WO2017130717A1 - 車載器及びコンピュータプログラム - Google Patents

車載器及びコンピュータプログラム Download PDF

Info

Publication number
WO2017130717A1
WO2017130717A1 PCT/JP2017/000808 JP2017000808W WO2017130717A1 WO 2017130717 A1 WO2017130717 A1 WO 2017130717A1 JP 2017000808 W JP2017000808 W JP 2017000808W WO 2017130717 A1 WO2017130717 A1 WO 2017130717A1
Authority
WO
WIPO (PCT)
Prior art keywords
recording medium
function
data communication
connection
communication function
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2017/000808
Other languages
English (en)
French (fr)
Inventor
祥平 藤原
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Denso Corp
Original Assignee
Denso Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Denso Corp filed Critical Denso Corp
Priority to US16/072,957 priority Critical patent/US10789379B2/en
Publication of WO2017130717A1 publication Critical patent/WO2017130717A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • BPERFORMING OPERATIONS; TRANSPORTING
    • B60VEHICLES IN GENERAL
    • B60RVEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
    • B60R16/00Electric or fluid circuits specially adapted for vehicles and not otherwise provided for; Arrangement of elements of electric or fluid circuits specially adapted for vehicles and not otherwise provided for
    • B60R16/02Electric or fluid circuits specially adapted for vehicles and not otherwise provided for; Arrangement of elements of electric or fluid circuits specially adapted for vehicles and not otherwise provided for electric constitutive elements
    • B60R16/023Electric or fluid circuits specially adapted for vehicles and not otherwise provided for; Arrangement of elements of electric or fluid circuits specially adapted for vehicles and not otherwise provided for electric constitutive elements for transmission of signals between vehicle parts or subsystems
    • B60R16/0231Circuits relating to the driving or the functioning of the vehicle
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/10File systems; File servers
    • G06F16/16File or folder operations, e.g. details of user interfaces specifically adapted to file systems
    • G06F16/162Delete operations
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/10Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]
    • G06F21/12Protecting executable software
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/629Protecting access to data via a platform, e.g. using keys or access control rules to features or functions of an application
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/30Services specially adapted for particular environments, situations or purposes
    • H04W4/40Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P]
    • H04W4/48Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P] for in-vehicle communication

Definitions

  • This disclosure relates to an in-vehicle device and a computer program.
  • the microcomputer of the vehicle-mounted device constituting the navigation system and the IVI (In-VehicleehInfotainment) system is equipped with a general-purpose operating system (hereinafter referred to as OS (Operating System)) function and an application function for storing logs and data. ing.
  • OS Operating System
  • This type of vehicle-mounted device is generally attached to the vehicle in a non-removable manner. Therefore, when a problem occurs in the market, an analysis tool for log analysis and data analysis is connected to the on-board unit, the data communication function implemented in the general-purpose OS function is started, and logs and data are analyzed from the on-board unit. It is supposed to be transferred to the tool.
  • Patent Document 1 discloses a technique for preventing unauthorized access to the vehicle-mounted device from the outside.
  • Patent Document 2 discloses a technique for ensuring security when the vehicle-mounted device is removed from the vehicle.
  • An object of the present disclosure is to provide an in-vehicle device and a computer program capable of appropriately achieving both security guarantee and log analysis and data analysis when a failure occurs in the market.
  • connection detection function detects the connection of the recording medium to the recording medium connection unit and determines that the specific file protected by the password is stored in the recording medium. Then, a specific file is expanded using a predefined password, the data communication function is copied to a specific area of the general-purpose operating system function, and the data communication function is activated.
  • the connection release detection function detects the connection release from the recording medium connection part of the recording medium, and if it determines that the data communication function is activated, the activated data communication function is stopped and the data communication function is Remove from operating system functionality.
  • the second specific file is acquired from the external server, and the data communication function is activated by expanding the second specific file.
  • the application function is from the general-purpose operating system function during the period in which the recording medium is connected.
  • transfer of a log and data from onboard equipment to an analysis tool is attained, and log analysis and data analysis can be performed.
  • the data communication function that is activated is stopped and deleted, so that the general-purpose operating system function cannot access the application function during the period when the recording medium is not connected. It becomes.
  • unauthorized access to the application function from the outside can be prevented and security can be ensured.
  • FIG. 1 is a functional block diagram illustrating the configuration of the vehicle-mounted device according to the first embodiment.
  • FIG. 2 is a diagram showing information stored in the USB memory.
  • FIG. 3 is a diagram showing a mode when a USB memory is connected
  • FIG. 4 is a diagram showing an aspect when the USB memory is disconnected.
  • FIG. 5 is a diagram showing USB connection detection processing.
  • FIG. 6 is a diagram showing USB connection release detection processing.
  • FIG. 7 is a functional block diagram illustrating the configuration of the vehicle-mounted device according to the second embodiment.
  • FIG. 8 is a diagram showing a mode when a CD is connected, FIG.
  • FIG. 9 is a diagram showing an aspect when the CD is disconnected
  • FIG. 10 is a diagram illustrating the information stored in the USB memory according to the third embodiment.
  • FIG. 11 is a diagram showing information stored in an external server.
  • FIG. 12 is a diagram showing a mode when a USB memory is connected
  • FIG. 13 is a diagram showing an aspect when the USB memory is disconnected.
  • FIG. 14 is a diagram illustrating USB connection detection processing.
  • the vehicle-mounted device 1 is a device constituting, for example, a navigation system or an IVI system, and includes a microcomputer 2, a first USB port 3 (corresponding to an analysis tool connection unit), and a second USB port 4 (recording medium connection unit). Corresponding to).
  • the microcomputer 2 executes processing corresponding to the computer program by executing the computer program stored in the non-transitional tangible recording medium, and controls the overall operation of the vehicle-mounted device 1.
  • the microcomputer 2 includes a general-purpose operating system (hereinafter referred to as OS) function 5 and an application function 6 as software configurations.
  • a function means a module that executes a specific program.
  • the general-purpose OS function 5 includes a first USB driver 7, a second USB driver 8, and a Bluetooth (registered trademark, hereinafter referred to as BT) driver 9.
  • the first USB driver 7 performs data communication conforming to the USB communication protocol with a USB device (not shown) having a USB communication function connected to the first USB port 3. I do.
  • the second USB driver 8 performs data communication conforming to the USB communication protocol with a USB device having a USB communication function (not shown) connected to the second USB port 4. I do. If a BT device (not shown) having a BT communication function registered in advance exists in a communication area where BT communication is possible and authentication is established with the BT device, the BT driver 9 Data communication conforming to the BT communication protocol.
  • the application function 6 has a log function 10, an audio function 11, an HMI (Human Machine Interface) function 12, a navigation function 13, and a telematics function 14.
  • the log function 10 manages a log indicating the operation history of the vehicle-mounted device 1.
  • the audio function 11, the HMI function 12, the navigation function 13, and the telematics function 14 manage audio control, HMI control, navigation control, and telematics control data, respectively.
  • the general-purpose OS function 5 has a USB device detection function 15 in addition to the USB drivers 7 and 8 and the BT driver 9 described above.
  • the USB device detection function 15 has a connection detection function 15a and a connection release detection function 15b.
  • the connection detection function 15a detects the connection of the USB device to the second USB port 4, the connection detection function 15a performs USB connection detection processing described later.
  • the connection release detection function 15b detects the connection release from the second USB port 4 of the USB device, the connection release detection function 15b performs a USB connection release detection process described later.
  • the present embodiment employs the following configuration.
  • the microcomputer 2 detects the connection of the USB memory 16 to the second USB port 4, the microcomputer 2 expands a specific file, copies the SSH connection function 18 to a specific area of the general-purpose OS function 5, and starts it.
  • the general-purpose OS function 5 can access the application function 6.
  • data communication is possible between the analysis tool 17 connected to the first USB port 3 and the microcomputer 2, and logs and data stored in the application function 6 can be transferred to the analysis tool 17. It becomes.
  • the general-purpose OS function 25 has a CD detection function 28.
  • the CD detection function 28 is equivalent to the USB device detection function 15 described in the first embodiment, and includes a connection detection function 28a and a connection release detection function 28b.
  • the connection detection function 28a detects the connection of the CD to the CD deck 24, the connection detection function 28a performs a process equivalent to the USB connection detection process described in the first embodiment.
  • the connection release detection function 28b detects the connection release of the CD from the CD deck 24, the connection release detection function 28b performs a process equivalent to the USB connection release detection process described in the first embodiment.
  • a CD 29 (corresponding to a recording medium) storing a specific file with a specific file name is prepared.
  • the microcomputer 22 detects the insertion of the CD 29 into the CD deck 24 and detects the connection of the CD 29 to the CD deck 24, the microcomputer 22 expands a specific file and makes the SSH connection function 18 a general-purpose OS function.
  • the application function 6 can be accessed from the general-purpose OS function 25 by copying to a specific area 25 and starting up. Further, as shown in FIG.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Databases & Information Systems (AREA)
  • Computing Systems (AREA)
  • Automation & Control Theory (AREA)
  • Mechanical Engineering (AREA)
  • Multimedia (AREA)
  • Technology Law (AREA)
  • Human Computer Interaction (AREA)
  • Data Mining & Analysis (AREA)
  • Storage Device Security (AREA)

Abstract

車載器(1)において、接続検知機能(15a)は、特定のファイルが格納されているUSBメモリ(16)が接続されると、特定のファイルを展開してSSH接続機能(18)を起動することで、そのUSBメモリが接続されている期間において汎用OS機能(5)からアプリケーション機能(6)へのアクセスを可能とする。又、接続解除検知機能(15b)は、USBメモリが接続解除されると、SSH接続機能を停止して削除することで、そのUSBメモリが接続されていない期間において汎用OS機能からアプリケーション機能へのアクセスを不能とする。

Description

車載器及びコンピュータプログラム 関連出願の相互参照
 本出願は、2016年1月28日に出願された日本出願番号2016-14388号に基づくもので、ここにその記載内容を援用する。
 本開示は、車載器及びコンピュータプログラムに関する。
 ナビゲーションシステムやIVI(In-Vehicle Infotainment)システムを構成する車載器のマイコンには、汎用オペレーティングシステム(以下、OS(Operating System)と称する)機能と、ログやデータを記憶するアプリケーション機能とが搭載されている。この種の車載器は取り外し不能に車両に取り付けられているのが一般的である。そのため、市場での不具合発生時には、ログ解析やデータ解析を行うための解析ツールを車載器に接続し、汎用OS機能に実装されているデータ通信機能を起動し、ログやデータを車載器から解析ツールに転送するようになっている。
 汎用OSに実装されているデータ通信機能としてSSH(Secure Shell)接続機能を採用している構成では、SSH接続機能がパスワードによる認証を行うので、一定レベルのセキュリティを担保することができる。しかしながら、パスワードの流出や解析により、外部から車載器に不正にアクセスして車両制御を行う不正行為が顕在化し始めており、セキュリティを十分に担保することができない問題がある。その一方、セキュリティを十分に担保すべくSSH接続機能を削除すると、車載器から解析ツールへのログやデータの転送が不能となり、市場での不具合発生時にログ解析やデータ解析を行えない問題が発生する。このようにセキュリティの担保と、市場での不具合発生時におけるログ解析やデータ解析の実施とを両立させることが望まれている。
 一方、例えば特許文献1には、外部から車載器への不正なアクセスを防止する技術が開示されている。又、例えば特許文献2には、車載器が車両から取り外された場合のセキュリティを担保する技術が開示されている。
特開2014-69599号公報 特開2010-254007号公報
 特許文献1及び2に開示されている何れの技術でも、セキュリティの担保と、市場での不具合発生時におけるログ解析やデータ解析の実施とを両立させることは困難である。
 本開示は、セキュリティの担保と、市場での不具合発生時におけるログ解析やデータ解析の実施とを適切に両立させることができる車載器及びコンピュータプログラムを提供することにある。
 本開示の第1の態様によれば、接続検知機能は、記録媒体の記録媒体接続部への接続を検知し、記録媒体にパスワードで保護されている特定のファイルが格納されていると判定すると、予め定義しているパスワードを用いて特定のファイルを展開し、データ通信機能を汎用オペレーティングシステム機能の特定の領域にコピーし、データ通信機能を起動する。接続解除検知機能は、記録媒体の記録媒体接続部からの接続解除を検知し、データ通信機能を起動していると判定すると、その起動しているデータ通信機能を停止し、データ通信機能を汎用オペレーティングシステム機能から削除する。
 即ち、特定のファイルが格納されている記録媒体が接続されると、特定のファイルを展開してデータ通信機能を起動することで、その記録媒体が接続されている期間において汎用オペレーティングシステム機能からアプリケーション機能へのアクセスが可能となる。これにより、ログやデータの車載器から解析ツールへの転送が可能となり、ログ解析やデータ解析を行うことができる。又、記録媒体が接続解除されると、その起動しているデータ通信機能を停止して削除することで、その記録媒体が接続されていない期間において汎用オペレーティングシステム機能からアプリケーション機能へのアクセスが不能となる。これにより、外部からアプリケーション機能への不正なアクセスを防止し、セキュリティを担保することができる。以上により、セキュリティの担保と、市場での不具合発生時におけるログ解析やデータ解析の実施とを適切に両立させることができる。
 本開示の第2の態様によれば、接続検知機能は、記録媒体の記録媒体接続部への接続を検知し、記録媒体に第1の特定のファイルが格納されていると判定すると、パスワードで保護されている第2の特定のファイルを外部サーバから取得し、予め定義しているパスワードを用いて当該第2の特定のファイルを展開し、データ通信機能を汎用オペレーティングシステム機能の特定の領域にコピーし、データ通信機能を起動する。接続解除検知機能は、記録媒体の記録媒体接続部からの接続解除を検知し、データ通信機能を起動していると判定すると、その起動しているデータ通信機能を停止し、データ通信機能を汎用オペレーティングシステム機能から削除する。
 即ち、第1の特定のファイルが格納されている記録媒体が接続されると、第2の特定のファイルを外部サーバから取得し、その第2の特定のファイルを展開してデータ通信機能を起動することで、その記録媒体が接続されている期間において汎用オペレーティングシステム機能からアプリケーション機能へのアクセスが可能となる。これにより、ログやデータの車載器から解析ツールへの転送が可能となり、ログ解析やデータ解析を行うことができる。又、記録媒体が接続解除されると、その起動しているデータ通信機能を停止して削除することで、その記録媒体が接続されていない期間において汎用オペレーティングシステム機能からアプリケーション機能へのアクセスが不能となる。これにより、外部からアプリケーション機能への不正なアクセスを防止し、セキュリティを担保することができる。以上により、前述した第1の態様と同様の作用効果を得ることができ、セキュリティの担保と、市場での不具合発生時におけるログ解析やデータ解析の実施とを適切に両立させることができる。
 本開示についての上記目的及びその他の目的、特徴や利点は、添付の図面を参照しながら下記の詳細な記述により、より明確になる。その図面は、
図1は、第1の実施形態を示し、車載器の構成を示す機能ブロック図であり、 図2は、USBメモリに格納されている情報を示す図であり、 図3は、USBメモリを接続したときの態様を示す図であり、 図4は、USBメモリを接続解除したときの態様を示す図であり、 図5は、USB接続検知処理を示す図であり、 図6は、USB接続解除検知処理を示す図であり、 図7は、第2の実施形態を示し、車載器の構成を示す機能ブロック図であり、 図8は、CDを接続したときの態様を示す図であり、 図9は、CDを接続解除したときの態様を示す図であり、 図10は、第3の実施形態を示し、USBメモリに格納されている情報を示す図であり、 図11は、外部サーバに格納されている情報を示す図であり、 図12は、USBメモリを接続したときの態様を示す図であり、 図13は、USBメモリを接続解除したときの態様を示す図であり、 図14は、USB接続検知処理を示す図である。
 (第1の実施形態)
 以下、第1の実施形態について図1から図6を参照して説明する。車載器1は、例えばナビゲーションシステムやIVIシステムを構成する機器であり、マイコン2と、第1のUSBポート3(解析ツール接続部に相当する)と、第2のUSBポート4(記録媒体接続部に相当する)とを有する。マイコン2は、非遷移的実体的記録媒体に格納されているコンピュータプログラムを実行することで、コンピュータプログラムに対応する処理を実行し、車載器1の動作全般を制御する。マイコン2は、ソフトウェアの構成として、汎用オペレーティングシステム(以下、OSと称する)機能5と、アプリケーション機能6とを搭載している。機能とは特定のプログラムを実行するモジュールの意味である。
 汎用OS機能5は、第1のUSBドライバ7と、第2のUSBドライバ8と、Bluetooth(登録商標、以下、BTと称する)ドライバ9とを有する。第1のUSBドライバ7は、USB通信機能を有するUSBデバイス(図示せず)が第1のUSBポート3に接続されている状態で、そのUSBデバイスとの間でUSB通信プロトコルに準拠したデータ通信を行う。第2のUSBドライバ8は、USB通信機能を有するUSBデバイス(図示せず)が第2のUSBポート4に接続されている状態で、そのUSBデバイスとの間でUSB通信プロトコルに準拠したデータ通信を行う。BTドライバ9は、予め登録されているBT通信機能を有するBTデバイス(図示せず)がBT通信可能な通信圏内に存在し、そのBTデバイスとの間で認証が成立すれば、そのBTデバイスとの間でBT通信プロトコルに準拠したデータ通信を行う。
 アプリケーション機能6は、ログ機能10と、オーディオ機能11と、HMI(Human Machine Interface)機能12と、ナビゲーション機能13と、テレマティクス機能14とを有する。ログ機能10は、車載器1の動作履歴を示すログを管理している。オーディオ機能11、HMI機能12、ナビゲーション機能13及びテレマティクス機能14は、それぞれオーディオ制御、HMI制御、ナビゲーション制御及びテレマティクス制御のデータを管理している。
 汎用OS機能5は、前述したUSBドライバ7,8、BTドライバ9に加え、USBデバイス検知機能15を有する。USBデバイス検知機能15は、接続検知機能15aと、接続解除検知機能15bとを有する。接続検知機能15aは、USBデバイスの第2のUSBポート4への接続を検知すると、後述するUSB接続検知処理を行う。接続解除検知機能15bは、USBデバイスの第2のUSBポート4からの接続解除を検知すると、後述するUSB接続解除検知処理を行う。
 さて、前述した[背景技術]で説明したように、汎用OS機能にデータ通信機能としてSSH接続機能が実装されている構成では、パスワードの流出や解析によりセキュリティを十分に担保することができない問題があり、その一方、汎用OS機能からSSH接続機能を削除する構成では、市場での不具合発生時にログ解析やデータ解析を行えない問題がある。この点に関し、本実施形態では、以下の構成を採用している。
 図2に示すように、特定のファイル名の特定のファイルが格納されているUSBメモリ16(記録媒体に相当する)を用意する。特定のファイルは、パスワードで保護されており、ソフトウェアモジュールで構成されるSSH接続機能、SSH接続機能を起動するための起動スクリプト、SSH接続機能を実行するための設定ファイルを含む。USBメモリ16の使用形態としては、市場での不具合が発生したことでログ解析やデータ解析を行う必要が生じたときには、図3に示すように、例えばパーソナルコンピュータからなる解析ツール17をUSBケーブル(図示せず)を介して第1のUSBポート3に接続し、前述したUSBメモリ16を第2のUSBポート4に接続する。そして、ログ解析やデータ解析を終えたときには、図4に示すように、接続しているUSBメモリ16を第2のUSBポート4から接続解除する。尚、USBメモリ16を第2のUSBポート4に接続する態様としては、USBメモリ16を第2のUSBポート4に挿入して(即ちUSBケーブルを介さずに)接続しても良いし、USBメモリ16をUSBケーブルを介して第2のUSBポート4に接続しても良い。
 次に、上記した構成の作用について図5及び図6を参照して説明する。ここでは、接続検知機能15aがUSBデバイスの第2のUSBポート4への接続を検知したときに行うUSB接続検知処理、接続解除検知機能15bがUSBデバイスの第2のUSBポート4からの接続解除を検知したときに行うUSB接続解除検知処理について説明する。
 (1)USB接続検知処理
 接続検知機能15aは、USBデバイスの第2のUSBポート4への接続を検知し、USB接続検知処理を開始すると、そのUSBデバイスに特定のファイルが格納されているか否かを判定する(S1、格納判定手順に相当する)。ここで、前述したUSBメモリ16以外のUSBデバイスが第2のUSBポート4に接続された場合であれば、接続検知機能15aは、そのUSBデバイスに特定のファイルが格納されていないと判定し(S1:NO)、USB接続検知処理を終了する。
 一方、前述したUSBメモリ16が第2のUSBポート4に挿入されて接続された場合であれば、接続検知機能15aは、そのUSBメモリ16に特定のファイルが格納されていると判定し(S1:YES)、予め定義しているパスワードを用いて特定のファイルを展開する(S2、展開手順に相当する)。そして、接続検知機能15aは、SSH接続機能18を汎用OS機能5の特定の領域にコピーし(S3、コピー手順に相当する)、SSH接続機能18を起動し(S4、起動手順に相当する)、USB接続検知処理を終了する。
 即ち、マイコン2は、USBメモリ16の第2のUSBポート4への接続を検知すると、特定のファイルを展開してSSH接続機能18を汎用OS機能5の特定の領域にコピーして起動することで、汎用OS機能5からアプリケーション機能6へのアクセスを可能とする。その結果、第1のUSBポート3に接続されている解析ツール17とマイコン2との間でデータ通信が可能となり、アプリケーション機能6に記憶されているログやデータの解析ツール17への転送が可能となる。
 (2)USB接続解除検知処理
 接続解除検知機能15bは、USBデバイスの第2のUSBポート4からの接続解除を検知し、USB接続解除検知処理を開始すると、SSH接続機能18を起動しているか否かを判定する(S11、起動判定手順)。ここで、前述したUSBメモリ16以外のUSBデバイスが第2のUSBポート4から接続解除された場合であれば、接続解除検知機能15bは、SSH接続機能18を起動していないと判定し(S11、NO)、USB接続解除検知処理を終了する。
 一方、前述したUSBメモリ16が第2のUSBポート4から抜去されて接続解除された場合であれば、接続解除検知機能15bは、SSH接続機能18を起動していると判定し(S11、YES)、その起動しているSSH接続機能18を停止する(S12、停止手順に相当する)。そして、接続解除検知機能15bは、SSH接続機能18を汎用OS機能5から削除し(S13)、USB接続解除検知処理を終了する。
 即ち、マイコン2は、USBメモリ16の第2のUSBポート4からの接続解除を検知すると、SSH接続機能18を停止して汎用OS機能5から削除することで、汎用OS機能5からアプリケーション機能6へのアクセスを不能とする。その結果、外部から車載器1への不正なアクセスの防止が可能となる。
 以上説明したように第1の実施形態によれば、次に示す効果を得ることができる。
 車載器1において、USBメモリ16が接続されると、特定のファイルを展開してSSH接続機能18を起動することで、そのUSBメモリ16が接続されている期間において汎用OS機能5からアプリケーション機能6へのアクセスが可能となる。これにより、ログやデータの車載器1から解析ツール17への転送が可能となり、ログ解析やデータ解析を行うことができる。又、USBメモリ16が接続解除されると、SSH接続機能18を停止して削除することで、そのUSBメモリ16が接続されていない期間において汎用OS機能5からアプリケーション機能6へのアクセスが不能となる。これにより、外部から車載器1への不正なアクセスの防止が可能となり、セキュリティを担保することができる。以上により、セキュリティの担保と、市場での不具合発生時におけるログ解析やデータ解析の実施とを適切に両立させることができる。
 (第2の実施形態)
 次に、第2の実施形態について図7から図9を参照して説明する。尚、前述した第1の実施形態と同一部分については説明を省略し、異なる部分について説明する。第1の実施形態は、特定のファイルが格納されているUSBメモリ16を用い、SSH接続機能18を起動する構成であるが、第2の実施形態は、特定のファイルが格納されているコンパクトディスク(登録商標、以下、CDと称する、ディスク型記録媒体に相当する)を用い、SSH接続機能18を起動する構成である。
 車載器21は、マイコン22と、USBポート23(解析ツール接続部に相当する)と、CDデッキ24(記録媒体接続部に相当する)とを有する。マイコン22は、第1の実施形態で説明したマイコン2と同等であり、ソフトウェアの構成として、汎用OS機能25と、アプリケーション機能6とを搭載している。汎用OS機能25は、USBドライバ26と、CDドライバ27と、第1の実施形態で説明したBTドライバ9とを有する。USBドライバ26は、USB通信機能を有するUSBデバイス(図示せず)がUSBポート23に接続されている状態で、そのUSBデバイスとの間でUSB通信プロトコルに準拠したデータ通信を行う。CDドライバ27は、CD(図示せず)がCDデッキ24に接続されている状態で、そのCDに記録されているデータを読み取る。又、汎用OS機能25は、CD検知機能28を有する。CD検知機能28は、第1の実施形態で説明したUSBデバイス検知機能15と同等であり、接続検知機能28aと、接続解除検知機能28bとを有する。接続検知機能28aは、CDのCDデッキ24への接続を検知すると、第1の実施形態で説明したUSB接続検知処理と同等の処理を行う。接続解除検知機能28bは、CDのCDデッキ24からの接続解除を検知すると、第1の実施形態で説明したUSB接続解除検知処理と同等の処理を行う。
 この場合も、第1の実施形態で説明したUSBメモリ16と同様に、特定のファイル名の特定のファイルが格納されているCD29(記録媒体に相当する)を用意する。マイコン22は、図8に示すように、CD29のCDデッキ24への挿入を検知し、CD29のCDデッキ24への接続を検知すると、特定のファイルを展開してSSH接続機能18を汎用OS機能25の特定の領域にコピーして起動することで、汎用OS機能25からアプリケーション機能6へのアクセスを可能とする。又、マイコン22は、図9に示すように、CD29のCDデッキ24からの抜去を検知し、CD29のCDデッキ24からの接続解除を検知すると、SSH接続機能18を停止して汎用OS機能25から削除することで、汎用OS機能25からアプリケーション機能6へのアクセスを不能とする。
 以上に説明したように第2の実施形態によれば、特定のファイルが格納されている記録媒体としてUSBメモリ16に代えてCD29を用いる場合でも、前述した第1の実施形態と同様の作用効果を得ることができ、セキュリティの担保と、市場での不具合発生時におけるログ解析やデータ解析の実施とを適切に両立させることができる。
 (第3の実施形態)
 次に、第3の実施形態について図10から図14を参照して説明する。尚、前述した第1の実施形態と同一部分については説明を省略し、異なる部分について説明する。第1の実施形態は、SSH接続機能、起動スクリプト及び設定ファイルを含む特定のファイルがUSBメモリ16に格納されている構成であるが、第3の実施形態は、それらを含む特定のファイルが外部サーバで管理される構成である。
 この場合は、第1の実施形態で説明したUSBメモリ16とは異なり、図10に示すように、第1の特定のファイル名の第1の特定のファイルが格納されているUSBメモリ31(記録媒体に相当する)を用意する。第1の特定のファイルは、第1の実施形態で説明したUSBメモリ16に格納されている特定のファイルとは異なり、パスワードで保護されておらず、SSH接続機能、起動スクリプト及び設定ファイルを含まない。一方、図11に示すように、外部サーバ32には、第2の特定のファイル名の第2の特定のファイルが格納されている。第2の特定のファイルは、USBメモリ16に格納されている特定のファイルと同等であり、パスワードで保護されており、SSH接続機能、起動スクリプト及び設定ファイルを含む。
 この場合は、市場での不具合が発生したことでログ解析やデータ解析を行う必要が生じたときには、図12に示すように、解析ツール17をUSBケーブル(図示せず)を介して第1のUSBポート3に接続し、前述したUSBメモリ31を第2のUSBポート4に接続することに加え、外部サーバ32との間でデータ通信を行う通信機器としてBT機能を有する携帯電話機33をBT通信可能に接続する。そして、ログ解析やデータ解析を終えたときには、図13に示すように、接続しているUSBメモリ31を第2のUSBポート4から接続解除する。
 USBメモリ31が第2のUSBポート4に挿入されて接続されると、接続検知機能15aは、そのUSBメモリ31に第1の特定のファイルが格納されていると判定し(S21:YES)、テレマティクス機能14を起動して携帯電話機33を通信ネットワーク34を介して外部サーバ32に接続させ、第2の特定のファイルを外部サーバ32から取得する(S22、取得手順に相当する)。次いで、接続検知機能15aは、予め定義しているパスワードを用いて第2の特定のファイルを展開する(S23、展開手順に相当する)。そして、これ以降、接続検知機能15aは、第1の実施形態と同様に、SSH接続機能18を汎用OS機能5の特定の領域にコピーし(S24、コピー手順に相当する)、SSH接続機能18を起動し(S25、起動手順に相当する)、USB接続検知処理を終了する。
 即ち、マイコン2は、USBメモリ31の第2のUSBポート4への接続を検知すると、第2の特定のファイルを外部サーバ22から取得し、その取得した第2の特定のファイルを展開してSSH接続機能18を汎用OS機能5の特定の領域にコピーして起動することで、汎用OS機能5からアプリケーション機能6へのアクセスを可能とする。尚、これ以降、USBメモリ31が第2のUSBポート4から抜去されて接続解除されると、第1の実施形態で説明した場合と同様に、接続解除検知機能15bは、起動しているSSH接続機能18を停止し、SSH接続機能18を汎用OS機能5から削除する。
 以上に説明したように第3の実施形態によれば、USBメモリ16に格納されている特定のファイルと同等の第2の特定のファイルが外部サーバ32で管理される場合でも、前述した第1の実施形態と同様の作用効果を得ることができ、セキュリティの担保と、市場での不具合発生時におけるログ解析やデータ解析の実施とを適切に両立させることができる。又、外部サーバ32が第2の特定のファイルを管理することで、紛失や盗難の可能性があるUSBメモリ16を用いる第1の実施形態と比較すると、USBメモリ16が紛失や盗難される可能性を排除することができ、セキュリティをより強固に担保することができる。又、第2の特定のファイルを例えば機能向上によりバージョンアップする場合等でも柔軟に対応することができる。
 (その他の実施形態)
 本開示は、実施形態に準拠して記述されたが、当該実施形態や構造に限定されるものではないと理解される。本開示は、様々な変形例や均等範囲内の変形をも包含する。加えて、様々な組み合わせや形態、更には、それらに一要素のみ、それ以上、或いはそれ以下、を含む他の組み合わせや形態をも、本開示の範疇や思想範囲に入るものである。
 第1の特定のファイルが格納されているUSBメモリ31が接続されることで、第2の特定のファイルを外部サーバ32から取得する構成を例示したが、第1の特定のファイルが格納されているCDが接続されることで、第2の特定のファイルを外部サーバ32から取得する構成でも良い。
 車載器1が携帯電話機33との間でBT通信によるデータ通信を行う構成を例示したが、車載器1が携帯電話機33との間でBLE(Bluetooth Low Energy)やWiFi(Wireless Fidelity)(登録商標)等の無線通信によるデータ通信を行うことで、第2の特定のファイルを外部サーバ32から取得する構成でも良い。又、車載器1が携帯電話機33との間で有線通信によるデータ通信を行うことで、第2の特定のファイルを外部サーバ32から取得する構成でも良い。

Claims (7)

  1.  ログやデータを解析する解析ツール(17)を接続可能な解析ツール接続部(3,23)と、
     記録媒体(16,29)を接続可能な記録媒体接続部(4,24)と、
     アプリケーション機能(6)に記憶されている前記ログや前記データを前記解析ツールに転送するデータ通信機能を起動可能な汎用オペレーティングシステム機能(5,25)を有するマイコン(2,22)と、を備えた車載器(1,21)において、
     前記記録媒体の前記記録媒体接続部への接続を検知する接続検知機能(15a,28a)と、
     前記記録媒体の前記記録媒体接続部からの接続解除を検知する接続解除検知機能(15b,28b)と、を備え、
     前記接続検知機能は、前記記録媒体の前記記録媒体接続部への接続を検知し、前記記録媒体にパスワードで保護されている特定のファイルが格納されていると判定すると、予め定義しているパスワードを用いて特定のファイルを展開し、前記データ通信機能を前記汎用オペレーティングシステム機能の特定の領域にコピーし、前記データ通信機能を起動し、
     前記接続解除検知機能は、前記記録媒体の前記記録媒体接続部からの接続解除を検知し、前記データ通信機能を起動していると判定すると、その起動している前記データ通信機能を停止し、前記データ通信機能を前記汎用オペレーティングシステム機能から削除する車載器。
  2.  ログやデータを解析する解析ツール(17)を接続可能な解析ツール接続部(3,23)と、
     記録媒体(31)を接続可能な記録媒体接続部(4,24)と、
     アプリケーション機能(6)に記憶されている前記ログや前記データを前記解析ツールに転送するデータ通信機能を起動可能な汎用オペレーティングシステム機能(5,25)を有するマイコン(2,22)と、を備えた車載器(1,21)において、
     前記記録媒体の前記記録媒体接続部への接続を検知する接続検知機能(15a,28a)と、
     前記記録媒体の前記記録媒体接続部からの接続解除を検知する接続解除検知機能(15b,28b)と、を備え、
     前記接続検知機能は、前記記録媒体の前記記録媒体接続部への接続を検知し、前記記録媒体に第1の特定のファイルが格納されていると判定すると、パスワードで保護されている第2の特定のファイルを外部サーバ(32)から取得し、予め定義しているパスワードを用いて当該取得した第2の特定のファイルを展開し、前記データ通信機能を前記汎用オペレーティングシステム機能の特定の領域にコピーし、前記データ通信機能を起動し、
     前記接続解除検知機能は、前記記録媒体の前記記録媒体接続部からの接続解除を検知し、前記データ通信機能を起動していると判定すると、その起動している前記データ通信機能を停止し、前記データ通信機能を前記汎用オペレーティングシステム機能から削除する車載器。
  3.  前記記録媒体接続部は、前記記録媒体としてUSBメモリ(16,31)を接続可能なUSB接続部(4)を含む請求項1又は2に記載の車載器。
  4.  前記記録媒体接続部は、前記記録媒体としてディスク型記録媒体(29)を接続可能なディスク型記録媒体接続部(24)を含む請求項1又は2に記載の車載器。
  5.  ログやデータを解析する解析ツール(17)を接続可能な解析ツール接続部(3,23)と、
     記録媒体(16,29)を接続可能な記録媒体接続部(4,24)と、
     アプリケーション機能(6)に記憶されている前記ログや前記データを前記解析ツールに転送するデータ通信機能を起動可能な汎用オペレーティングシステム機能(5,25)を有するマイコン(2,22)と、を備えた車載器(1,21)の前記マイコンに、
     前記記録媒体の前記記録媒体接続部への接続を検知すると、前記記録媒体にパスワードで保護されている特定のファイルが格納されているか否かを判定する格納判定手順と、
     特定のファイルが格納されていると前記格納判定手順により判定すると、予め定義しているパスワードを用いて特定のファイルを展開する展開手順と、
     前記データ通信機能を前記汎用オペレーティングシステム機能の特定の領域にコピーするコピー手順と、
     前記データ通信機能を起動する起動手順と、
     前記記録媒体の前記記録媒体接続部からの接続解除を検知すると、前記データ通信機能を起動しているか否かを判定する起動判定手順と、
     前記データ通信機能を起動していると前記起動判定手順により判定すると、その起動しているデータ通信機能を停止する停止手順と、
     前記データ通信機能を前記汎用オペレーティングシステム機能から削除する削除手順と、を実行させるコンピュータプログラム。
  6.  ログやデータを解析する解析ツール(17)を接続可能な解析ツール接続部(3,23)と、
     記録媒体(31)を接続可能な記録媒体接続部(4,24)と、
     アプリケーション機能(6)に記憶されている前記ログや前記データを前記解析ツールに転送するデータ通信機能を起動可能な汎用オペレーティングシステム機能(5,25)を有するマイコン(2,22)と、を備えた車載器(1,21)の前記マイコンに、
     前記記録媒体の前記記録媒体接続部への接続を検知すると、前記記録媒体に第1の特定のファイルが格納されているか否かを判定する格納判定手順と、
     第1の特定のファイルが格納されていると前記格納判定手順により判定すると、パスワードで保護されている第2の特定のファイルを外部サーバ(32)から取得する取得手順と、
     予め定義しているパスワードを用いて当該取得した第2の特定のファイルを展開する展開手順と、
     前記データ通信機能を前記汎用オペレーティングシステム機能の特定の領域にコピーするコピー手順と、
     前記データ通信機能を起動する起動手順と、
     前記記録媒体の前記記録媒体接続部からの接続解除を検知すると、前記データ通信機能を起動しているか否かを判定する起動判定手順と、
     前記データ通信機能を起動していると前記起動判定手順により判定すると、その起動しているデータ通信機能を停止する停止手順と、
     前記データ通信機能を前記汎用オペレーティングシステム機能から削除するファイル削除手順と、を実行させるコンピュータプログラム。
  7.  請求項5又は6に記載のコンピュータプログラムを記憶する、コンピュータ読み取り可能な非一時的な記憶媒体。
PCT/JP2017/000808 2016-01-28 2017-01-12 車載器及びコンピュータプログラム Ceased WO2017130717A1 (ja)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US16/072,957 US10789379B2 (en) 2016-01-28 2017-01-12 Vehicle onboard apparatus and computer program

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2016-014388 2016-01-28
JP2016014388A JP6555141B2 (ja) 2016-01-28 2016-01-28 車載器及びコンピュータプログラム

Publications (1)

Publication Number Publication Date
WO2017130717A1 true WO2017130717A1 (ja) 2017-08-03

Family

ID=59398908

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2017/000808 Ceased WO2017130717A1 (ja) 2016-01-28 2017-01-12 車載器及びコンピュータプログラム

Country Status (3)

Country Link
US (1) US10789379B2 (ja)
JP (1) JP6555141B2 (ja)
WO (1) WO2017130717A1 (ja)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102021237B1 (ko) * 2018-05-08 2019-09-11 주식회사 투비원솔루션즈 스마트카 클라우드 서버 시스템 및 그 시스템을 이용한 사용자 단말기와 서비스 제공 서버의 연결 방법
CN113741946B (zh) * 2021-08-25 2023-06-09 烽火通信科技股份有限公司 公共接口函数库的裁剪方法、装置、设备及可读存储介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2006146358A (ja) * 2004-11-16 2006-06-08 Nec Nexsolutions Ltd Usb周辺機器制御システム、及びusb周辺機器制御方法
JP2012155712A (ja) * 2011-01-05 2012-08-16 Sb System Kk 情報処理装置の遠隔保守管理方法及びシステム並びにそれに使用する情報端末装置及びプログラム
JP2013192090A (ja) * 2012-03-14 2013-09-26 Denso Corp 通信システム、中継装置、車外装置及び通信方法

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8140358B1 (en) * 1996-01-29 2012-03-20 Progressive Casualty Insurance Company Vehicle monitoring system
JP5334663B2 (ja) 2009-04-22 2013-11-06 富士通テン株式会社 車載器機制御装置、車載器機制御方法、及び車載器機
JP5545026B2 (ja) * 2010-05-18 2014-07-09 Dmg森精機株式会社 電子機器、および制限解除方法
US9704310B2 (en) * 2011-01-31 2017-07-11 Trimble Navigation Limited Multi-mode vehicle computing device supporting in-cab and stand-alone operation
US9020733B2 (en) * 2012-08-10 2015-04-28 Xrs Corporation Vehicle data acquisition for transportation management
JP6060592B2 (ja) 2012-09-27 2017-01-18 三菱自動車工業株式会社 車載機器類の遠隔操作システム
US9170866B2 (en) * 2013-03-08 2015-10-27 Dell Products L.P. System and method for in-service diagnostics based on health signatures

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2006146358A (ja) * 2004-11-16 2006-06-08 Nec Nexsolutions Ltd Usb周辺機器制御システム、及びusb周辺機器制御方法
JP2012155712A (ja) * 2011-01-05 2012-08-16 Sb System Kk 情報処理装置の遠隔保守管理方法及びシステム並びにそれに使用する情報端末装置及びプログラム
JP2013192090A (ja) * 2012-03-14 2013-09-26 Denso Corp 通信システム、中継装置、車外装置及び通信方法

Also Published As

Publication number Publication date
JP2017134655A (ja) 2017-08-03
JP6555141B2 (ja) 2019-08-07
US10789379B2 (en) 2020-09-29
US20190034655A1 (en) 2019-01-31

Similar Documents

Publication Publication Date Title
CN104866336B (zh) 无声车载软件更新
EP3480720B1 (en) Method and system for downloading software based on mobile terminal
CN111061499A (zh) 一种基于文件系统的ecu更新方法及系统
JP6060782B2 (ja) 中継装置
KR102002517B1 (ko) 전자식 제어기 보안 기능 설정 방법 및 시스템
CN108241498A (zh) 一种车载设备升级方法、装置及车辆
CN111104148A (zh) 集成有Linux和android两系统的芯片平台的升级方法、系统及可读存储介质
US20090138969A1 (en) Device and method for blocking autorun of malicious code
CN101841559A (zh) 网络装置以及将外部存储装置公开于网络上的方法
CN108628765B (zh) 开源分布式存储软件Ceph中Cache实现方法和装置
JP5790551B2 (ja) 通信システム、中継装置、車外装置及び通信方法
JP6555141B2 (ja) 車載器及びコンピュータプログラム
US20200026864A1 (en) Method for the secured access of data of a transportation vehicle
JP2003535498A (ja) 車両通信網内でエラーのある装置の処理方法
JP2002070636A (ja) 車載電子制御装置、データ書換システム、データ書換方法、及び記憶媒体
CN108416193A (zh) 鉴权方法、装置及车辆
TWI896147B (zh) 數據備份方法、系統、儲存介質及車輛
WO2016042726A1 (ja) 車載システム
CN107977313B (zh) 一种调试接口的调用方法和装置
CN111583460A (zh) 认证方法、装置及计算机设备
JP6969426B2 (ja) 電子制御装置
JP7683379B2 (ja) 情報処理システム
KR102895837B1 (ko) 차량용 네비게이션 장치 및 이의 동작 방법
US20240419769A1 (en) Drive video record system and method of controlling the same
KR20110005119A (ko) 차량용 블랙박스 시스템에서의 비상사태에 따른 영상 저장 방법 및 장치

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17743948

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17743948

Country of ref document: EP

Kind code of ref document: A1