In-vehicle control device, management device, and communication control method

WO2026168456A1PCT designated stage Publication Date: 2026-08-13AUTONETWORKS TECH LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-02-03
Publication Date
2026-08-13

Smart Images

  • Figure JP2026003881_13082026_PF_FP_ABST
    Figure JP2026003881_13082026_PF_FP_ABST
Patent Text Reader

Abstract

According to the present invention, an in-vehicle control device mounted on a vehicle includes: a detection unit that detects a new device which is an in-vehicle device newly connected to an in-vehicle network including one or a plurality of in-vehicle devices; a transmission unit that transmits an authentication request, for requesting execution of authentication processing of the new device detected by the detection unit, to an external device outside the vehicle; a reception unit that receives authentication results of the authentication processing from the external device; and a determination unit that performs determination processing of determining permission or non-permission of communication by the new device, in accordance with the authentication results received by the reception unit.
Need to check novelty before this filing date? Find Prior Art

Description

Vehicle-mounted control device, management device, and communication control method

[0006] ,

[0005] ,

[0001] The present disclosure relates to a vehicle-mounted control device, a management device, and a communication control method. This application claims priority based on Japanese Patent Application No. 2025-18226 filed on February 6, 2025, and incorporates all of the disclosure thereof herein.

[0002] Patent Document 1 (Japanese Unexamined Patent Application Publication No. 2018-7163) discloses the following technology. That is, an in-vehicle device control system includes a plurality of in-vehicle devices that can communicate by an in-vehicle device communication protocol individually set and mounted on a vehicle, a connection device that can mutually convert a plurality of different in-vehicle device communication protocols and a preset standard communication protocol, and a control terminal that can be brought into the vehicle, communicate with the connection device by the standard communication protocol, and control the plurality of in-vehicle devices via the connection device.

[0003] Japanese Unexamined Patent Application Publication No. 2018-7163

[0004] The vehicle-mounted control device of the present disclosure is a vehicle-mounted control device mounted on a vehicle, and includes a detection unit that detects a new device that is a vehicle-mounted device newly connected to a vehicle-mounted network including one or more vehicle-mounted devices, a transmission unit that transmits an authentication request for requesting execution of authentication processing of the new device detected by the detection unit to an external device outside the vehicle, a reception unit that receives an authentication result of the authentication processing from the external device, and a determination unit that performs a determination process of permitting or not permitting communication by the new device according to the authentication result received by the reception unit.

[0005] One aspect of the present disclosure can be realized not only as a vehicle-mounted control device including such a characteristic processing unit, but also as a program for causing a computer to execute steps of such characteristic processing. Further, one aspect of the present disclosure can be realized as a semiconductor integrated circuit that realizes part or all of the vehicle-mounted control device, or can be realized as a system including the vehicle-mounted control device.

[0006] One aspect of this disclosure can be implemented not only as a management device equipped with such characteristic processing, but also as a method in which such characteristic processing is performed in steps, or as a program for causing a computer to perform such steps. Furthermore, one aspect of this disclosure can be implemented as a semiconductor integrated circuit that implements part or all of the management device, or as a system including the management device.

[0007] Figure 1 is a diagram showing an example of the configuration of a vehicle management system according to an embodiment of the present disclosure. Figure 2 is a diagram showing an example of the configuration of an in-vehicle system according to an embodiment of the present disclosure. Figure 3 is a diagram showing an example of the configuration of a new network in an in-vehicle system according to an embodiment of the present disclosure. Figure 4 is a diagram showing an example of the configuration of an in-vehicle relay device according to an embodiment of the present disclosure. Figure 5 is a diagram showing an example of the configuration of a server according to an embodiment of the present disclosure. Figure 6 is a diagram showing an example of a user management table held by a server according to an embodiment of the present disclosure. Figure 7 is a diagram showing an example of a communication table held by a server according to an embodiment of the present disclosure. Figure 8 is a flowchart defining an example of the operation procedure when an in-vehicle relay device according to an embodiment of the present disclosure performs the process of sending an authentication request. Figure 9 is a flowchart defining an example of the operation procedure when a server according to an embodiment of the present disclosure performs the request transmission process. Figure 10 is a diagram showing an example of the processing sequence of in-vehicle equipment, an in-vehicle relay device, a server, and a terminal device in a vehicle management system according to an embodiment of the present disclosure.

[0008] Conventionally, technologies have been developed to customize various settings in in-vehicle equipment installed in a vehicle according to the user's requests.

[0009] [Problems this disclosure aims to solve] After a vehicle is shipped, in-vehicle equipment such as an ECU (Electronic Control Unit) may be newly connected to the in-vehicle network. If a fraudulent in-vehicle device, impersonating a legitimate in-vehicle device, is connected to the in-vehicle network, other in-vehicle devices on that network may be under attack.

[0010] This disclosure was made to solve the aforementioned problems, and its purpose is to provide an in-vehicle control device, a management device, and a communication control method that can improve security in an in-vehicle network.

[0011] [Effects of this disclosure] This disclosure can improve security in in-vehicle networks.

[0012] [Description of Embodiments of the Disclosure] First, the contents of the embodiments of the Disclosure will be listed and described. (1) An in-vehicle control device according to an embodiment of the Disclosure is an in-vehicle control device mounted on a vehicle, comprising: a detection unit that detects a new device which is an in-vehicle device newly connected to an in-vehicle network including one or more in-vehicle devices; a transmission unit that transmits an authentication request to an external device outside the vehicle to request the execution of an authentication process for the new device detected by the detection unit; a receiving unit that receives the authentication result of the authentication process from the external device; and a determination unit that performs a determination process to determine whether to permit or deny communication by the new device according to the authentication result received by the receiving unit.

[0013] In this configuration, the system determines whether or not to allow communication by a newly connected in-vehicle device based on its authentication result. If the authentication result is negative, meaning there is a high probability that the newly connected in-vehicle device is malicious, attacks by that device on the in-vehicle network can be prevented. Therefore, the security of the in-vehicle network can be improved.

[0014] (2) In (1) above, the in-vehicle device may communicate with other in-vehicle devices in accordance with the CAN standard, the in-vehicle control device may further include a relay unit that relays information transmitted and received between the in-vehicle devices, and the determination unit may, as the determination process, perform a process to determine whether to permit or dispermit the relay of communication of the new device in the relay unit.

[0015] With this configuration, in an in-vehicle network where multiple in-vehicle devices communicate with each other according to CAN standards, for example, if the authentication result of an in-vehicle device newly connected to the network is negative, the relay of information transmitted from that in-vehicle device can be stopped, thereby preventing attacks on the in-vehicle device to which the information is intended.

[0016] (3) The management device according to the embodiment of the present disclosure includes a receiving unit that receives an authentication request from a vehicle equipped with the in-vehicle network for requesting the execution of authentication processing for an in-vehicle device newly connected to the in-vehicle network, which includes one or more in-vehicle devices, and a transmitting unit that performs a request transmission process to transmit the authentication request received by the receiving unit to a terminal device corresponding to the vehicle, wherein the receiving unit receives the authentication result of the authentication process from the terminal device, and the transmitting unit transmits the authentication result received by the receiving unit to the vehicle.

[0017] With this configuration, the vehicle can determine whether or not to allow communication by a newly connected in-vehicle device to the in-vehicle network based on the authentication result received from the management device. Therefore, if the authentication result is negative, meaning there is a high probability that the in-vehicle device is a malicious device, attacks by that device on the in-vehicle network can be prevented. Thus, the security of the in-vehicle network can be improved.

[0018] (4) In (3) above, the receiving unit may receive the authentication request from a plurality of vehicles, and the management device may further include a storage unit that holds first correspondence information indicating the correspondence between vehicle identification information, which is the identification information of the vehicle, and user identification information, which is the identification information of the user of the terminal device, and the transmitting unit may perform the request transmission process using the first correspondence information in the storage unit.

[0019] With this configuration, when receiving authentication requests from multiple vehicles, the terminal device to which the authentication request is sent can be easily identified using the first correspondence information.

[0020] (5) In (4) above, the storage unit may store second correspondence information indicating the correspondence between the user identification information and the communication method between the management device and the terminal device, and the management device may further include a modification unit that uses the second correspondence information in the storage unit to change at least one of the method of transmitting the authentication request by the transmitting unit and the method of receiving the authentication result by the receiving unit for each vehicle.

[0021] For example, the method of communication with the terminal device may differ from vehicle to vehicle. With the above configuration, the method of communication with the terminal device corresponding to the vehicle that sent the authentication request can be accurately identified using the second correspondence information, thereby making it possible to send the authentication request to the terminal device or receive the authentication result from the terminal device more reliable.

[0022] (6) In any of (3) to (5) above, the management device may further include a log creation unit that creates log information including the communication history of at least one of the authentication request and the authentication result by the management device, and a storage unit that stores the log information created by the log creation unit.

[0023] This configuration allows for various analyses using log information after the authentication process of newly connected in-vehicle devices to the in-vehicle network.

[0024] (7) A communication control method according to an embodiment of the present disclosure is a communication control method for an in-vehicle control device mounted on a vehicle, comprising the steps of: detecting a new device which is an in-vehicle device newly connected to an in-vehicle network including one or more in-vehicle devices; transmitting an authentication request to an external device outside the vehicle to request the execution of an authentication process for the detected new device; receiving the authentication result of the authentication process from the external device; and performing a determination process to determine whether to permit or deny communication by the new device according to the received authentication result.

[0025] In this way, by determining whether or not to permit communication by an in-vehicle device based on the authentication result of the newly connected in-vehicle device to the in-vehicle network, if the authentication result is negative, i.e., if there is a high probability that the newly connected in-vehicle device is a malicious in-vehicle device, it is possible to prevent attacks by that in-vehicle device on the in-vehicle network. Therefore, the security of the in-vehicle network can be improved.

[0026] Embodiments of this disclosure will be described below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals, and their descriptions will not be repeated. Furthermore, at least some of the embodiments described below may be combined in any way.

[0027] [Vehicle Management System] Figure 1 is a diagram showing an example of the configuration of a vehicle management system according to an embodiment of the present disclosure. Referring to Figure 1, the vehicle management system 501 comprises a server 151, one or more in-vehicle systems 301, and one or more terminal devices 171. The server 151 is an example of an external device and an example of a management device.

[0028] In the example shown in Figure 1, the vehicle management system 501 comprises a plurality of in-vehicle systems 301 and a plurality of terminal devices 171. The plurality of in-vehicle systems 301 are each installed in a plurality of vehicles 1. The plurality of terminal devices 171 are each owned by a user of a plurality of vehicles 1. The terminal devices 171 are communication terminal devices such as smartphones and tablets.

[0029] Server 151 is located outside of vehicle 1. Server 151 manages information regarding the terminal device 171 corresponding to each vehicle 1. Server 151 is used, for example, by the manufacturer of vehicle 1.

[0030] The server 151 and each terminal device 171 transmit and receive information via an external network 161, such as the Internet.

[0031] [In-vehicle system] Figure 2 is a diagram showing an example of the configuration of an in-vehicle system according to an embodiment of the present disclosure. Referring to Figure 2, the in-vehicle system 301 comprises an in-vehicle relay device 101 and a plurality of in-vehicle devices 202. The in-vehicle relay device 101 is an example of an in-vehicle control device.

[0032] In the example shown in Figure 2, the in-vehicle system 301 includes a plurality of in-vehicle devices 202, namely in-vehicle devices 202A, 202B, 202C, 202D, 202E, and 202F.

[0033] The in-vehicle equipment 202 includes in-vehicle ECUs, sensors, navigation systems, human-machine interfaces, and cameras. The in-vehicle ECUs include TCUs (Telematics Communication Units), autonomous driving ECUs, engine ECUs, steering control ECUs, door control ECUs, and facial recognition ECUs.

[0034] The in-vehicle equipment 202 is connected to the in-vehicle relay device 101, for example, via a CAN (Controller Area Network) bus 51. The in-vehicle relay device 101 and the multiple in-vehicle equipment 202 constitute an in-vehicle network 401.

[0035] In the example shown in Figure 2, the in-vehicle devices 202A and 202B are connected to the in-vehicle relay device 101 via CAN bus 51A, which is CAN bus 51. The in-vehicle devices 202C and 202D are connected to the in-vehicle relay device 101 via CAN bus 51B, which is CAN bus 51. The in-vehicle devices 202E and 202F are connected to the in-vehicle relay device 101 via CAN bus 51C, which is CAN bus 51.

[0036] The in-vehicle device 202 communicates with other in-vehicle devices 202 in accordance with the CAN standard. Specifically, each in-vehicle device 202 transmits a CAN frame containing various information, such as information to assist the automated driving performed by the vehicle 1 and information used for entertainment, to other in-vehicle devices 202 via the in-vehicle relay device 101.

[0037] Note that the in-vehicle device 202 is not limited to a configuration connected to the in-vehicle relay device 101 via the CAN bus 51, and may be configured to be connected to the in-vehicle relay device 101 via a transmission line conforming to CAN FD (CAN with Flexible Data Rate).

[0038] The in-vehicle relay device 101 is, for example, a gateway device. The in-vehicle relay device 101 performs a relay process for relaying information transmitted and received between the in-vehicle devices 202.

[0039] Further, the in-vehicle relay device 101 creates a CAN frame including various pieces of information described later and transmits it to the in-vehicle device 202.

[0040] [TCU] In the example shown in FIG. 2, the in-vehicle device 202A is a TCU. In the following description, the in-vehicle device 202A is also referred to as the TCU 202A.

[0041] Referring to FIGS. 1 and 2, the TCU 202A communicates with the server 151 via, for example, the radio base station device 181.

[0042] More specifically, the TCU 202A performs wireless communication with the radio base station device 181 in accordance with a communication standard such as LTE (Long Term Evolution) (registered trademark) or 5G.

[0043] Specifically, when the TCU 202A receives a CAN frame including various pieces of information from the in-vehicle relay device 101, it transmits a wireless signal including the various pieces of information to the radio base station device 181.

[0044] When the radio base station device 181 receives a wireless signal from the TCU 202A, it transmits various pieces of information included in the received wireless signal to the server 151 via the external network 161.

[0045] Further, when the radio base station device 181 receives an IP packet from the server 151 via the external network 161, it includes the received IP packet in a wireless signal and transmits it to the TCU 202A.

[0046] When the TCU 202A receives a wireless signal including an IP packet from the server 151 from the wireless base station device 181, it acquires the IP packet from the received wireless signal. Then, the TCU 202A stores the acquired IP packet in a CAN frame and transmits it to the in-vehicle relay device 101.

[0047] [New Network] In the following description, an in-vehicle device 202 newly connected to the in-vehicle network 401 shown in FIG. 2 is also referred to as a "new device", and the in-vehicle network 401 including the new device is also referred to as a "new network".

[0048] FIG. 3 is a diagram showing an example of the configuration of a new network in an in-vehicle system according to an embodiment of the present disclosure. FIG. 3 shows the configuration of the in-vehicle network 401 in which an in-vehicle device 202G is newly added to the in-vehicle network 401 shown in FIG. 2.

[0049] Referring to FIG. 3, the in-vehicle device 202G is connected to the in-vehicle relay device 101 via the CAN bus 51C.

[0050] Referring to FIG. 1 again, the terminal device 171 performs authentication processing of a new device connected to the in-vehicle relay device 101 of the vehicle 1 owned by the user of the terminal device 171, and transmits the authentication result C of the authentication processing to the vehicle 1 via the server 151.

[0051] [In-vehicle Relay Device] FIG. 4 is a diagram showing an example of the configuration of an in-vehicle relay device according to an embodiment of the present disclosure. Referring to FIG. 4, the in-vehicle relay device 101 includes a relay unit 11, a processing unit 12, and a storage unit 13. The processing unit 12 includes a device management unit 21, a communication unit 22, and a determination unit 23. One or both of the relay unit 11 and the processing unit 12 are realized by, for example, a processing circuit (Circuitry) including one or more processors. The storage unit 13 is, for example, a non-volatile memory included in the processing circuit. The device management unit 21 is an example of a detection unit. The communication unit 22 is an example of a transmission unit and also an example of a reception unit.

[0052] (Relay Unit) The relay unit 11 receives CAN frames transmitted from a certain in-vehicle device 202. For example, the storage unit 13 stores a correspondence table that shows the correspondence between CAN-IDs and the devices to which the CAN frames are transmitted.

[0053] When the relay unit 11 receives a CAN frame transmitted from a certain in-vehicle device 202, it checks the destination device of the received CAN frame by referring to the correspondence table in the storage unit 13.

[0054] Then, if the relay unit 11 determines that the destination device for the received CAN frame is its own in-vehicle relay device 101, it outputs the CAN frame to the processing unit 12.

[0055] Furthermore, if the destination of a received CAN frame is an in-vehicle device 202 connected to the same CAN bus 51 as the source device 202 of the CAN frame (hereinafter also referred to as the "source device"), the relay unit 11 discards the CAN frame.

[0056] Furthermore, if the destination of the received CAN frame is an in-vehicle device 202 connected to a CAN bus 51 different from the source device, the relay unit 11 checks whether the source device is authenticated or not.

[0057] For example, the storage unit 13 stores an unauthenticated list that indicates the CAN-ID included in the CAN frame transmitted from an unauthenticated in-vehicle device 202.

[0058] The relay unit 11 checks whether the CAN-ID included in the received CAN frame is registered in the unauthenticated list if the destination of the received CAN frame is an in-vehicle device 202 connected to a CAN bus 51 different from the source device.

[0059] Then, the relay unit 11 performs relay processing if the CAN-ID included in the received CAN frame is not registered in the unauthenticated list.

[0060] On the other hand, the relay unit 11 does not perform relay processing if the CAN-ID included in the received CAN frame is registered in the unauthenticated list.

[0061] (Equipment Management Unit) Referring to Figures 3 and 4, the equipment management unit 21 detects new equipment in the new network. In this case, the equipment management unit 21 detects the in-vehicle equipment 202G as new equipment.

[0062] For example, when the in-vehicle device 202G is connected to the CAN bus 51C, it sends a connection request notification to the in-vehicle relay device 101 indicating that it is requesting a communication connection on the in-vehicle network 401 and that it has its own CAN-ID.

[0063] In the in-vehicle relay device 101, when the device management unit 21 receives a connection request notification from the in-vehicle device 202G via the relay unit 11, it detects the in-vehicle device 202, i.e., the in-vehicle device 202G, which is the source of the connection request notification, as a new device. The device management unit 21 then outputs detection result information to the communication unit 22 indicating that a new device has been detected and the CAN-ID indicated in the connection request notification.

[0064] The device management unit 21 may also be configured to periodically broadcast a search message via the relay unit 11 to detect new devices. In this case, the new device receives the search message and sends a connection request notification as a response to the received search message.

[0065] Furthermore, when the device management unit 21 detects a new device, it updates the unauthenticated list in the storage unit 13.

[0066] Specifically, for example, when the device management unit 21 detects a new device, it reads the unauthenticated list in the storage unit 13. Then, the device management unit 21 registers the CAN-ID indicated by the connection request notification received from the new device in the unauthenticated list.

[0067] (Sending of authentication request R) The communication unit 22 sends an authentication request R to the server 151 to request the execution of authentication processing for the new device detected by the device management unit 21.

[0068] For example, the storage unit 13 stores identification information (hereinafter also referred to as "vehicle ID") of the vehicle 1 on which its in-vehicle relay device 101 is installed. The vehicle ID is an example of vehicle identification information.

[0069] When the communications unit 22 receives detection result information from the equipment management unit 21, it sends a transmission request R to the server 151 indicating that it requests the transmission of the authentication result C for the authentication process of the new equipment.

[0070] Specifically, for example, the communication unit 22 transmits request information Q, which includes an authentication request R, a CAN-ID indicated by the detection result information received from the equipment management unit 21, and a vehicle ID stored in the storage unit 13, to the server 151 via the relay unit 11 and the TCU 202A.

[0071] When the communication unit 22 sends the request information Q to the server 151, it outputs a request completion notification to the determination unit 23 indicating that the request information Q has been sent.

[0072] [Server] Figure 5 shows an example of the configuration of a server according to an embodiment of the present disclosure. Referring to Figure 5, the server 151 comprises a communication unit 31, a modification unit 32, a log creation unit 33, and a storage unit 34. Some or all of the communication unit 31, the modification unit 32, and the log creation unit 33 are implemented by a processing circuit including, for example, one or more processors. The storage unit 34 is, for example, a non-volatile memory included in the processing circuit. The communication unit 31 is an example of a receiving unit and an example of a transmitting unit.

[0073] (Receiving Authentication Request R) Referring to Figures 1, 4, and 5, for example, the communication unit 31 receives authentication requests R from multiple vehicles 1. More specifically, for example, the communication unit 31 receives request information Q, including the authentication request R, from the TCU 202A in each vehicle 1 via the wireless base station device 181 and the external network 161.

[0074] The communication unit 31 stores the request information Q received from the TCU 202A of a certain vehicle 1 in the storage unit 34.

[0075] Furthermore, the communication unit 31 notifies the log creation unit 33 of the reception time ta of the authentication request R received from the vehicle 1. More specifically, the server 151 is equipped with a counter (not shown). The communication unit 31 notifies the log creation unit 33 of the count value of the counter at the time of reception of the request information Q as the reception time ta.

[0076] Specifically, the communication unit 31 outputs time information L1, which indicates the reception time ta and the vehicle ID included in the received request information Q, to the log creation unit 33.

[0077] (User Management Table) Figure 6 shows an example of a user management table held by a server according to the embodiment of this disclosure.

[0078] Referring to Figure 6, for example, the storage unit 34 holds a user management table Tb1 that shows the correspondence between the vehicle ID and the user identification information of the terminal device 171 (hereinafter also referred to as "user ID"). User ID is an example of user identification information. User management table Tb1 is an example of the first correspondence information.

[0079] In the example shown in Figure 6, in the user management table Tb1, the user ID of the user who owns terminal device 171 corresponding to vehicle 1 with vehicle ID "xxx" is "11111". The user ID of the user who owns terminal device 171 corresponding to vehicle 1 with vehicle ID "yyy" is "22222". The user ID of the user who owns terminal device 171 corresponding to vehicle 1 with vehicle ID "zzz" is "33333".

[0080] (Communication Table) Figure 7 shows an example of a communication table held by a server according to an embodiment of the present disclosure.

[0081] Referring to Figure 7, for example, the storage unit 34 stores a communication table Tb2 that shows the correspondence between the user ID, the communication method M between its own server 151 and terminal device 171, and the contact information of the terminal device 171. The communication table Tb2 is an example of second correspondence information.

[0082] The communication methods M registered in the communication table Tb2 include "email," "SMS (Short Message Service)," and "dedicated message." A "dedicated message" is a message sent when the terminal device 171 is a dedicated terminal that performs authentication processing for new equipment.

[0083] In the communication table Tb2, if the communication method M is "email", the contact information is the email address. If the communication method M is "SMS", the contact information is the telephone number. If the communication method M is "private message", the contact information is the identification information of the terminal device 171 (hereinafter also referred to as "terminal ID").

[0084] In the communication table Tb2 shown in Figure 7, the communication method M between server 151 and terminal device 171 owned by user ID "11111", and the contact information for terminal device 171 are "mail" and "AAA@dddd.jp", respectively. The communication method M between server 151 and terminal device 171 owned by user ID "22222", and the contact information for terminal device 171 are "SMS" and "080-bbbb-cccc". The communication method M between server 151 and terminal device 171 owned by user ID "33333", and the contact information for terminal device 171 are "private message" and terminal ID "EEE", respectively.

[0085] (Sending of Authentication Request R) Referring again to Figure 5, the communication unit 31 performs a request transmission process to send the received authentication request R to the terminal device 171 corresponding to the vehicle 1 that sent the authentication request R.

[0086] More specifically, for example, the communication unit 31 performs request transmission processing using the user management table Tb1 in the storage unit 34.

[0087] Specifically, when the communication unit 31 receives request information Q from the vehicle 1, it refers to the user management table Tb1 in the storage unit 34 to identify the user ID corresponding to the vehicle ID contained in the request information Q. Then, the communication unit 31 notifies the modification unit 32 of the identified user ID.

[0088] For example, the modification unit 32 uses the communication table Tb2 in the storage unit 34 to perform modification processing for each vehicle 1 to change the method of sending authentication requests R and receiving authentication results C by its own server 151.

[0089] More specifically, for example, when the modification unit 32 receives a notification from the communication unit 31, it refers to the communication table Tb2 in the storage unit 34 to identify the communication method M and contact information corresponding to the user ID notified by the communication unit 31. The modification unit 32 then outputs destination information indicating the identified communication method M and contact information, along with the user ID, to the communication unit 31.

[0090] The communication unit 31 transmits the authentication request R contained in the request information Q received from the vehicle 1 to the terminal device 171 (hereinafter also referred to as the "corresponding terminal device") owned by the user ID indicated in the destination information received from the modification unit 32, via the external network 161, in accordance with the communication method M indicated in the destination information.

[0091] Specifically, for example, if the communication method M indicated by the destination information received from the modification unit 32 is "email", the communication unit 31 sends an HTML (HyperText Markup Language) email, which includes an authentication request R and is addressed to the email address indicated by the destination information received from the modification unit 32, to the corresponding terminal device.

[0092] Furthermore, for example, if the communication method M indicated by the destination information received from the modification unit 32 is "SMS", the communication unit 31 sends an SMS to the corresponding terminal device that includes an authentication request R and is addressed to the telephone number indicated by the destination information received from the modification unit 32.

[0093] Furthermore, for example, if the communication method M indicated by the destination information received from the modification unit 32 is a "dedicated message", the communication unit 31 sends a dedicated message corresponding to the authentication request R to the terminal device corresponding to the terminal ID indicated by the destination information received from the modification unit 32.

[0094] When the communication unit 31 sends an authentication request R to the corresponding terminal device, it notifies the log creation unit 33 of the transmission time tb of the authentication request R. More specifically, the communication unit 31 notifies the log creation unit 33 of the count value of the counter on its own server 151 at the time of transmission of the authentication request R as the transmission time tb.

[0095] Specifically, the communication unit 31 outputs time information L2, which indicates the transmission time tb and the vehicle ID corresponding to the authentication request R sent to the corresponding terminal device, to the log creation unit 33.

[0096] Furthermore, if the only difference between multiple terminal devices 171, each corresponding to a different vehicle 1, is the method of receiving authentication requests R from the server 151, the server 151 may be configured to change only the method of sending authentication requests R to the terminal devices 171 for each vehicle 1.

[0097] Furthermore, if the only difference between multiple terminal devices 171 is the method of sending the authentication result C to the server 151, the server 151 may be configured to change only the method of receiving the authentication result C from the terminal devices 171 for each vehicle 1.

[0098] Furthermore, if the method for receiving authentication requests R from the server 151 and the method for sending authentication results C to the server 151 are the same for each terminal device 171 in the vehicle management system 501, the server 151 may not maintain the communication table Tb2 and may not perform any modification processing.

[0099] [Terminal device] Referring again to Figure 1, when the terminal device 171 receives an authentication request R from the server 151 via the external network 161, it performs authentication processing for the new device.

[0100] More specifically, for example, terminal device 171 performs notification processing based on the authentication request R received from server 151.

[0101] Specifically, for example, when terminal device 171 receives an authentication request R from server 151, it displays a screen G on its own display unit prompting the user to input whether or not to allow the connection of a new device to the in-vehicle network 401. This allows the user to authenticate a new device even when they are away from their own vehicle 1.

[0102] The terminal device 171 transmits the authentication result C of the authentication process for the new device to the server 151 via the external network 161.

[0103] More specifically, for example, the terminal device 171 accepts user input operations on the screen G displayed on its display unit.

[0104] For example, when terminal device 171 receives input indicating permission to connect a new device, it sends connection permission information C1, which indicates permission to connect a new device to the in-vehicle network 401 and the user ID of the user who owns it, to server 151 as authentication result C.

[0105] Furthermore, for example, when terminal device 171 receives input indicating that it does not permit the connection of a new device, it sends connection denial information C2, which indicates that it does not permit the connection of a new device to the in-vehicle network 401 and the user ID of the user who owns it, to server 151 as authentication result C.

[0106] [Server] (Receipt of authentication result C) Referring again to Figure 5, in the server 151, the communication unit 31 receives the authentication result C from the terminal device 171 via the external network 161.

[0107] When the communication unit 31 receives the authentication result C from the terminal device 171, it refers to the user management table Tb1 in the storage unit 34 to identify the vehicle ID corresponding to the user ID indicated by the authentication result C.

[0108] When the communication unit 31 identifies the vehicle ID, it notifies the log creation unit 33 of the time tc when the authentication result C from the terminal device 171 was received. More specifically, the communication unit 31 notifies the log creation unit 33 of the count value of its own server 151's counter at the time the authentication result C was received, as the reception time tc.

[0109] Specifically, the communication unit 31 outputs time information L3, which indicates the reception time tc and the identified vehicle ID, to the log creation unit 33.

[0110] (Transmission of authentication result C) When the communication unit 31 identifies the vehicle ID, it retrieves the request information Q from the one or more request information Q stored in the storage unit 34 that contains the same vehicle ID as the vehicle ID in question.

[0111] The communication unit 31 includes the CAN-ID contained in the retrieved request information Q in the authentication result C received from the terminal device 171. The communication unit 31 then creates an IP packet (hereinafter also referred to as "packet P") containing the authentication result C, which includes the IP address of its own server 151 and the IP address of vehicle 1 with the identified vehicle ID as the source IP address and destination IP address, respectively.

[0112] The communications unit 31 transmits the created packet P to the TCU 202A via the external network 161 and the wireless base station equipment 181.

[0113] The communication unit 31 notifies the log creation unit 33 of the transmission time td of the authentication result C to the TCU 202A. More specifically, when the communication unit 31 transmits packet P to the TCU 202A, it notifies the log creation unit 33 of the count value of its own server 151's counter at the time of transmission of packet P as the transmission time td.

[0114] Specifically, the communication unit 31 outputs time information L4, which indicates the transmission time td and the identified vehicle ID, to the log creation unit 33.

[0115] (Log creation unit) For example, the log creation unit 33 creates log information including the communication history W of the authentication request R and authentication result C from its own server 151.

[0116] Specifically, when the log creation unit 33 receives time information L1, L2, L3, and L4 containing the same vehicle ID from the communication unit 31, it creates log information that includes the vehicle ID, the reception time ta, tc, and the transmission time tb, td as a communication history W. The log creation unit 33 then stores the created log information in the storage unit 34.

[0117] [In-vehicle relay device] (Reception of authentication result C) Referring again to Figures 3 and 4, TCU 202A transmits the authentication result C contained in packet P received from server 151 via external network 161 and wireless base station device 181 to in-vehicle relay device 101.

[0118] In the in-vehicle relay device 101, the communication unit 22 receives the authentication result C from the server 151 via the TCU 202A and the relay unit 11. The communication unit 22 then outputs the authentication result C received from the server 151 to the determination unit 23.

[0119] (Decision Processing) The decision unit 23 performs a decision processing to determine whether to permit or deny communication by the new device on the new network, according to the authentication result C received by the communication unit 22.

[0120] More specifically, for example, the determination unit 23 performs a determination process to determine whether to permit or deny the relaying of communications from the new device in the relay unit 11.

[0121] For example, if the authentication result C does not arrive from the server 151 within a predetermined time, or if the authentication result C received from the server 151 is negative, the determination unit 23 will decide not to allow the relay of communication from the new device.

[0122] Specifically, the determination unit 23 determines that it will not permit the relay of communication from the new device if the authentication result C does not arrive within a predetermined time after receiving a request completion notification from the communication unit 22, or if the authentication result C received from the communication unit 22 is connection rejection information C2.

[0123] On the other hand, the determination unit 23 receives an authentication result C from the server 151 within a predetermined time, and if the authentication result C is positive, it determines that it will permit the relay of communication from the new device.

[0124] Specifically, the determination unit 23 receives an authentication result C from the communication unit 22 within a predetermined time after receiving a request completion notification from the communication unit 22, and if the authentication result C is connection permission information C1, it determines to permit the relay of communication from the new device.

[0125] The determination unit 23 then notifies the equipment management unit 21 of the CAN-ID included in the connection permission information C1 received from the communication unit 22.

[0126] The device management unit 21 updates the unauthenticated list if the decision unit 23 permits the relaying of communications from a new device.

[0127] Specifically, for example, when the device management unit 21 receives a notification from the judgment unit 23, it reads the unauthenticated list in the storage unit 13. Then, the device management unit 21 removes the CAN-ID notified by the judgment unit 23 from the unauthenticated list.

[0128] [Operation Flow] Next, the operation flow of each device in the vehicle management system 501 according to the embodiment of this disclosure will be explained with reference to the drawings.

[0129] Figure 8 is a flowchart illustrating an example of the operation procedure when an in-vehicle relay device according to an embodiment of the present disclosure performs the process of transmitting an authentication request.

[0130] Referring to Figure 8, first, the in-vehicle relay device 101 waits for a connection request notification from the in-vehicle equipment 202 (NO in step ST101).

[0131] Then, when the in-vehicle relay device 101 receives a connection request notification from the in-vehicle device 202 (YES in step ST101), it detects the in-vehicle device 202 as a new device (step ST102).

[0132] Next, when the in-vehicle relay device 101 detects a new device, it updates the unauthenticated list in the storage unit 13. For example, as described above, the in-vehicle relay device 101 registers the CAN-ID indicated by the connection request notification received from the new device in the unauthenticated list (step ST103).

[0133] Next, when the in-vehicle relay device 101 updates the unauthenticated list, it sends an authentication request R to the server 151 to request the execution of the authentication process for the new device. For example, as described above, the in-vehicle relay device 101 sends request information Q, which includes the authentication request R, the vehicle ID, and the CAN-ID of the new device, to the server 151 (step ST104).

[0134] Next, the in-vehicle relay device 101 receives an authentication result C from the server 151 within a predetermined time, and if the authentication result C is connection permission information C1 (YES in step ST105), it decides to allow relaying of communication from the new device (step ST106).

[0135] Next, when the in-vehicle relay device 101 determines that it is authorized to relay communication from a new device, it updates the unauthenticated list in the storage unit 13. For example, as described above, the in-vehicle relay device 101 removes the CAN-ID included in the connection authorization information C1 from the unauthenticated list (step ST107) and waits to receive a new connection request notification from the in-vehicle device 202 (NO in step ST101).

[0136] On the other hand, if the authentication result C received from the server 151 is connection rejection information C2, or if the authentication result C does not arrive from the server 151 within a predetermined time (NO in step ST105), the in-vehicle relay device 101 decides not to allow relaying of communication from the new device (step ST108) and waits to receive a new connection request notification from the in-vehicle device 202 (NO in step ST101).

[0137] Figure 9 is a flowchart illustrating an example of the operation procedure when a server according to the embodiment of this disclosure performs the process of sending a request transmission process.

[0138] Referring to Figure 9, first, the server 151 waits for the receipt of request information Q from the vehicle 1 (NO in step ST201).

[0139] Then, when the server 151 receives request information Q from the vehicle 1 (YES in step ST201), it refers to the user management table Tb1 in the storage unit 34 to identify the user ID corresponding to the vehicle ID contained in the received request information Q (step ST202).

[0140] Next, when the server 151 identifies the user ID, it performs a request transmission process to send the authentication request R contained in the received request information Q to the terminal device 171 owned by the user of that user ID. For example, as described above, the server 151 identifies the communication method M and contact information corresponding to the identified user ID by referring to the communication table Tb2 in the storage unit 34. Then, the server 151 sends the authentication request R contained in the received request information Q to the terminal device 171 owned by the user of that user ID according to the communication method M (step ST203).

[0141] Next, the server 151 waits for the authentication result C to be received from the terminal device 171 (NO in step ST204).

[0142] Then, when server 151 receives authentication result C from terminal device 171 (YES in step ST204), it includes the CAN-ID contained in the request information Q received from vehicle 1 in the authentication result C and sends it to vehicle 1 (step ST205), and waits to receive new request information Q from vehicle 1 (NO in step ST201).

[0143] Figure 10 shows an example of the processing sequence of in-vehicle equipment, in-vehicle relay device, server, and terminal device in a vehicle management system according to an embodiment of the present disclosure.

[0144] Referring to Figure 10, first, when the in-vehicle device 202 is newly connected to the in-vehicle network 401, it sends a connection request notification to the in-vehicle relay device 101 (step ST301).

[0145] Next, when the in-vehicle relay device 101 receives a connection request notification from the in-vehicle device 202, it detects the in-vehicle device 202 as a new device (step ST302).

[0146] Next, when the in-vehicle relay device 101 detects a new device, it updates the unauthenticated list in the storage unit 13. For example, as described above, the in-vehicle relay device 101 registers the CAN-ID indicated by the received connection request notification in the unauthenticated list (step ST303).

[0147] Next, when the in-vehicle relay device 101 updates the unauthenticated list, it sends a request information Q to the server 151, which includes an authentication request R to request the execution of authentication processing for the new device, the vehicle ID, and the CAN-ID of the new device (step ST304).

[0148] Next, when the server 151 receives request information Q from the in-vehicle relay device 101, it refers to the user management table Tb1 in the storage unit 13 to identify the user ID corresponding to the vehicle ID included in the request information Q (step ST305).

[0149] Next, the server 151 sends the authentication request R contained in the received request information Q to the terminal device 171 owned by the user with the identified user ID (step ST306).

[0150] Next, when the terminal device 171 receives an authentication request R from the server 151, it performs notification processing based on the received authentication request R. For example, as described above, the terminal device 171 displays a screen G on its display unit prompting the user to input whether or not to allow the connection of a new device to the in-vehicle network 401 (step ST307).

[0151] Next, the terminal device 171 accepts user input for the screen G displayed on its display unit (step ST308). Here, it is assumed that the terminal device 171 has received input to authorize the connection of a new device.

[0152] Next, the terminal device 171 sends connection permission information C1, which indicates permission to connect a new device and the user ID of the user who owns it, to the server 151 as authentication result C (step ST309).

[0153] Next, when the server 151 receives connection permission information C1 from the terminal device 171, it transmits the received connection permission information C1 to the in-vehicle relay device 101. For example, as described above, the server 151 includes the CAN-ID contained in the received request information Q in the connection permission information C1 and transmits it to the in-vehicle relay device 101 (step ST310).

[0154] Next, when the in-vehicle relay device 101 receives connection permission information C1 from the server 151 within a predetermined time, it decides to permit relaying of communication from the new device (step ST311).

[0155] Next, when the in-vehicle relay device 101 determines that it is authorized to relay communication from a new device, it updates the unauthenticated list in the storage unit 13. For example, as described above, the in-vehicle relay device 101 removes the CAN-ID included in the received connection permission information C1 from the unauthenticated list (step ST312).

[0156] Next, the in-vehicle relay device 101 performs relay processing. For example, as described above, the in-vehicle relay device 101 relays a CAN frame received from an in-vehicle device 202, which is destined for a new device, to the new device. The in-vehicle relay device 101 also relays a CAN frame received from the new device to the destination in-vehicle device 202 (step ST313).

[0157] In the vehicle management system 501 according to the embodiment of this disclosure, the in-vehicle relay device 101 is configured to perform a decision process to determine whether to permit or deny communication by a new device in accordance with the authentication result C received from the server 151, but the invention is not limited to this configuration. A device other than the in-vehicle relay device 101 in the in-vehicle network 401 may perform the decision process and notify the device such as the in-vehicle relay device 101 of the decision result.

[0158] Furthermore, in the vehicle management system 501 according to the embodiment of this disclosure, the server 151 is configured to maintain a user management table Tb1 that shows the correspondence between vehicle IDs and user IDs, and to perform request transmission processing using the user management table Tb1, but the system is not limited to this. The server 151 may be configured not to maintain a user management table Tb1. In this case, for example, the in-vehicle relay device 101 includes the user ID corresponding to vehicle 1 in the request information Q and sends it to the server 151. The server 151 identifies the terminal device 171 to which the authentication request R is sent by confirming the user ID included in the request information Q.

[0159] Furthermore, in the vehicle management system 501 according to the embodiment of this disclosure, the server 151 is configured to perform a modification process that changes at least one of the methods for sending an authentication request R to the terminal device 171 and the method for receiving an authentication result C from the terminal device 171 for each vehicle 1, using the communication table Tb2 it holds. However, the system is not limited to this configuration. The server 151 may not hold a communication table Tb2. In this case, for example, the in-vehicle relay device 101 sends to the server 151 a request information Q that includes the communication method M between the server 151 and the terminal device 171, as well as the contact information of the terminal device 171, corresponding to the vehicle 1.

[0160] Furthermore, in the vehicle management system 501 according to the embodiment of this disclosure, the server 151 is configured to create log information including the communication history of authentication requests R and authentication results C by itself and store it in the storage unit 34, but it is not limited to this. The log information may be configured to include the communication history of either the authentication request R or the authentication result C by the server 151. Alternatively, the server 151 may be configured not to create log information.

[0161] Furthermore, some or all of the functions of the server 151 according to the embodiment of this disclosure may be provided by cloud computing. That is, the server 151 according to the embodiment of this disclosure may be a cloud server composed of multiple servers.

[0162] The embodiments described above should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than the above description, and all modifications within the meaning and scope of the claims are intended to be included.

[0163] Each process (each function) in the above-described embodiment is implemented by a processing circuit including one or more processors. The processing circuit may consist of an integrated circuit, etc., which combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the above processes. The one or more processors may execute each of the above processes according to the programs read from the one or more memories, or they may execute each of the above processes according to logic circuits that have been designed in advance to execute each of the above processes. The above-mentioned processor may be various processors suitable for computer control, such as a CPU (Central Processing Unit), GPU (Graphics Processing Unit), DSP (Digital Signal Processor), FPGA (Field Programmable Gate Array), and ASIC (Application Specific Integrated Circuit). Furthermore, multiple physically separated processors may cooperate with each other to perform the above-mentioned processes. For example, processors installed in multiple physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), WAN (Wide Area Network), and the Internet to perform the above-mentioned processes. The above program may be installed on the above memory via the above network from an external server device, or it may be distributed on a recording medium such as a CD-ROM (Compact Disc Read Only Memory), DVD-ROM (Digital Versatile Disc Read Only Memory), or semiconductor memory, and then installed on the above memory from the above recording medium.

[0164] The above description includes the following features: [Addendum 1] A device authentication method for a management device, comprising the steps of: receiving an authentication request from a vehicle equipped with an in-vehicle network to request the execution of authentication processing for an in-vehicle device newly connected to an in-vehicle network including one or more in-vehicle devices; performing a request transmission process to transmit the received authentication request to a terminal device corresponding to the vehicle; receiving the authentication result of the authentication process from the terminal device; and transmitting the received authentication result to the vehicle.

[0165] [Note 2] An in-vehicle control device mounted on a vehicle, comprising a processing circuit, wherein the processing circuit detects a new device which is an in-vehicle device newly connected to an in-vehicle network including one or more in-vehicle devices, transmits an authentication request to an external device outside the vehicle to request the execution of an authentication process for the detected new device, receives the authentication result of the authentication process from the external device, and performs a decision process to determine whether to permit or deny communication by the new device according to the received authentication result.

[0166] [Note 3] A management device comprising a processing circuit, the processing circuit receiving an authentication request from a vehicle equipped with the in-vehicle network for requesting the execution of authentication processing for an in-vehicle device newly connected to the in-vehicle network, which includes one or more in-vehicle devices; performing a request transmission process to send the received authentication request to a terminal device corresponding to the vehicle; receiving the authentication result of the authentication process from the terminal device; and transmitting the received authentication result to the vehicle.

[0167] 1 Vehicle 11 Relay Unit 12 Processing Unit 13, 34 Storage Unit 21 Equipment Management Unit 22, 31 Communication Unit 23 Decision Unit 32 Change Unit 33 Log Creation Unit 51 CAN Bus 101 In-vehicle Relay Device 202 In-vehicle Equipment 151 Server 161 External Network 171 Terminal Device 181 Wireless Base Station Device 301 In-vehicle System 401 In-vehicle Network 501 Vehicle Management System Tb1 User Management Table Tb2 Communication Table

Claims

1. An in-vehicle control device mounted on a vehicle, comprising: a detection unit for detecting a new device which is an in-vehicle device newly connected to an in-vehicle network including one or more in-vehicle devices; a transmission unit for transmitting an authentication request to an external device outside the vehicle to request the execution of an authentication process for the new device detected by the detection unit; a receiving unit for receiving the authentication result of the authentication process from the external device; and a determination unit for performing a determination process to determine whether to permit or deny communication by the new device according to the authentication result received by the receiving unit.

2. The in-vehicle device communicates with other in-vehicle devices in accordance with CAN standards, and the in-vehicle control device further comprises a relay unit that relays information transmitted and received between the in-vehicle devices, and the determination unit performs a determination process to determine whether to permit or dispermit the relay of communication of the new device in the relay unit.

3. A management device comprising: a receiving unit that receives an authentication request from a vehicle equipped with an in-vehicle network for requesting the execution of authentication processing for an in-vehicle device newly connected to an in-vehicle network including one or more in-vehicle devices; and a transmitting unit that performs request transmission processing to transmit the authentication request received by the receiving unit to a terminal device corresponding to the vehicle, wherein the receiving unit receives the authentication result of the authentication processing from the terminal device, and the transmitting unit transmits the authentication result received by the receiving unit to the vehicle.

4. The management device according to claim 3, wherein the receiving unit receives the authentication request from a plurality of vehicles, the management device further includes a storage unit that holds first correspondence information indicating the correspondence between vehicle identification information, which is the identification information of the vehicle, and user identification information, which is the identification information of the user of the terminal device, and the transmitting unit performs the request transmission process using the first correspondence information in the storage unit.

5. The management device according to claim 4, wherein the storage unit holds second correspondence information indicating the correspondence between the user identification information and the communication method between the management device and the terminal device, and the management device further includes a modification unit that uses the second correspondence information in the storage unit to change at least one of the method of transmitting the authentication request by the transmitting unit and the method of receiving the authentication result by the receiving unit for each vehicle.

6. The management device according to any one of claims 3 to 5, further comprising: a log creation unit that creates log information including communication history of at least one of the authentication request and the authentication result by the management device; and a storage unit that stores the log information created by the log creation unit.

7. A communication control method for an in-vehicle control device mounted on a vehicle, comprising the steps of: detecting a new device which is an in-vehicle device newly connected to an in-vehicle network including one or more in-vehicle devices; transmitting an authentication request to an external device outside the vehicle to request the execution of an authentication process for the detected new device; receiving the authentication result of the authentication process from the external device; and performing a decision process to determine whether to permit or deny communication by the new device according to the received authentication result.