019] (5) In (4) above, the key generation information may include priority information indicating the priority of each key completion device, and the key generation unit may decide whether or not to perform the key completion process based on the priority information included in the key generation information.
[0020] With this configuration, by referring to the priority information contained in the key generation information, it is possible to easily check the priority for key completion processing set in the device itself, as well as the priority set in each other key completion device.
[0021] (6) An in-vehicle device according to an embodiment of the present disclosure is an in-vehicle device that performs key generation processing for generating and distributing key information used in encrypted communication, comprising: a monitoring unit that monitors the status of the in-vehicle device itself; a communication unit that transmits information indicating the status monitored by the monitoring unit and information used in the key generation processing to another in-vehicle device that performs the key generation processing; and a key receiving unit that uses the key information received from the other in-vehicle device in the encrypted communication.
[0022] With this configuration, for example, if the state of the device is abnormal, information indicating the monitoring result of that state and information used by the device in the key generation process can be transmitted to other in-vehicle devices that perform key generation processing, thereby causing those other in-vehicle devices to generate and distribute key information. Therefore, failures in encrypted communication between in-vehicle devices can be prevented.
[0023] (7) The relay device according to the embodiment of the present disclosure is a relay device used in an in-vehicle network including a first in-vehicle device and a second in-vehicle device that performs key generation processing for generating and distributing key information used in encrypted communication, and comprises a relay unit that relays information transmitted and received between the first in-vehicle device and the second in-vehicle device, the relay unit receiving from the first in-vehicle device state information which is information indicating the state of the first in-vehicle device and key generation information which is information used by the first in-vehicle device in the key generation processing, and relaying the received state information and key generation information to the second in-vehicle device, the relay unit receiving from the second in-vehicle device supplementary key information which is key information used by the first in-vehicle device in the encrypted communication generated by the second in-vehicle device, and relaying the received supplementary key information to the first in-vehicle device.
[0024] In this configuration, the status information and key generation information of the first in-vehicle device are relayed to the second in-vehicle device. This allows the second in-vehicle device to monitor the status of the first in-vehicle device, and if the status of the first in-vehicle device is abnormal, it can generate the key information used by the first in-vehicle device for encrypted communication on behalf of the first in-vehicle device. Furthermore, by relaying the key information generated by the second in-vehicle device to the first in-vehicle device, the first in-vehicle device can more reliably perform encrypted communication using this key information. Therefore, failures in encrypted communication between in-vehicle devices can be prevented.
[0025] (8) An in-vehicle communication system according to an embodiment of the present disclosure comprises a first in-vehicle device and a second in-vehicle device that perform key generation processing for generating and distributing key information used in encrypted communication, and a relay device, wherein the first in-vehicle device monitors its own state and transmits state information indicating the monitored state and key generation information used in the key generation processing to the relay device, the relay device relays the state information and key generation information received from the first in-vehicle device to the second in-vehicle device, and the second in-vehicle device receives the Based on the status information, the status is determined, and if the second in-vehicle device determines that the status is abnormal, it generates supplemental key information, which is the key information used by the first in-vehicle device in the encrypted communication, based on the key generation information received from the relay device, the second in-vehicle device transmits the generated supplemental key information to the relay device, the relay device relays the supplemental key information received from the second in-vehicle device to the first in-vehicle device, and the first in-vehicle device uses the supplemental key information received from the relay device in the encrypted communication.
[0026] With this configuration, if the state of the first in-vehicle device is abnormal, the second in-vehicle device can generate and distribute the key information used by the first in-vehicle device in encrypted communication on behalf of the first in-vehicle device. Therefore, failures in encrypted communication between in-vehicle devices can be prevented.
[0027] (9) An encryption communication program according to an embodiment of the present disclosure is an encryption communication program used in an in-vehicle device that is mounted in a vehicle and performs key generation processing to generate and distribute key information used in encrypted communication, and is a program that causes a computer to function as: a key generation unit that generates first key information which is the key information used by the device, which is the in-vehicle device, in encrypted communication; an acquisition unit that acquires key generation information used by the other device in the key generation processing from another device, which is another in-vehicle device that performs the key generation processing; a monitoring unit that monitors the state of the other device; and a determination unit that determines the state monitored by the monitoring unit, wherein if the determination unit determines that the state is abnormal, the key generation unit performs key completion processing to generate second key information which is the key information used by the other device in encrypted communication based on the key generation information acquired by the acquisition unit, and the key generation unit distributes the generated second key information to the other device.
[0028] With this configuration, if the state of another in-vehicle device performing key generation processing is abnormal, the system can generate and distribute the key information used by that other in-vehicle device in encrypted communication on its behalf. Therefore, it is possible to prevent failures in encrypted communication between in-vehicle devices.
[0029] (10) An encryption communication program according to an embodiment of the present disclosure is an encryption communication program used in an in-vehicle device that performs key generation processing to generate and distribute key information used in encrypted communication, and is a program that causes a computer to function as a monitoring unit that monitors the status of its own in-vehicle device, a communication unit that transmits information indicating the status monitored by the monitoring unit and information used in the key generation processing to another in-vehicle device that performs the key generation processing, and a key receiving unit that uses the key information received from the other in-vehicle device in the encrypted communication.
[0030] With this configuration, for example, if the state of the device is abnormal, information indicating the monitoring result of that state and information used by the device in the key generation process can be transmitted to other in-vehicle devices that perform key generation processing, thereby causing those other in-vehicle devices to generate and distribute key information. Therefore, failures in encrypted communication between in-vehicle devices can be prevented.
[0031] (11) The relay program according to the embodiment of the present disclosure is a relay program used in a relay device used in an in-vehicle network including a first in-vehicle device and a second in-vehicle device that performs a key generation process for generating and distributing key information used in encrypted communication, and is a program for causing a computer to function as a relay unit that relays information transmitted and received between the first in-vehicle device and the second in-vehicle device, wherein the relay unit receives from the first in-vehicle device state information which is information indicating the state of the first in-vehicle device and key generation information which is information used by the first in-vehicle device in the key generation process, and relays the received state information and key generation information to the second in-vehicle device, and the relay unit receives from the second in-vehicle device supplementary key information which is key information used by the first in-vehicle device in encrypted communication generated by the second in-vehicle device, and relays the received supplementary key information to the first in-vehicle device.
[0032] In this configuration, the status information and key generation information of the first in-vehicle device are relayed to the second in-vehicle device. This allows the second in-vehicle device to monitor the status of the first in-vehicle device, and if the status of the first in-vehicle device is abnormal, it can generate the key information used by the first in-vehicle device for encrypted communication on behalf of the first in-vehicle device. Furthermore, by relaying the key information generated by the second in-vehicle device to the first in-vehicle device, the first in-vehicle device can more reliably perform encrypted communication using this key information. Therefore, failures in encrypted communication between in-vehicle devices can be prevented.
[0033] Embodiments of this disclosure will be described below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals, and their descriptions will not be repeated. Furthermore, at least some of the embodiments described below may be combined in any way.
[0034] [In-vehicle communication system] Figure 1 is a diagram showing an example of the configuration of an in-vehicle communication system according to an embodiment of the present disclosure. Referring to Figure 1, the in-vehicle communication system 301 comprises a central unit 101, a plurality of in-vehicle relay devices 201, and a plurality of end ECUs (Electronic Control Units) 251. The in-vehicle communication system 301 is mounted on a vehicle 1. The central unit 101 is an example of a relay device.
[0035] The in-vehicle communication system 301 comprises a plurality of in-vehicle relay devices 201, namely in-vehicle relay devices 201A, 201B, and 201C, and a plurality of end ECUs 251, namely end ECUs 251A, 251B, 251C, 251D, and 251E. In-vehicle relay device 201A is an example of a first in-vehicle device. In-vehicle relay devices 201B and 201C are examples of a second in-vehicle device.
[0036] The central unit 101, multiple in-vehicle relay devices 201, and multiple end ECUs 251 constitute an in-vehicle network 401.
[0037] For example, the in-vehicle relay device 201 is connected to the central device 101 via an Ethernet cable 51.
[0038] The end ECU 251 is connected to the in-vehicle relay device 201 via an Ethernet cable 51.
[0039] In the example shown in Figure 1, end ECUs 251A and 251B are connected to the in-vehicle relay device 201A via Ethernet cable 51. End ECUs 251C and 251D are connected to the in-vehicle relay device 201B via Ethernet cable 51. End ECU 251E is connected to the in-vehicle relay device 201C via Ethernet cable 51.
[0040] Note that the number of end ECUs 251 connected to in-vehicle relay device 201A or in-vehicle relay device 201B is not limited to two, and may be one or three or more. Also, the number of end ECUs 251 connected to in-vehicle relay device 201C is not limited to one, and may be two or more.
[0041] Also, in-vehicle communication system 301 is not limited to a configuration including three in-vehicle relay devices 201, and may be a configuration including two or four or more in-vehicle relay devices 201.
[0042] [Encrypted Communication] In in-vehicle communication system 301, in-vehicle relay device 201 and central device 101, and in-vehicle relay device 201 and end ECU 251 perform encrypted communication in accordance with the MACsec standard defined in, for example, IEEE802.1AE and IEEE802.1X.
[0043] In-vehicle relay device 201 and central device 101, and in-vehicle relay device 201 and end ECU 251 transmit frames including various information through encrypted communication based on key information. The key information is, for example, a common key SAK (Secure Association Key).
[0044] In-vehicle relay device 201 performs a key generation process Ka for generating and distributing the common key SAK used in encrypted communication. More specifically, for example, in-vehicle relay device 201 distributes the generated common key SAK to central device 101 and end ECU 251 connected to itself. [[ID=十四]]
[0045] Central device 101 and end ECU 251 perform a key reception process Kb for receiving the common key SAK from in-vehicle relay device 201. Central device 101 and end ECU 251 perform encrypted communication using the received common key SAK1.
[0046] For example, in the in-vehicle network 401, a plurality of groups G are configured, each including an in-vehicle relay device 201 that performs key generation processing Ka, and a central device 101 and end ECUs 251 that perform key reception processing Kb. That is, the group G includes an in-vehicle relay device 201 that generates and distributes a common key SAK, and the central device 101 and end ECUs 251 that are the distribution destinations of the common key SAK. Hereinafter, the central device 101 and the end ECUs 251 belonging to a certain group G are collectively referred to as key reception devices as well.
[0047] More specifically, for example, in the in-vehicle network 401, a plurality of groups G are configured according to predetermined conditions defined in the specifications of AUTOSAR (AUTomotive Open System ARChitecture) (registered trademark) or specifications such as IEEE802.1AE. Specifically, the conditions include configuring the group G by a device that communicates according to the communication standard of Ethernet, and configuring the group G by a plurality of devices that are time synchronized.
[0048] In the example shown in FIG. 1, in the in-vehicle network 401, groups G1, G2, and G3, which are a plurality of groups G, are configured. The group G1 includes an in-vehicle relay device 201A, a central device 101, and end ECUs 251A and 251B. The group G2 includes an in-vehicle relay device 201B, a central device 101, and end ECUs 251C and 251D. The group G3 includes an in-vehicle relay device 201C, a central device 101, and an end ECU 251E. The group G1 is an example of the second group, and the groups G2 and G3 are examples of the first group.
[0049] In the in-vehicle network 401, the common key SAK used in the encrypted communication in a certain group G is different from the common key SAK used in the encrypted communication in other groups G. That is, the common key SAK generated by the in-vehicle relay device 201 belonging to a certain group G is different from the common key SAK generated by the in-vehicle relay device 201 belonging to other groups G.
[0050] A key receiving device belonging to a certain group G holds confidential information that is shared in advance with an in-vehicle relay device 201 belonging to the same group G. This confidential information is, for example, a pre-shared key (PSK). The pre-shared key (PSK) is key information used to generate a common key (SAK), and to encrypt and decrypt the common key (SAK), etc. The pre-shared key (PSK) of each group G is registered, for example, in the storage units of the in-vehicle relay device 201 and the key receiving device in the group G by the manufacturer of the vehicle 1 when the vehicle 1 is shipped. The pre-shared key (PSK) is an example of a third type of key information.
[0051] The key receiving device decrypts the shared key received from the in-vehicle relay device 201 based on the pre-shared key (PSK) it holds. The key receiving device then uses the decrypted shared key to perform encrypted communication.
[0052] Hereinafter, the pre-shared keys (PSKs) of groups G1, G2, and G3 will also be referred to as pre-shared keys PSK1, PSK2, and PSK3, respectively.
[0053] For example, the end ECU 251 transmits frame F1, which contains various information such as information to assist in the automated driving performed by vehicle 1 and information used for entertainment, to a device belonging to the same group G as itself. Alternatively, for example, the end ECU 251 may transmit frame F1 to a device belonging to a different group G than the group G to which it belongs. Hereinafter, the various information contained in frame F1 will also be referred to as device information.
[0054] For example, when the in-vehicle relay device 201 receives a frame F1 from an end ECU 251 belonging to the same group as itself, it performs predetermined processing based on the equipment information contained in the received frame F1. Also, for example, when the in-vehicle relay device 201 receives a frame F1 from an end ECU 251 destined for an equipment belonging to a different group G than the group G to which it belongs, it transmits the received frame F1 to the central device 101.
[0055] The central device 101 transmits the frame F1 received from the in-vehicle relay device 201 to the in-vehicle relay device 201 of the group G to which the destination device of frame F1 belongs.
[0056] Specifically, for example, when the central device 101 receives frame F1 from the in-vehicle relay device 201, it decrypts frame F1 using the common key SAK of the group G to which the in-vehicle relay device 201 belongs. Then, the central device 101 encrypts the decrypted frame F1 using the common key SAK of the group G to which the destination device of frame F1 belongs, and transmits it to the destination device.
[0057] Furthermore, for example, the central device 101 creates a frame F2 containing various information and destined for the end ECU 251. The central device 101 then transmits the created frame F2 to the in-vehicle relay device 201 of group G to which the end ECU 251 belongs.
[0058] Figure 2 is a diagram illustrating an example of encrypted communication in an in-vehicle communication system according to an embodiment of the present disclosure. Figure 2 shows a case in which the central device 101 performs encrypted communication using a common key SAK distributed from the in-vehicle relay device 201.
[0059] Referring to Figure 2, for example, the central device 101 encrypts the created frame F2 using the common key SAK received from the in-vehicle relay device 201. Then, the central device 101 transmits the encrypted frame F2 to the in-vehicle relay device 201.
[0060] When the in-vehicle relay device 201 receives the encrypted frame F2 from the central device 101, it transmits the frame F2 to the end ECU 251.
[0061] Figure 3 illustrates another example of encrypted communication in an in-vehicle communication system according to an embodiment of the present disclosure. Figure 3 shows a case where the end ECU 251 performs encrypted communication using a common key SAK distributed from the in-vehicle relay device 201.
[0062] Referring to Figure 3, for example, the end ECU 251 encrypts a frame F1 destined for a device belonging to a different group G than the one to which it belongs, using the common key SAK received from the in-vehicle relay device 201. Then, the end ECU 251 transmits the encrypted frame F1 to the in-vehicle relay device 201.
[0063] When the in-vehicle relay device 201 receives the encrypted frame F1 from the end ECU 251, it transmits the frame F1 to the central device 101.
[0064] Referring to Figures 2 and 3, for example, each of the central unit 101, the in-vehicle relay unit 201, and the end ECU 251 has a priority A2 set for the key generation process Ka in accordance with MACsec standards.
[0065] Hereinafter, priority A2 set in the central device 101 will also be referred to as priority A21. Furthermore, priority A2 set in the in-vehicle relay device 201 will also be referred to as priority A22. Furthermore, priority A2 set in the end ECU 251 will also be referred to as priority A23.
[0066] For example, the in-vehicle relay device 201 performs key generation processing Ka if its own priority A22 is higher than the priority A21 of the central device 101 and the priority A23 of the end ECU 251. The central device 101 performs key reception processing Kb if its own priority A21 is lower than the priority A22 of the in-vehicle relay device 201. The end ECU 251 performs key reception processing Kb if its own priority A23 is lower than the priority A22 of the in-vehicle relay device 201. In this embodiment, priority A22 is higher than priorities A21 and A23.
[0067] Figure 4 is a diagram showing an example of an encrypted communication sequence in an in-vehicle communication system according to an embodiment of the present disclosure. As an example, Figure 4 shows the encrypted communication sequence in group G3.
[0068] Referring to Figure 4, first, the central unit 101, the in-vehicle relay unit 201C, and the end ECU 251E perform pre-configuration before starting encrypted communication (step ST11) upon startup.
[0069] More specifically, for example, when the central unit 101 is activated, it notifies the in-vehicle relay unit 201C and the end ECU 251E of its own priority A21.
[0070] When the in-vehicle relay device 201C is activated, it notifies the central unit 101 and the end ECU 251E of its own priority A22.
[0071] When the end ECU 251E starts up, it notifies the central unit 101 and the in-vehicle relay unit 201C of its own priority A23.
[0072] The central device 101 compares its own priority A21 with priority A22 notified by the in-vehicle relay device 201C and priority A23 notified by the end ECU 251E.
[0073] Then, the central device 101 decides to perform key generation processing Ka as a process related to encrypted communication if priority A21 satisfies predetermined condition J1. The predetermined condition J1 is that priority A21 is the highest among priorities A21, A22, and A23. In key generation processing Ka, the central device 101 transmits the generated common key SAK to the in-vehicle relay device 201C and also transmits the common key SAK to the end ECU 251E via the in-vehicle relay device 201C.
[0074] On the other hand, if priority A21 does not satisfy the predetermined condition J1, the central device 101 decides to perform key reception processing Kb as processing related to encrypted communication.
[0075] In this embodiment, priority A21 is lower than priority A22. That is, priority A21 does not satisfy the predetermined condition J1. In this case, the central device 101 performs settings for performing key reception processing Kb (hereinafter also referred to as "setting processing S1") by performing register settings, etc.
[0076] The end ECU 251E compares its own priority A23 with priority A21 notified by the central unit 101 and priority A22 notified by the in-vehicle relay device 201C.
[0077] Then, if priority A23 satisfies predetermined condition J2, the end ECU 251E decides to perform key generation process Ka as a process related to encrypted communication. Predetermined condition J2 is that of priorities A21, A22, and A23, priority A23 is the highest. In key generation process Ka, the end ECU 251E transmits the generated common key SAK to the in-vehicle relay device 201C and also transmits the common key SAK to the central device 101 via the in-vehicle relay device 201C.
[0078] On the other hand, if priority A23 does not satisfy the predetermined condition J2, the end ECU 251E decides to perform key reception processing Kb as processing related to encrypted communication.
[0079] In this embodiment, priority A23 is lower than priority A22. That is, priority A23 does not satisfy the predetermined condition J2. In this case, the end ECU 251E performs settings for key reception processing Kb (hereinafter also referred to as "setting processing S2") by performing register settings, etc.
[0080] The in-vehicle relay device 201C compares its own priority A22 with priority A21 notified by the central device 101 and priority A23 notified by the end ECU 251E.
[0081] Then, the in-vehicle relay device 201C decides to perform key generation processing Ka as a process related to encrypted communication if priority A22 satisfies predetermined condition J3. The predetermined condition J3 is that priority A22 is the highest among priorities A21, A22, and A23. In key generation processing Ka, the in-vehicle relay device 201 transmits the generated common key SAK to the central device 101 and the end ECU 251E.
[0082] On the other hand, if priority A22 does not satisfy the predetermined condition J3, the in-vehicle relay device 201C decides to perform key reception processing Kb as processing related to encrypted communication.
[0083] In this embodiment, among priorities A21, A22, and A23, priority A22 has the highest priority. That is, priority A22 satisfies predetermined condition J3. In this case, the in-vehicle relay device 201 performs settings for key generation processing Ka (hereinafter also referred to as "setting processing S3") by performing register settings, etc.
[0084] Next, once the central device 101 has completed the setup process S1, it sends a key request notification to the in-vehicle relay device 201C indicating a request for the transmission of the common key SAK and identification information for identifying the group G to which it belongs (hereinafter also referred to as "group ID (Identifier)") (step ST12).
[0085] Next, the central device 101 sends a key request notification to the in-vehicle relay device 201C and generates a KEK (Key Encrypting Key) for encrypting or decrypting the common key. Hereinafter, the KEKs of groups G1, G2, and G3 will also be referred to as KEK1, KEK2, and KEK3, respectively.
[0086] The central device 101 generates key KEK3 using the pre-shared key PSK3 it holds (step ST13). Steps ST12 and ST13 may be executed in any order or in parallel.
[0087] Furthermore, once the end ECU 251E completes the configuration process S2, it sends a key request notification to the in-vehicle relay device 201C indicating a request for the transmission of the common key SAK and its own group ID (step ST14).
[0088] Next, the end ECU 251E sends a key request notification to the in-vehicle relay device 201C and generates key KEK3. More specifically, the end ECU 251E generates key KEK3 using the pre-shared key PSK it holds (step ST15). Steps ST14 and ST15 may be executed in any order or in parallel.
[0089] Next, when the in-vehicle relay device 201C receives a key request notification from the central device 101 and the end ECU 251E, it generates the key KEK3. More specifically, the in-vehicle relay device 201C generates the key KEK3 using the pre-shared key PSK3 it holds (step ST16).
[0090] Next, the in-vehicle relay device 201C generates the key KEK3 and then generates the common key SAK. More specifically, the in-vehicle relay device 201C generates a random number when it generates the key KEK3. Then, the in-vehicle relay device 201C generates the common key SAK by encrypting the generated random number using the key KEK3 (step ST17).
[0091] Next, the in-vehicle relay device 201C transmits the generated common key SAK to the key receiving devices belonging to group G of the group ID indicated in the received key request notification, i.e., the central device 101 and the end ECU 251E belonging to group G3 (steps ST18 and ST19).
[0092] Next, when the central device 101 receives the common key SAK from the in-vehicle relay device 201C, it performs a decryption process Q1 to decrypt the received common key SAK. More specifically, the central device 101 decrypts the common key SAK received from the in-vehicle relay device 201C using the key KEK3. As a result, the common key SAK is shared between the in-vehicle relay device 201C and the central device 101 (step ST20).
[0093] Furthermore, when the end ECU 251E receives the common key SAK from the in-vehicle relay device 201C, it performs a decryption process Q2 to decrypt the received common key SAK. More specifically, the end ECU 251E decrypts the common key SAK received from the in-vehicle relay device 201C using the key KEK3. As a result, the common key SAK is shared between the in-vehicle relay device 201C and the end ECU 251E (step ST21).
[0094] Next, the end ECU 251E and the in-vehicle relay device 201C communicate with each other using the common key SAK (step ST22).
[0095] Furthermore, the in-vehicle relay device 201C and the central device 101 communicate with each other using a common key SAK (step ST23). The sequence of encrypted communication in groups G1 and G2 is the same as the sequence shown in Figure 4.
[0096] [Explanation of the problem] Referring again to Figure 1, if an abnormality occurs in the key generation process Ka in the in-vehicle relay device 201 of a certain group G in the in-vehicle network 401, the common key SAK may not be distributed to each key receiving device in that group G. In this case, encrypted communication in that group G may fail.
[0097] Therefore, the in-vehicle communication system 301 according to the embodiment of this disclosure solves the above problem through the following configuration and operation.
[0098] [In-vehicle communication system] The following describes what happens when an abnormality occurs in the key generation process Ka in the in-vehicle relay device 201A in group G1 shown in Figure 1.
[0099] Figure 5 is a diagram illustrating the key completion process in an in-vehicle communication system according to an embodiment of the present disclosure.
[0100] Referring to Figure 5, if an abnormality occurs in the key generation process Ka in the in-vehicle relay device 201A, a key completion process is performed in the other in-vehicle relay devices 201 in group G other than group G1, i.e., in-vehicle relay device 201B or in-vehicle relay device 201C, to generate a common key SAK (hereinafter also referred to as "common key SAK1") used by the in-vehicle relay device 201A in encrypted communication. Hereinafter, in-vehicle relay devices 201B and 201C will also be referred to as key completion devices. Common key SAK1 is an example of second key information and an example of completion key information.
[0101] For example, in the in-vehicle network 401, a priority H for key completion processing is set for each of the multiple key completion devices, namely the in-vehicle relay device 201B and the in-vehicle relay device 201C.
[0102] In the example shown in Figure 5, the priority H of the in-vehicle relay device 201B is higher than the priority H of the in-vehicle relay device 201C. That is, in the example shown in Figure 5, the in-vehicle relay device 201B performs the key completion process. Details of the key completion process by the in-vehicle relay device 201B will be described later.
[0103] [In-vehicle relay device 201A] Figure 6 is a diagram showing an example of the configuration of an in-vehicle relay device according to an embodiment of the present disclosure. Figure 6 shows the configuration of the in-vehicle relay device 201A.
[0104] Referring to Figure 6, the in-vehicle relay device 201A comprises a communication unit 11, a processing unit 12, and a storage unit 13. The processing unit 12 includes a key generation unit 21, an encryption unit 22, a monitoring unit 23, a decryption unit 24, and a key transfer unit 25. One or both of the communication unit 11 and the processing unit 12 are implemented by a processing circuit (Circuitry) including, for example, one or more processors. The storage unit 13 is, for example, a non-volatile memory included in the processing circuit. The communication unit 11 is an example of an acquisition unit. The key transfer unit 25 is an example of a key receiving unit.
[0105] If the encryption communication process in its in-vehicle relay device 201A is key generation process Ka, the communication unit 11 receives a key request notification from the key receiving device in group G1 to which the in-vehicle relay device 201A belongs. The communication unit 11 outputs the received key request notification to the key generation unit 21 and the monitoring unit 23.
[0106] When the key generation unit 21 receives a key request notification from the communication unit 11, it generates a common key SAK1. For example, the storage unit 13 stores key generation information used by its own in-vehicle relay device 201A in the key generation process Ka. For example, the key generation information includes key identification information for identifying the common key SAK1, information indicating the number of bits in the common key SAK1, a random number for generating the common key SAK1, and an algorithm for encrypting the common key SAK1. The key generation information is registered in the storage unit 13 by the manufacturer of the vehicle 1 when the vehicle 1 is shipped.
[0107] The key generation unit 21 generates a common key SAK1 using the key generation information stored in the storage unit 13. The key generation unit 21 then outputs the generated common key SAK1 to the encryption unit 22. In addition, once the key generation unit 21 has generated the common key SAK1, it outputs a key generation notification to the monitoring unit 23 indicating that the common key SAK1 has been generated.
[0108] The encryption unit 22 encrypts the common key SAK1 received from the key generation unit 21 using the key KEK1 stored in the storage unit 13. Then, the encryption unit 22 outputs the encrypted common key SAK1 to the key generation unit 21.
[0109] The key generation unit 21 distributes the generated common key SAK1 to each key receiving device in group G1. More specifically, when the key generation unit 21 receives the encrypted common key SAK1 from the encryption unit 22, it transmits the common key SAK1 to each key receiving device in group G1 via the communication unit 11.
[0110] (Monitoring Unit) The monitoring unit 23 monitors the status P of its own in-vehicle relay device 201. More specifically, for example, the monitoring unit 23 monitors whether the common key SAK1 can be generated in its own in-vehicle relay device 201A as a status P.
[0111] Specifically, if the monitoring unit 23 receives a key generation notification from the key generation unit 21 within a predetermined time after receiving a key request notification from the communication unit 11, it determines that it can generate the common key SAK1 in its own in-vehicle relay device 201A within a predetermined period E. The monitoring unit 23 then outputs status information (hereinafter also referred to as "normal status information") indicating that the state P is normal to the communication unit 11.
[0112] On the other hand, if the monitoring unit 23 does not receive a key generation notification from the key generation unit 21 within a predetermined time after receiving a key request notification from the communication unit 11, it determines that it is not possible to generate the common key SAK1 in its own in-vehicle relay device 201A within a predetermined period E. The monitoring unit 23 then outputs status information (hereinafter also referred to as "status abnormality information") indicating that state P is abnormal to the communication unit 11.
[0113] Furthermore, if the monitoring unit 23 receives a key generation notification from the key generation unit 21 after a predetermined period has elapsed since receiving a key request notification from the communication unit 11, it determines that it is not possible to generate the common key SAK1 in its own in-vehicle relay device 201A within the predetermined period E. The monitoring unit 23 then outputs status abnormality information to the communication unit 11.
[0114] Furthermore, for example, the monitoring unit 23 monitors whether or not the common key SAK1 has been received in its own in-vehicle relay device 201A, as a state P.
[0115] For example, if the communication unit 11's processing related to encrypted communication in its in-vehicle relay device 201A is key reception processing Kb, it receives the common key SAK1 from the end ECU 251 or central device 101 that performs the key generation processing Ka in group G1. When the communication unit 11 receives the common key SAK1, it stores the received common key SAK1 in the storage unit 13 and outputs a key reception notification to the monitoring unit 23 indicating that the common key SAK1 has been received.
[0116] If the monitoring unit 23 receives a key reception notification from the communication unit 11 within a predetermined time after its in-vehicle relay device 201A is activated, it outputs status normal information to the communication unit 11. On the other hand, if the monitoring unit 23 does not receive a key reception notification from the communication unit 11 within a predetermined time after its in-vehicle relay device 201A is activated, it outputs status abnormal information to the communication unit 11.
[0117] (Priority Information) For example, the key generation information stored in the memory unit 13 further includes priority information L indicating the priority H of each key completion device in the in-vehicle network 401.
[0118] In this embodiment, as described above, the key completion devices in the in-vehicle network 401 are the in-vehicle relay devices 201B and 201C. That is, the priority information L included in the key generation information indicates the priority H of the in-vehicle relay device 201B and the priority H of the in-vehicle relay device 201C.
[0119] (Transmission of status information and key generation information) The communication unit 11 transmits status information indicating the status P monitored by the monitoring unit 23 to the in-vehicle relay devices 201B and 201C.
[0120] More specifically, the communication unit 11 transmits the status normal information received from the monitoring unit 23 to the in-vehicle relay devices 201B and 201C. Specifically, for example, when the communication unit 11 receives status normal information from the monitoring unit 23, it transmits a status frame F11 addressed to the in-vehicle relay device 201B containing the status normal information, and a status frame F12 addressed to the in-vehicle relay device 201C containing the status normal information, to the central device 101.
[0121] Furthermore, the communication unit 11 transmits the abnormal status information received from the monitoring unit 23 to the in-vehicle relay devices 201B and 201C. Specifically, for example, when the communication unit 11 receives abnormal status information from the monitoring unit 23, it transmits to the central device 101 a status frame F21 addressed to the in-vehicle relay device 201B, which contains the abnormal status information and key generation information stored in the storage unit 13, and a status frame F22 addressed to the in-vehicle relay device 201C, which contains the abnormal status information and key generation information.
[0122] (Central Device) Figure 7 is a diagram showing an example of the configuration of a central device according to an embodiment of the present disclosure. Referring to Figure 7, the central device 101 comprises a plurality of communication ports 30, a relay unit 31, a processing unit 32, and a storage unit 33. The processing unit 32 includes a creation unit 41, a decryption unit 42, and an encryption unit 43. One or both of the relay unit 31 and the processing unit 32 are implemented by a processing circuit including, for example, one or more processors. The storage unit 33 is, for example, a non-volatile memory included in the processing circuit.
[0123] The communication port 30 is a connector to which an Ethernet cable 51 can be connected. In the example shown in Figure 7, the central device 101 has three communication ports 30. Each communication port 30 is assigned a unique port number.
[0124] The relay unit 31 performs relay processing to relay information transmitted and received between the in-vehicle relay devices 201.
[0125] The storage unit 33 stores an address table that shows the correspondence between the port number of the communication port 30 and the MAC address of the device connected to the communication port 30. The relay unit 31 performs relay processing using the address table in the storage unit 33.
[0126] Furthermore, when the relay unit 31 receives a frame from the in-vehicle relay device 201 destined for its own central device 101, it outputs the received frame to the processing unit 32.
[0127] (Reception of the shared key SAK) The relay unit 31 receives the encrypted shared key SAK from the in-vehicle relay device 201. The relay unit 31 outputs the shared key SAK received from the in-vehicle relay device 201 to the decryption unit 42.
[0128] When the decryption unit 42 receives the encrypted common key SAK from the relay unit 31, it performs the decryption process Q1. After completing the decryption process Q1, the decryption unit 42 stores the decrypted common key SAK in the storage unit 33.
[0129] (Creation and encryption of frame F2) When the creation unit 41 creates frame F2 containing various information, it outputs the created frame F2 to the encryption unit 43.
[0130] The encryption unit 43 encrypts the frame F2 received from the relay unit 31 using the common key SAK stored in the storage unit 33. Then, the encryption unit 43 outputs the encrypted frame F2 to the creation unit 41.
[0131] When the creation unit 41 receives the encrypted frame F2 from the encryption unit 43, it transmits the frame F2 to the in-vehicle relay device 201 of group G to which the destination end ECU 251 belongs, via the relay unit 31.
[0132] (Relay of status information) The relay unit 31 receives status information from the in-vehicle relay device 201A and relays the received status information to the in-vehicle relay devices 201B and 201C.
[0133] Specifically, the relay unit 31 relays the status frame F11, which contains status normal information, received from the in-vehicle relay device 201A, to the in-vehicle relay device 201B. The relay unit 31 also relays the status frame F12, which contains status normal information, received from the in-vehicle relay device 201A, to the in-vehicle relay device 201C.
[0134] Furthermore, the relay unit 31 relays the status frame F21, which includes status abnormality information and key generation information, received from the in-vehicle relay device 201A, to the in-vehicle relay device 201B. Also, the relay unit 31 relays the status frame F22, which includes status abnormality information and key generation information, received from the in-vehicle relay device 201A, to the in-vehicle relay device 201C.
[0135] (In-vehicle relay device 201B) Figure 8 shows another example of the configuration of an in-vehicle relay device according to an embodiment of the present disclosure. Figure 8 shows the configuration of the in-vehicle relay device 201B.
[0136] Referring to Figure 8, the in-vehicle relay device 201B comprises a communication unit 61, a processing unit 62, and a storage unit 63. The processing unit 62 includes a key generation unit 71, an encryption unit 72, a monitoring unit 73, and a determination unit 74. One or both of the communication unit 61 and the processing unit 62 are implemented by a processing circuit including, for example, one or more processors. The storage unit 63 is, for example, a non-volatile memory included in the processing circuit. The communication unit 61 is an example of an acquisition unit.
[0137] The communication unit 61 receives a key request notification from a key receiving device in group G2, to which its in-vehicle relay device 201B belongs. The communication unit 61 outputs the received key request notification to the key generation unit 71.
[0138] (Key Generation Unit) The key generation unit 71 generates a common key SAK (hereinafter also referred to as "common key SAK2") that its in-vehicle relay device 201B will use in encrypted communication. Common key SAK2 is an example of the first key information.
[0139] More specifically, when the key generation unit 71 receives a key request notification from the communication unit 61, it generates a random number. Then, the key generation unit 71 generates a common key SAK2 based on the generated random number. The key generation unit 71 outputs the generated common key SAK2 to the encryption unit 72.
[0140] The encryption unit 72 encrypts the common key SAK2 received from the key generation unit 71 using the key KEK2 stored in the storage unit 13. Then, the encryption unit 72 outputs the encrypted common key SAK2 to the key generation unit 71.
[0141] The key generation unit 71 distributes the generated common key SAK2 to each key receiving device in group G2. More specifically, when the key generation unit 71 receives the encrypted common key SAK2 from the encryption unit 72, it transmits the common key SAK2 to each key receiving device in group G2 via the communication unit 61.
[0142] (Acquisition of status information and key generation information) The communication unit 61 acquires status information and key generation information from the in-vehicle relay device 201A via the central device 101.
[0143] More specifically, the communication unit 61 receives a status frame F11 containing status normal information from the central device 101. The communication unit 61 outputs the status normal information contained in the received status frame F11 to the monitoring unit 73.
[0144] Furthermore, the communication unit 61 receives a status frame F21 from the central device 101, which includes status anomaly information and key generation information. The communication unit 61 outputs the status anomaly information contained in the received status frame F21 to the monitoring unit 73. The communication unit 61 also stores the key generation information contained in the received status frame F21 in the storage unit 63.
[0145] (Monitoring Unit) The monitoring unit 73 monitors the status P of the in-vehicle relay device 201A. More specifically, for example, the monitoring unit 73 monitors whether the common key SAK1 can be generated in the in-vehicle relay device 201A.
[0146] When the monitoring unit 73 receives status normal information from the communication unit 61, it determines that the in-vehicle relay device 201A is capable of generating the common key SAK1. The monitoring unit 73 then outputs monitoring result information C31 to the determination unit 74, indicating that the status of the key generation process Ka in the in-vehicle relay device 201A is normal.
[0147] Furthermore, when the monitoring unit 73 receives abnormal status information from the communication unit 61, it determines that the in-vehicle relay device 201A is unable to generate the common key SAK1. The monitoring unit 73 then outputs monitoring result information C32 to the determination unit 74, indicating that the status of the key generation process Ka in the in-vehicle relay device 201A is abnormal.
[0148] (Determination Unit) The determination unit 74 determines the state P monitored by the monitoring unit 73. More specifically, when the determination unit 74 receives monitoring result information C31 from the monitoring unit 73, it determines that the state P is normal.
[0149] On the other hand, when the determination unit 74 receives monitoring result information C32 from the monitoring unit 73, it determines that state P is abnormal.
[0150] The determination unit 74 then outputs status abnormality information to the key generation unit 71, indicating that state P is abnormal.
[0151] For example, the storage unit 63 stores in advance a pre-shared key PSK1 corresponding to group G1, to which the in-vehicle relay device 201A belongs, in addition to the pre-shared key PSK2 corresponding to group G2 to which its own in-vehicle relay device 201B belongs.
[0152] (Key completion processing) If the determination unit 74 determines that state P is abnormal, the key generation unit 71 performs key completion processing to generate a common key SAK1 that the in-vehicle relay device 201A will use in encrypted communication, based on the key generation information obtained by the communication unit 61 and the pre-shared key PSK1 stored in the storage unit 63.
[0153] More specifically, for example, when the key generation unit 71 receives status abnormality information from the determination unit 74, it decides whether or not to perform key completion processing based on the priority information L contained in the key generation information stored in the storage unit 63.
[0154] Specifically, the key generation unit 71 compares the priority H of its own in-vehicle relay device 201B, indicated by the priority information L contained in the key generation information stored in the storage unit 63, with the priority H of another in-vehicle relay device 201C, which is another in-vehicle relay device 201 capable of performing key completion processing.
[0155] The key generation unit 71 then decides to perform key completion processing if the priority H of its own in-vehicle relay device 201B is higher than the priority H of the in-vehicle relay device 201C.
[0156] On the other hand, the key generation unit 71 decides not to perform key completion processing if the priority H of its own in-vehicle relay device 201B is lower than the priority H of the in-vehicle relay device 201C.
[0157] In this embodiment, as described above, the priority H of the in-vehicle relay device 201B is higher than the priority H of the in-vehicle relay device 201C. Therefore, the in-vehicle relay device 201B performs the key completion process.
[0158] When the key generation unit 71 decides to perform key completion processing, it generates a common key SAK1 using the key generation information stored in the memory unit 63. The key generation unit 71 outputs the generated common key SAK1 to the encryption unit 72.
[0159] When the encryption unit 72 receives the common key SAK1 from the key generation unit 71, it generates the key KEK1 using the key generation information and the pre-shared key PSK1 stored in the storage unit 63. Then, the encryption unit 72 encrypts the common key SAK1 received from the key generation unit 71 using the generated key KEK1. The encryption unit 72 outputs the encrypted common key SAK1 to the key generation unit 71.
[0160] The key generation unit 71 distributes the generated common key SAK1 to the in-vehicle relay device 201A. More specifically, when the key generation unit 71 receives the encrypted common key SAK1 from the encryption unit 72, it transmits the common key SAK1 to the central device 101.
[0161] Specifically, the key generation unit 71 transmits a key completion frame addressed to the in-vehicle relay device 201A, which contains the encrypted common key SAK1, to the central device 101 via the communication unit 61.
[0162] [Relay of Common Key SAK1] Referring again to Figure 7, in the central device 101, the relay unit 31 receives a key completion frame including the common key SAK1 from the in-vehicle relay device 201B and relays the received key completion frame to the in-vehicle relay device 201A.
[0163] [Receiving the Common Key SAK1] Referring again to Figure 6, in the in-vehicle relay device 201A, when the communication unit 11 receives a key completion frame from the central device 101, it outputs the encrypted common key SAK1 contained in the received key completion frame to the decryption unit 24.
[0164] When the decryption unit 24 receives the encrypted common key SAK1 from the communication unit 11, it decrypts the common key SAK1 using the KEK1 stored in the storage unit 13. The decryption unit 24 then stores the decrypted common key SAK1 in the storage unit 13 and outputs a decryption completion notification to the key transfer unit 25 indicating that the common key SAK1 has been decrypted.
[0165] The key transfer unit 25 processes the common key SAK1 received from the in-vehicle relay device 201B for use in encrypted communication.
[0166] More specifically, for example, the key transfer unit 25 performs key transfer processing to transfer the common key SAK1 received from the in-vehicle relay device 201B to each key receiving device in group G1 to which its own in-vehicle relay device 201A belongs, namely the central device 101 and the end ECUs 251A and 251B.
[0167] Specifically, when the key transfer unit 25 receives a decryption completion notification from the decryption unit 24, it transmits the common key SAK1 stored in the storage unit 13 to the central device 101 and the end ECUs 251A and 251B via the communication unit 11.
[0168] Referring again to Figure 1, when the central device 101 receives the common key SAK1 from the in-vehicle relay device 201A, it performs the decryption process Q1.
[0169] When the end ECUs 251A and 251B receive the common key SAK1 from the in-vehicle relay device 201A, they perform the decryption process Q2.
[0170] [In-vehicle relay device 201C] Figure 8 also shows the configuration of the in-vehicle relay device 201C. Referring to Figure 8, in the in-vehicle relay device 201C, the communication unit 61 receives a status frame F12 containing status normal information from the central device 101. The communication unit 61 outputs the status normal information contained in the received status frame F12 to the monitoring unit 73.
[0171] Furthermore, the communication unit 61 receives a status frame F22 from the central device 101, which includes status anomaly information and key generation information. The communication unit 61 outputs the status anomaly information contained in the received status frame F22 to the monitoring unit 73. The communication unit 61 also stores the key generation information contained in the received status frame F22 in the storage unit 63.
[0172] When the monitoring unit 73 receives abnormal status information from the communication unit 61, it determines that the in-vehicle relay device 201A is unable to generate the common key SAK1. The monitoring unit 73 then outputs the monitoring result information C32 to the determination unit 74.
[0173] When the determination unit 74 receives monitoring result information C32 from the monitoring unit 73, it determines that state P is abnormal. The determination unit 74 then outputs abnormal state information indicating that state P is abnormal to the key generation unit 71.
[0174] When the key generation unit 71 receives status abnormality information from the determination unit 74, it compares the priority H of its own in-vehicle relay device 201C with the priority H of the in-vehicle relay device 201B, as indicated by the priority information L contained in the key generation information stored in the memory unit 63.
[0175] In this embodiment, as described above, the priority H of the in-vehicle relay device 201B is higher than the priority H of the in-vehicle relay device 201C. Therefore, the key generation unit 71 in the in-vehicle relay device 201C decides not to perform key completion processing.
[0176] On the other hand, in the in-vehicle relay device 201C, the key generation unit 71 decides to perform key completion processing if the priority H of the in-vehicle relay device 201C is higher than the priority H of the in-vehicle relay device 201B.
[0177] Referring to Figures 5 and 8, the storage unit 63 in the in-vehicle relay device 201C stores in advance the pre-shared key PSK1 corresponding to group G1 to which the in-vehicle relay device 201A belongs, in addition to the pre-shared key PSK3 corresponding to group G3 to which the in-vehicle relay device 201C belongs.
[0178] The key generation unit 71 performs key completion processing based on the key generation information obtained by the communication unit 61 and the pre-shared key PSK1 stored in the storage unit 63.
[0179] Referring again to Figures 1 and 5, in the in-vehicle communication system 301 according to this embodiment, if an abnormality occurs in the key generation process Ka in the in-vehicle relay device 201A, the in-vehicle relay device 201B generates and distributes a common key SAK1 used by the in-vehicle relay device 201A for encrypted communication, using the key generation information received from the in-vehicle relay device 201A and the pre-shared key PSK1 stored in the storage unit 63. As a result, even if the abnormality occurs, the group G1 to which the in-vehicle relay device 201A belongs can perform encrypted communication using the common key SAK1 distributed by the in-vehicle relay device 201B.
[0180] Furthermore, in the example shown in Figure 5, in addition to the storage unit 13 of the in-vehicle relay device 201A, the storage units 63 of the in-vehicle relay devices 201B and 201C, which are key completion devices, also pre-store the pre-shared key PSK1. In other words, in the in-vehicle network 401, the devices that hold the pre-shared key PSK1 are the in-vehicle relay devices 201A, 201B, and 201C. This reduces the risk of the pre-shared key PSK1 being illegally obtained compared to a configuration where each device in the in-vehicle network 401 holds the pre-shared key PSK1, thereby improving the security of the in-vehicle network 401. In addition, the number of key information items that need to be managed in the in-vehicle network 401 can be reduced.
[0181] [Operation Flow] Next, the operation flow of each device in the in-vehicle communication system 301 according to the embodiment of this disclosure will be explained with reference to the drawings.
[0182] Figure 9 is a flowchart illustrating an example of the operation procedure when an in-vehicle relay device according to an embodiment of the present disclosure performs a process to transmit status information.
[0183] Referring to Figure 9, first, the in-vehicle relay device 201A monitors its own state P when the setting process S1 for performing the key generation process Ka has been completed. For example, as described above, the in-vehicle relay device 201A monitors whether or not the common key SAK1 can be generated within a predetermined period E as state P (step ST101).
[0184] Next, if the in-vehicle relay device 201A is able to generate the common key SAK1 within a predetermined period E (YES in step ST102), it sends a status frame F11 addressed to the in-vehicle relay device 201B containing status normal information indicating that state P is normal, and a status frame F12 addressed to the in-vehicle relay device 201C containing the same status normal information, to the central device 101 (step ST103), and monitors state P again (step ST101).
[0185] On the other hand, if the in-vehicle relay device 201A is unable to generate the common key SAK1 within a predetermined period E (NO in step ST102), it transmits to the central device 101 a status frame F21 addressed to the in-vehicle relay device 201B, which contains status abnormality information indicating that state P is abnormal and key generation information stored in the storage unit 13, and a status frame F22 addressed to the in-vehicle relay device 201C, which contains the status abnormality information and the said key generation information (step ST104).
[0186] Next, the in-vehicle relay device 201A transmits status frames F21 and F22 to the central device 101 and waits for the reception of a key completion frame from the central device 101 (NO in step ST105).
[0187] Then, when the in-vehicle relay device 201A receives a key completion frame from the central device 101 (YES in step ST105), it decrypts the encrypted common key SAK1 contained in the received key completion frame and stores it in the storage unit 13 (step ST106).
[0188] Next, the in-vehicle relay device 201A distributes the decrypted common key SAK1 to the central device 101 and end ECUs 251A and 251B, which are key receiving devices in the group G1 to which it belongs (step ST107).
[0189] Figure 10 is a flowchart illustrating an example of the operation procedure when the central device according to the embodiment of this disclosure performs relay processing. Figure 10 shows the case when the central device 101 relays information transmitted and received between the in-vehicle relay device 201A and the in-vehicle relay device 201B.
[0190] Referring to Figure 10, first, the central device 101 waits for the reception of a status frame F11 or status frame F21 from the in-vehicle relay device 201A (NO in step ST201).
[0191] Then, when the central device 101 receives a status frame F11 or status frame F12 from the in-vehicle relay device 201 (YES in step ST201), it relays the received status frame F11 or status frame F12 to the in-vehicle relay device 201B (step ST202).
[0192] Next, if the central device 101 relays the status frame F21 to the in-vehicle relay device 201B (YES in step ST203), it waits for the reception of a key completion frame from the in-vehicle relay device 201B (NO in step ST204).
[0193] Then, when the central device 101 receives a key completion frame from the in-vehicle relay device 201B (YES in step ST204), it relays the received key completion frame to the in-vehicle relay device 201A (step ST205).
[0194] Next, the central device 101 relays the key completion frame to the in-vehicle relay device 201A and waits for the encrypted common key SAK1 to be received from the in-vehicle relay device 201A (NO in step ST206).
[0195] Then, when the central device 101 receives the encrypted common key SAK1 from the in-vehicle relay device 201A (YES in step ST206), it decrypts the common key SAK1 and stores it in the storage unit 33 (step ST207).
[0196] On the other hand, if the central device 101 relays the status frame F11 to the in-vehicle relay device 201B (NO in step ST203), it waits for the reception of a new status frame F11 from the in-vehicle relay device 201A, or for the reception of a status frame F21 from the in-vehicle relay device 201A (NO in step ST201).
[0197] Figure 11 is a flowchart illustrating an example of the operation procedure when an in-vehicle relay device according to an embodiment of the present disclosure performs key completion processing. Figure 11 shows the case when the in-vehicle relay device 201B performs key completion processing.
[0198] Referring to Figure 11, first, the in-vehicle relay device 201B monitors the state P of the in-vehicle relay device 201A when the setting process S1 for performing the key generation process Ka has been completed. For example, as described above, the in-vehicle relay device 201B monitors the state P by checking the contents of the state frame received from the central device 101 (step ST301).
[0199] Next, the in-vehicle relay device 201B determines whether or not state P is abnormal (step ST302).
[0200] Then, if the in-vehicle relay device 201B is normal, that is, if it receives a status frame F11 from the central device 101 (YES in step ST302), it continues to monitor status P (step ST301).
[0201] On the other hand, if the in-vehicle relay device 201B receives a status frame F21 from the central device 101 when the state P is abnormal (i.e., NO in step ST302), it decides whether or not to perform key completion processing based on the priority information L contained in the received status frame F21. For example, as described above, the in-vehicle relay device 201B checks whether its own priority H for key completion processing is higher than the priority H of the in-vehicle relay device 201C for key completion processing (step ST303). Here, it is assumed that the priority H of the in-vehicle relay device 201B is higher than the priority H of the in-vehicle relay device 201C. Therefore, the in-vehicle relay device 201B decides to perform key completion processing (step ST304).
[0202] Next, when the in-vehicle relay device 201B decides to perform key completion processing, it performs key completion processing to generate a common key SAK1 that the in-vehicle relay device 201A will use in encrypted communication, based on the key generation information contained in the received state frame F21 and the pre-shared key PSK1 stored in the storage unit 63 (step ST305).
[0203] Next, the in-vehicle relay device 201B transmits a key completion frame addressed to the in-vehicle relay device 201A, which contains the generated common key SAK1, to the central device 101 (step ST306).
[0204] On the other hand, if the in-vehicle relay device 201B's own priority H is lower than the priority H of the in-vehicle relay device 201C (NO in step ST303), it decides not to perform key completion processing (step ST307).
[0205] Figures 12 and 13 show an example of the processing sequence of an in-vehicle relay device, a central device, and an end ECU in an in-vehicle communication system according to an embodiment of the present disclosure.
[0206] Referring to Figures 12 and 13, first, the in-vehicle relay device 201A monitors its own state P, specifically whether or not the common key SAK1 can be generated within a predetermined period E. Here, it is assumed that the in-vehicle relay device 201A has determined that it is not possible to generate the common key SAK1 within the predetermined period E (step ST401).
[0207] Next, the in-vehicle relay device 201A transmits to the central device 101 a status frame F21 addressed to the in-vehicle relay device 201B, which contains status abnormality information indicating that state P is abnormal and key generation information stored in the storage unit 13, and a status frame F22 addressed to the in-vehicle relay device 201C, which contains the status abnormality information and the said key generation information (step ST402).
[0208] Next, the central device 101 relays the status frame F21 received from the in-vehicle relay device 201A to the in-vehicle relay device 201B (step ST403).
[0209] Furthermore, the central device 101 relays the status frame F22 received from the in-vehicle relay device 201A to the in-vehicle relay device 201C (step ST404).
[0210] Next, when the in-vehicle relay device 201B receives the status frame F21 from the central device 101, it determines that status P is abnormal (step ST405).
[0211] Next, when the in-vehicle relay device 201B determines that state P is abnormal, it decides whether or not to perform key completion processing based on the priority information L contained in the received state frame F21. Here, it is assumed that the in-vehicle relay device 201B has decided to perform key completion processing (step ST406).
[0212] Furthermore, when the in-vehicle relay device 201C receives the status frame F22 from the central device 101, it determines that status P is abnormal (step ST407).
[0213] Next, when the in-vehicle relay device 201C determines that state P is abnormal, it decides whether or not to perform key completion processing based on the priority information L contained in the received state frame F22. Here, it is assumed that the in-vehicle relay device 201C has decided not to perform key completion processing (step ST408).
[0214] When the in-vehicle relay device 201B decides to perform key completion processing, it generates the common key SAK1 that the in-vehicle relay device 201A will use in encrypted communication (step ST409).
[0215] Next, the in-vehicle relay device 201B transmits a key completion frame addressed to the in-vehicle relay device 201A, which contains the generated common key SAK1, to the central device 101 (step ST410).
[0216] Next, when the central device 101 receives a key completion frame from the in-vehicle relay device 201B, it relays the received key completion frame to the in-vehicle relay device 201A (step ST411).
[0217] Next, when the in-vehicle relay device 201A receives a key completion frame from the central device 101, it decrypts the encrypted common key SAK1 contained in the received key completion frame and stores it in the storage unit 13 (step ST412).
[0218] Furthermore, when the in-vehicle relay device 201A receives a key completion frame from the central device 101, it transmits the encrypted common key SAK1 contained in the received key completion frame to the central device 101 and the end ECUs 251A and 251B (step ST413).
[0219] Next, when the central device 101 receives the encrypted common key SAK1 from the in-vehicle relay device 201A, it decrypts the common key SAK1 and stores it in the storage unit 13 (step ST414).
[0220] Furthermore, when the end ECUs 251A and 251B receive the encrypted common key SAK1 from the in-vehicle relay device 201A, they decrypt the common key SAK1 and store it in the storage unit 13 (step ST415).
[0221] Next, the end ECUs 251A and 251B and the in-vehicle relay device 201A communicate with each other using encryption. For example, as described above, the end ECU 251A or end ECU 251B transmits a frame F1 encrypted using the common key SAK1 to the in-vehicle relay device 201A (step ST416).
[0222] Next, the in-vehicle relay device 201A and the central device 101 communicate with each other using encrypted methods. For example, as described above, the in-vehicle relay device 201A transmits the encrypted frame F1 received from the end ECU 251A or end ECU 251B to the central device 101. The central device 101 then transmits a frame F2 encrypted using the common key SAK1 to the in-vehicle relay device 201A (step ST417).
[0223] In the in-vehicle communication system 301 according to the embodiment of this disclosure, the storage units 63 of each of the in-vehicle relay devices 201B and 201C are configured to store the pre-shared key PSK1 in advance, but the invention is not limited to this configuration. The storage units 63 of each of the in-vehicle relay devices 201B and 201C may not be configured to store the pre-shared key PSK1 in advance. In this case, for example, the in-vehicle relay device 201A includes the pre-shared key PSK1 in the key generation information and transmits it to the in-vehicle relay devices 201B and 201C.
[0224] Furthermore, in the in-vehicle communication system 301 according to the embodiment of this disclosure, the key generation information transmitted by the in-vehicle relay device 201A to the in-vehicle relay devices 201B and 201C includes priority information L indicating the respective priority H of the in-vehicle relay devices 201B and 201C regarding key completion processing, but the disclosure is not limited to this. The key generation information may also be configured not to include priority information L. In this case, for example, each of the storage units 63 of the in-vehicle relay devices 201B and 201C stores the priority information L in advance. The in-vehicle relay devices 201B and 201C decide whether or not to perform key completion processing based on the priority information L stored in the storage unit 63.
[0225] Furthermore, although the in-vehicle communication system 301 according to the embodiment of this disclosure is configured to include a plurality of key completion devices, namely in-vehicle relay devices 201B and 201C, it is not limited thereto. The in-vehicle communication system 301 may also be configured to include either the in-vehicle relay device 201B or the in-vehicle relay device 201C.
[0226] Furthermore, in the in-vehicle communication system 301 according to the embodiment of this disclosure, the in-vehicle relay device 201A is configured to perform a key transfer process in which it transfers the common key SAK1 received from the in-vehicle relay device 201B to the central device 101 and end ECUs 251A and 251B belonging to the same group G1 as itself, and to use the common key SAK1 in encrypted communication. However, the invention is not limited to this configuration. For example, the in-vehicle relay device 201A may be configured to perform a process in which it encrypts various information it has created using the common key SAK1 received from the in-vehicle relay device 201B and transmits it to other devices, and to use the common key SAK1 in encrypted communication.
[0227] Furthermore, while the in-vehicle communication system 301 according to the embodiment of this disclosure is configured such that in-vehicle relay devices 201B and 201C perform key completion processing, and in-vehicle relay device 201A does not perform key completion processing, the system is not limited to this configuration. Each of the in-vehicle relay devices 201A, 201B, and 201C may perform key completion processing. In this case, each in-vehicle relay device 201 transmits status information indicating the monitoring result of its own status P to the other in-vehicle relay devices 201.
[0228] Furthermore, in the in-vehicle communication system 301 according to the embodiment of this disclosure, the central unit 101 and the in-vehicle relay device 201, and the in-vehicle relay device 201 and the end ECU 251 are configured to perform encrypted communication in accordance with the MACsec standard, but this is not limited to this. The central unit 101 and the in-vehicle relay device 201, and the in-vehicle relay device 201 and the end ECU 251 may be configured to perform encrypted communication in accordance with other methods, such as a private key and public key encryption scheme, not limited to the MACsec standard. In this case, the in-vehicle relay device 201 is connected to the central unit 101 via a transmission line that conforms to the communication standard corresponding to the other method. The end ECU 251 is also connected to the in-vehicle relay device 201 via a transmission line that conforms to the communication standard. The communication standard is not limited to Ethernet, but may be other communication standards other than Ethernet.
[0229] [Modification] Referring again to Figures 1 and 5, for example, the key generation information that the in-vehicle relay device 201A transmits to the in-vehicle relay devices 201B and 201C may further include identification information D1 and one or more pieces of identification information D2. Identification information D1 is an example of first identification information, and identification information D2 is an example of second identification information.
[0230] Identification information D1 is identification information for identifying the in-vehicle relay device 201A. Identification information D2 is identification information for identifying the key receiving device in group G1 to which the in-vehicle relay device 201A belongs. For example, identification information D1 and identification information D2 include the MAC (Media Access Control) address of the in-vehicle relay device 201A and the MAC address of the key receiving device, respectively.
[0231] For example, when the in-vehicle relay device 201B generates a common key SAK1 during key completion processing, it creates a key completion frame addressed to the in-vehicle relay device 201A containing the common key SAK1, and a key completion frame addressed to the key receiving device in group G1 containing the common key SAK1, using the identification information D1 and D2 included in the key generation information received from the in-vehicle relay device 201A. Then, the in-vehicle relay device 201B transmits each of the created key completion frames.
[0232] The embodiments described above should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than the above description, and all modifications within the meaning and scope of the claims are intended to be included.
[0233] Each process (each function) in the above-described embodiment is implemented by a processing circuit including one or more processors. The processing circuit may consist of an integrated circuit, etc., which combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the above processes. The one or more processors may execute each of the above processes according to the programs read from the one or more memories, or they may execute each of the above processes according to logic circuits that have been designed in advance to execute each of the above processes. The above-mentioned processor may be various processors suitable for computer control, such as a CPU (Central Processing Unit), GPU (Graphics Processing Unit), DSP (Digital Signal Processor), FPGA (Field Programmable Gate Array), and ASIC (Application Specific Integrated Circuit). Furthermore, multiple physically separated processors may cooperate with each other to perform the above-mentioned processes. For example, processors installed in multiple physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), WAN (Wide Area Network), and the Internet to perform the above-mentioned processes. The above program may be installed on the above memory via the above network from an external server device, or it may be distributed on a recording medium such as a CD-ROM (Compact Disc Read Only Memory), DVD-ROM (Digital Versatile Disc Read Only Memory), or semiconductor memory, and then installed on the above memory from the above recording medium.
[0234] The above description includes the following features: [Addendum 1] An encrypted communication method in an in-vehicle device that is mounted in a vehicle and performs key generation processing to generate and distribute key information used in encrypted communication, comprising: a step of generating first key information which is the key information used in encrypted communication by the device which is the in-vehicle device itself; a step of acquiring key generation information used by the other device in the key generation processing from another device which is another in-vehicle device that performs the key generation processing; a step of monitoring the state of the other device; a step of determining the monitored state; a step of performing key completion processing to generate second key information which is the key information used by the other device in encrypted communication based on the acquired key generation information if the state is determined to be abnormal; and a step of distributing the generated second key information to the other device.
[0235] [Note 2] An encrypted communication method in an in-vehicle device that performs key generation processing to generate and distribute key information used in encrypted communication, comprising: a step of monitoring the status of the in-vehicle device itself; a step of transmitting information indicating the monitored status and information used in the key generation processing to another in-vehicle device that performs the key generation processing; and a step of using the key information distributed by the other in-vehicle device in the encrypted communication.
[0236] [Note 3] A relay method in a relay device used in an in-vehicle network including a first in-vehicle device and a second in-vehicle device that performs a key generation process for generating and distributing key information used in encrypted communication, comprising the step of relaying information transmitted and received between the first in-vehicle device and the second in-vehicle device, wherein in the step of relaying the information, the relay device receives from the first in-vehicle device state information, which is the information indicating the state of the first in-vehicle device, and key generation information, which is the information used by the first in-vehicle device in the key generation process, and relays the received state information and key generation information to the second in-vehicle device, wherein in the step of relaying the information, the relay device receives from the second in-vehicle device supplementary key information, which is the key information used by the first in-vehicle device in the encrypted communication, generated by the second in-vehicle device, and relays the received supplementary key information to the first in-vehicle device.
[0237] [Note 4] An encrypted communication method in an in-vehicle communication system comprising a first in-vehicle device and a second in-vehicle device, and a relay device, which perform a key generation process for generating and distributing key information used in encrypted communication, the method comprising: the first in-vehicle device monitoring its own state and transmitting state information indicating the monitored state and key generation information used in the key generation process to the relay device; the relay device relaying the state information and key generation information received from the first in-vehicle device to the second in-vehicle device; the second in-vehicle device determining the state based on the state information received from the relay device; if the second in-vehicle device determines that the state is abnormal, generating supplementary key information, which is the key information used by the first in-vehicle device in encrypted communication, based on the key generation information received from the relay device; and the second in-vehicle device transmitting the generated supplementary key information to the relay device. An encrypted communication method comprising the steps of: relaying the supplementary key information received from the second in-vehicle device to the first in-vehicle device by the relay device; and using the supplementary key information received from the relay device in the encrypted communication by the first in-vehicle device.
[0238] [Note 5] An in-vehicle device that is mounted on a vehicle and performs key generation processing to generate and distribute key information used in encrypted communication, comprising a processing circuit, the processing circuit generating first key information which is the key information used by the device which is the in-vehicle device in encrypted communication, acquiring key generation information used by the other device in the key generation processing from another device which is another in-vehicle device that performs the key generation processing, monitoring the state of the other device, determining the monitored state, and if it is determined that the state is abnormal, performing key completion processing to generate second key information which is the key information used by the other device in encrypted communication based on the acquired key generation information, and distributing the generated second key information to the other device.
[0239] [Appendix 6] An in-vehicle device that performs key generation processing for generating and distributing key information used in encrypted communication, comprising a processing circuit, wherein the processing circuit monitors the status of the in-vehicle device itself, transmits information indicating the monitored status and information used in the key generation processing to another in-vehicle device that performs the key generation processing, and uses the key information distributed by the other in-vehicle device in the encrypted communication.
[0240] [Note 7] A relay device used in an in-vehicle network including a first in-vehicle device and a second in-vehicle device that performs key generation processing for generating and distributing key information used in encrypted communication, comprising a processing circuit, the processing circuit relaying information transmitted and received between the first in-vehicle device and the second in-vehicle device, receiving from the first in-vehicle device state information which indicates the state of the first in-vehicle device and key generation information which is used by the first in-vehicle device in the key generation processing, relaying the received state information and key generation information to the second in-vehicle device, receiving the key information used by the first in-vehicle device in the encrypted communication from the second in-vehicle device, and relaying the received key information to the first in-vehicle device.
[0241] 1 Vehicle 11, 61 Communication Unit 12, 32, 62 Processing Unit 13, 33, 63 Storage Unit 21, 71 Key Generation Unit 22, 43, 72 Encryption Unit 23, 73 Monitoring Unit 24, 42 Decryption Unit 25 Key Transfer Unit 30 Communication Port 31 Relay Unit 41 Creation Unit 51 Ethernet Cable 74 Judgment Unit 101 Central Unit 201, 201A, 201B, 201C In-vehicle Relay Device 251, 251A, 251B, 251C, 251D, 251E End ECU 301 In-vehicle Communication System 401 In-vehicle Network
Claims
1. An in-vehicle device that is mounted on a vehicle and performs key generation processing to generate and distribute key information used in encrypted communication, comprising: a key generation unit that generates first key information which is the key information used in encrypted communication by the device itself, which is the in-vehicle device; an acquisition unit that acquires key generation information used by another device, which is another in-vehicle device that performs the key generation processing, from the other device; a monitoring unit that monitors the status of the other device; and a determination unit that determines the status monitored by the monitoring unit, wherein if the determination unit determines that the status is abnormal, the key generation unit performs key completion processing to generate second key information which is the key information used by the other device in encrypted communication based on the key generation information acquired by the acquisition unit; and the key generation unit distributes the generated second key information to the other device.
2. The in-vehicle device further comprises a storage unit for storing a third key information in accordance with the MACsec standard, which is used to generate the second key information, and the key generation unit performs the key completion processing based on the third key information stored in the storage unit, according to claim 1.
3. The in-vehicle device according to claim 1 or 2, wherein in the in-vehicle network of the vehicle, a first group is formed including the device itself and an in-vehicle device to which the first key information is distributed, and a second group is formed including the other device and an in-vehicle device to which the second key information is distributed, and the key generation information includes first identification information for identifying the other device and second identification information for identifying the in-vehicle device to which the second key information is distributed, which is included in the second group.
4. The in-vehicle device according to any one of claims 1 to 3, wherein the in-vehicle network of the vehicle is provided with a plurality of key completion devices, each of the plurality of key completion devices is assigned a priority for the key completion process, and the key generation unit performs the key completion process if the priority of its own device is higher than the priority of each of the other key completion devices.
5. The in-vehicle device according to claim 4, wherein the key generation information includes priority information indicating the priority of each of the key completion devices, and the key generation unit determines whether or not to perform the key completion process based on the priority information included in the key generation information.
6. An in-vehicle device that performs key generation processing for generating and distributing key information used in encrypted communication, comprising: a monitoring unit that monitors the status of the in-vehicle device itself; a communication unit that transmits information indicating the status monitored by the monitoring unit and information used in the key generation processing to another in-vehicle device that performs the key generation processing; and a key receiving unit that uses the key information received from the other in-vehicle device in the encrypted communication.
7. A relay device used in an in-vehicle network including a first in-vehicle device and a second in-vehicle device that perform a key generation process for generating and distributing key information used in encrypted communication, comprising a relay unit that relays information transmitted and received between the first in-vehicle device and the second in-vehicle device, wherein the relay unit receives from the first in-vehicle device state information, which is information indicating the state of the first in-vehicle device, and key generation information, which is information used by the first in-vehicle device in the key generation process, and relays the received state information and key generation information to the second in-vehicle device, wherein the relay unit receives from the second in-vehicle device supplementary key information, which is key information used by the first in-vehicle device in encrypted communication, generated by the second in-vehicle device, and relays the received supplementary key information to the first in-vehicle device.
8. The system comprises a first in-vehicle device and a second in-vehicle device, and a relay device, which perform a key generation process for generating and distributing key information used in encrypted communication, wherein the first in-vehicle device monitors its own state and transmits state information indicating the monitored state and key generation information used in the key generation process to the relay device, the relay device relays the state information and key generation information received from the first in-vehicle device to the second in-vehicle device, the second in-vehicle device determines the state based on the state information received from the relay device, if the second in-vehicle device determines that the state is abnormal, it generates supplemental key information, which is the key information used by the first in-vehicle device in encrypted communication, based on the key generation information received from the relay device, the second in-vehicle device transmits the generated supplemental key information to the relay device, and the relay device relays the supplemental key information received from the second in-vehicle device to the first in-vehicle device. The first in-vehicle device is an in-vehicle communication system that uses the supplementary key information received from the relay device in the encrypted communication.
9. An encryption communication program for use in an in-vehicle device that is mounted in a vehicle and performs key generation processing to generate and distribute key information used in encrypted communication, wherein the program causes a computer to function as: a key generation unit that generates first key information which is the key information used by the device, which is the in-vehicle device, in the encrypted communication; an acquisition unit that acquires key generation information used by the other device in the key generation processing from another device, which is another in-vehicle device that performs the key generation processing; a monitoring unit that monitors the status of the other device; and a determination unit that determines the status monitored by the monitoring unit, wherein if the determination unit determines that the status is abnormal, the key generation unit performs key completion processing to generate second key information which is the key information used by the other device in the encrypted communication based on the key generation information acquired by the acquisition unit; and the key generation unit distributes the generated second key information to the other device.
10. An encryption communication program used in an in-vehicle device that performs key generation processing to generate and distribute key information used in encrypted communication, wherein the program causes a computer to function as: a monitoring unit that monitors the status of the in-vehicle device itself; a communication unit that transmits information indicating the status monitored by the monitoring unit and information used in the key generation processing to another in-vehicle device that performs the key generation processing; and a key receiving unit that uses the key information received from the other in-vehicle device in the encrypted communication.
11. A relay program used in a relay device used in an in-vehicle network including a first in-vehicle device and a second in-vehicle device that performs a key generation process for generating and distributing key information used in encrypted communication, wherein the program causes a computer to function as a relay unit that relays information transmitted and received between the first in-vehicle device and the second in-vehicle device, wherein the relay unit receives from the first in-vehicle device state information, which is information indicating the state of the first in-vehicle device, and key generation information, which is information used by the first in-vehicle device in the key generation process, and relays the received state information and key generation information to the second in-vehicle device, and the relay unit receives from the second in-vehicle device supplementary key information, which is key information used by the first in-vehicle device in the encrypted communication, generated by the second in-vehicle device, and relays the received supplementary key information to the first in-vehicle device.