WO2020100929A1 - 認証システム及び認証方法 - Google Patents
認証システム及び認証方法 Download PDFInfo
- Publication number
- WO2020100929A1 WO2020100929A1 PCT/JP2019/044488 JP2019044488W WO2020100929A1 WO 2020100929 A1 WO2020100929 A1 WO 2020100929A1 JP 2019044488 W JP2019044488 W JP 2019044488W WO 2020100929 A1 WO2020100929 A1 WO 2020100929A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- input
- unit
- parameter
- mobile terminal
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/069—Authentication using certificates or pre-shared keys
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B60—VEHICLES IN GENERAL
- B60R—VEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
- B60R25/00—Fittings or systems for preventing or indicating unauthorised use or theft of vehicles
- B60R25/20—Means to switch the anti-theft system on or off
- B60R25/24—Means to switch the anti-theft system on or off using electronic identifiers containing a code not memorised by the user
- B60R25/246—Means to switch the anti-theft system on or off using electronic identifiers containing a code not memorised by the user characterised by the challenge triggering
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3271—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B60—VEHICLES IN GENERAL
- B60R—VEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
- B60R2325/00—Indexing scheme relating to vehicle anti-theft devices
- B60R2325/10—Communication protocols, communication systems of vehicle anti-theft devices
- B60R2325/101—Bluetooth®
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B60—VEHICLES IN GENERAL
- B60R—VEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
- B60R25/00—Fittings or systems for preventing or indicating unauthorised use or theft of vehicles
- B60R25/01—Fittings or systems for preventing or indicating unauthorised use or theft of vehicles operating on vehicle systems or fittings, e.g. on doors, seats or windscreens
- B60R25/04—Fittings or systems for preventing or indicating unauthorised use or theft of vehicles operating on vehicle systems or fittings, e.g. on doors, seats or windscreens operating on the propulsion system, e.g. engine or drive motor
-
- B—PERFORMING OPERATIONS; TRANSPORTING
- B60—VEHICLES IN GENERAL
- B60R—VEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
- B60R25/00—Fittings or systems for preventing or indicating unauthorised use or theft of vehicles
- B60R25/20—Means to switch the anti-theft system on or off
- B60R25/24—Means to switch the anti-theft system on or off using electronic identifiers containing a code not memorised by the user
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/84—Vehicles
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/082—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying multi-factor authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0861—Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/18—Self-organising networks, e.g. ad-hoc networks or sensor networks
Definitions
- the present invention relates to an authentication system and an authentication method for wirelessly authenticating between a mobile terminal and its communication partner.
- an authentication system that performs authentication through wireless communication between a mobile terminal carried by a user and an in-vehicle device mounted on the vehicle in order to control the vehicle.
- a smart verification system is known as an authentication system.
- ID collation smart collation
- the mobile terminal automatically responds to a radio wave transmitted from the vehicle-mounted device to perform wireless communication with the vehicle-mounted device.
- Patent Document 1 discloses an authentication system that performs authentication using the authentication information input to the input unit provided in the vehicle. The authentication system determines whether the authentication information input to the input unit matches the authentication information registered in advance.
- the smart verification system can improve the security by imposing authentication of the authentication information on the user.
- this type of authentication system there is a problem in that the work of inputting authentication information into a predetermined input unit is required each time authentication is performed, which is not convenient for the user.
- An authentication system is an authentication system that authenticates wirelessly between a mobile terminal and its communication partner, and permits the operation of the communication partner based on the authentication result, and the authentication system is provided at different locations.
- a first input unit and a second input unit which are provided and are capable of inputting authentication information used for the authentication, and the authentication information input to the first input unit and a communication partner authentication parameter registered in the communication partner
- a first calculation unit that performs a calculation based on the above; a second calculation unit that performs a calculation based on the authentication information input to the second input unit and a mobile terminal side authentication parameter registered in the mobile terminal;
- the authentication unit performs the authentication based on the calculation result of the second calculation unit and the communication partner authentication parameter.
- An authentication method is an authentication method in which authentication is performed wirelessly between a mobile terminal and its communication partner, and the operation of the communication partner is permitted based on the authentication result, and the authentication method is different from each other.
- Receiving at least one of the first input section and the second input section provided in the authentication information used for the authentication, the authentication information input to the first input section, and the communication partner Performing an operation based on the registered communication partner authentication parameter, and performing an operation based on the authentication information input to the second input unit and the mobile terminal authentication parameter registered in the mobile terminal.
- the authentication is performed based on a calculation result calculated based on the communication partner authentication parameter and the mobile terminal authentication parameter, and the second input unit
- the authentication is performed based on the calculation result calculated based on the mobile terminal side authentication parameter and the communication partner side authentication parameter.
- An object of the present invention is to provide an authentication system and an authentication method that can achieve both security and convenience.
- the block diagram which shows the structure of the authentication system in 1st Embodiment The flowchart which shows the flow of authentication when authentication information is input into the 1st input part.
- the flowchart which shows the flow of authentication when authentication information is input into the 2nd input part The block diagram which shows the structure of the authentication system in 2nd Embodiment.
- the flowchart which shows the flow of authentication in 2nd Embodiment The block diagram which shows the structure of the authentication system in 3rd Embodiment.
- the authentication system 3 is applied to the vehicle 1 as a communication partner.
- the authentication system 3 includes a vehicle 1 and a mobile terminal 2.
- the vehicle 1 includes an in-vehicle device 4, a verification ECU (Electronic Control Unit) 5, and a vehicle-side communication unit 8.
- the vehicle-mounted device 4 includes a door lock device, an engine, or both of them.
- the authentication system 3 permits or executes the operation of the in-vehicle device 4 based on the authentication result.
- the mobile terminal 2 is preferably a high-performance mobile phone having a telephone function and capable of communicating with the vehicle 1 using short-range wireless communication.
- the authentication system 3 is a short-range wireless verification system that executes ID verification by short-range wireless communication triggered by short-range wireless communication from the vehicle 1.
- the short-range wireless communication is Bluetooth (registered trademark) communication.
- the verification ECU 5 is configured to perform ID verification.
- the verification ECU 5 is connected to the vehicle-mounted device 4 through the communication line 6 in the vehicle.
- the communication line 6 is, for example, a CAN (Controller Area Network) or a LIN (Local Interconnect Network).
- the verification ECU 5 includes a memory 7 in which data can be written and rewritten.
- the memory 7 stores the electronic key ID of at least one mobile terminal 2 registered in the vehicle 1.
- the ID collation is electronic key ID collation that confirms whether the electronic key ID is correct.
- the establishment of the electronic key ID collation is one of a plurality of conditions for permitting or executing the operation of the vehicle-mounted device 4.
- the memory 7 stores an authentication parameter A used for authentication between the vehicle 1 and the mobile terminal 2.
- establishment of authentication using the authentication parameter A is one of a plurality of conditions for permitting or executing the operation of the vehicle-mounted device 4.
- the authentication parameter A corresponds to the communication partner authentication parameter.
- the vehicle-side communication unit 8 performs short-range wireless communication with the mobile terminal 2.
- the vehicle-side communication unit 8 performs BLE (Bluetooth Low Energy) communication with the mobile terminal 2 as short-range wireless communication.
- BLE Bluetooth Low Energy
- the mobile terminal 2 is a master and the vehicle 1 is a slave.
- the mobile terminal 2 may be a slave and the vehicle 1 may be a master.
- the vehicle-side communication unit 8 regularly transmits an advertisement message to an area near the vehicle 1.
- the mobile terminal 2 includes a terminal control unit 20 that controls the operation of the mobile terminal 2, a network communication module 21 that performs network communication in the mobile terminal 2, a terminal communication unit 22 that performs short-range wireless communication in the mobile terminal 2, and data. And a rewritable memory 23.
- the terminal communication unit 22 performs BLE communication as short-range wireless communication.
- the memory 23 stores the electronic key ID of the mobile terminal 2 and the authentication parameter B.
- the mobile terminal 2 acquires the electronic key ID of the mobile terminal 2 from a server (not shown) through network communication when registering the mobile terminal 2 in the vehicle 1 (electronic key registration).
- the mobile terminal 2 registers the acquired electronic key ID of the mobile terminal 2 in the vehicle 1 via wireless communication.
- the authentication parameter B is used for authentication between the vehicle 1 and the mobile terminal 2.
- the authentication parameter B corresponds to the mobile terminal side authentication parameter.
- the terminal control unit 20 of the mobile terminal 2 has a user interface application (not shown) that manages the operation of the authentication system 3 in the mobile terminal 2.
- the terminal control unit 20 uses the user interface application to register the mobile terminal 2 in the vehicle 1 (electronic key registration), lock / unlock the vehicle door, start the engine of the vehicle 1, or perform any two or more operations. Performs various processes including combinations.
- the mobile terminal 2 When the mobile terminal 2 receives the advertisement message from the vehicle 1 and the connection for short-range wireless communication is established between the mobile terminal 2 and the vehicle 1, the mobile terminal 2 mutually communicates with the vehicle 1 through short-range wireless communication. Then, ID verification is automatically performed. For example, when the electronic key registration of the mobile terminal 2 is completed and the short-distance wireless communication connection is established between the vehicle 1 and the mobile terminal 2, the electronic key IDs of the verification ECU 5 and the terminal control unit 20 are set. The electronic key ID is collated by being transmitted and received between them. It should be noted that in the series of ID verification, the processing is automatically executed without the user operating the mobile terminal 2 or the user operating the vehicle 1.
- the authentication system 3 performs authentication using the authentication parameter A and the authentication parameter B through communication between the vehicle 1 and the mobile terminal 2.
- the authentication system 3 receives the authentication information Dc input by the user and determines the authentication based on the input authentication information Dc, the authentication parameter A, and the authentication parameter B.
- the authentication information Dc is a password registered in advance in the authentication system 3.
- the authentication system 3 may perform such authentication before the ID matching, after the ID matching, or during the ID matching.
- the vehicle 1 includes a first input unit 31 capable of inputting data.
- the first input unit 31 is a car navigation system provided inside the vehicle 1, a vehicle exterior door handle, a lock button for the vehicle exterior door handle, another input device provided outside the vehicle 1, or any of these two. Including one or more combinations.
- the mobile terminal 2 includes a second input unit 32 capable of inputting data.
- the second input unit 32 is a touch panel display of the mobile terminal 2.
- the first input unit 31 may be provided separately from the vehicle 1, and the second input unit 32 may be provided separately from the mobile terminal 2.
- the first input unit 31 and the second input unit 32 may be a fingerprint sensor, an iris sensor, or a camera.
- the vehicle 1 includes a first calculation unit 33 that performs a calculation based on the authentication information Dc and the authentication parameter A input to the first input unit 31.
- the first calculation unit 33 is provided in the verification ECU 5 of the vehicle 1.
- the first calculation unit 33 obtains a calculation result A ′ calculated by a predetermined calculation formula (calculation algorithm) using the authentication information Dc and the authentication parameter A input to the first input unit 31.
- the mobile terminal 2 includes a second calculation unit 34 that performs a calculation based on the authentication information Dc and the authentication parameter B input to the second input unit 32.
- the second calculation unit 34 is provided in the terminal control unit 20 of the mobile terminal 2.
- the second calculation unit 34 obtains a calculation result B ′ calculated by a predetermined calculation formula (calculation algorithm) using the authentication information Dc and the authentication parameter B input to the second input unit 32.
- the authentication system 3 includes an authentication unit 40 that executes authentication between the vehicle 1 and the mobile terminal 2.
- the authentication unit 40 performs authentication based on the calculation result of the first calculation unit 33 and the authentication parameter A, and the authentication information Dc is input to the second input unit 32. If so, authentication is performed based on the calculation result of the second calculation unit 34 and the authentication parameter B.
- the authentication unit 40 includes an authentication unit 41 provided in the verification ECU 5 and an authentication unit 42 provided in the terminal control unit 20.
- the authentication units 41 and 42 perform authentication based on the calculation result A ′ of the first calculation unit 33 and the authentication parameter B.
- the authentication units 41 and 42 perform authentication based on the calculation result B ′ of the second calculation unit 34 and the authentication parameter A.
- the authentication information Dc used for authentication is set when the electronic key is registered, for example. Further, the authentication parameter A and the authentication parameter B are generated by being associated with the authentication information Dc at the time of electronic key registration, and are registered in the vehicle 1 and the mobile terminal 2, respectively. Furthermore, the calculation formula (calculation algorithm) for calculating the calculation results A ′ and B ′ is given to the user interface application of the verification ECU 5 and the terminal control unit 20 at the time of electronic key registration, for example.
- the authentication units 41 and 42 confirm that the calculation result A ′ and the authentication parameter B match.
- the authentication units 41 and 42 confirm that the calculation result B ′ and the authentication parameter A match.
- step S101 the verification ECU 5 of the vehicle 1 periodically sends an advertisement message from the vehicle-side communication unit 8 to an area near the vehicle 1 in order to establish a short-distance communication connection with the mobile terminal 2.
- the terminal control unit 20 of the mobile terminal 2 enters the area near the vehicle 1 and receives the advertisement message, the terminal control unit 20 starts the short-range communication connection with the vehicle 1 with the vehicle-side communication unit 8.
- step S102 the vehicle 1 and the mobile terminal 2 operate according to a series of communication connection processes linked to the advertisement message, and automatically establish communication connection when device authentication (for example, address authentication) is established.
- device authentication for example, address authentication
- step S103 the vehicle 1 and the mobile terminal 2 start ID verification to confirm whether the electronic key ID is correct when the short-range communication connection is established.
- ID collation includes transmission / reception of an electronic key ID.
- the verification ECU 5 prohibits the operation of the vehicle 1 when the ID verification is unsuccessful.
- the verification ECU 5 starts authentication using the authentication information Dc.
- step S104 the verification ECU 5 accepts data input to the first input unit 31 when the ID verification is successful.
- the verification ECU 5 notifies the user of an input request for the authentication information Dc, and causes the first input unit 31 to input the authentication information Dc.
- the input request of the authentication information Dc is notified to the user by voice or display.
- the verification ECU 5 proceeds to step S105.
- the verification ECU 5 ends the process when the authentication information Dc is not input to either the first input unit 31 or the second input unit 32.
- step S105 the first calculation unit 33 of the verification ECU 5 calculates based on the authentication information Dc and the authentication parameter A input to the first input unit 31 to obtain a calculation result A ′.
- the calculation result A ′ of the first input unit 31 is written and stored in the memory 7.
- step S106 the authentication unit 41 generates a challenge code composed of random numbers having different values each time it is transmitted.
- the authentication unit 41 transmits a challenge signal including the generated challenge code to the mobile terminal 2.
- step S107 the authentication unit 41 calculates a challenge code by using the calculation result A ′ and generates a response code on the vehicle 1 side.
- step S108 upon receiving the challenge signal, the authentication unit 42 of the terminal control unit 20 calculates the challenge code included in the challenge signal using the authentication parameter B registered in the mobile terminal 2, and the mobile terminal 2 side Generate a response code.
- step S109 the authentication unit 42 transmits the response signal including the generated response code on the side of the mobile terminal 2 to the vehicle 1.
- the authentication unit 41 upon receiving the response signal from the mobile terminal 2, the authentication unit 41 confirms whether the response codes on the vehicle 1 side and the mobile terminal 2 side match. The authentication unit 41 determines that the authentication has been established when the response codes on the vehicle 1 side and the mobile terminal 2 side match. On the other hand, when the response codes on the vehicle 1 side and the mobile terminal 2 side do not match, the authentication unit 41 determines that the authentication has not been established.
- the second calculation unit 34 calculates “B XOR Dc” as the calculation result B ′.
- “B XOR Dc” indicates the exclusive ethics of the authentication parameter B and the authentication information Dc.
- the response code calculated using the calculation result B ′ matches the response code calculated using the authentication parameter A.
- the calculation formula of the first calculation unit 33 is configured to generate the calculation result A ′ that matches the authentication parameter B when calculated using the authentic authentication information Dc and the authentication parameter A.
- the calculation formula of the second calculation unit 34 is configured to generate a calculation result B ′ that matches the authentication parameter A when calculated using the authentic authentication information Dc and the authentication parameter B.
- step S111 the verification ECU 5 permits the operation of the in-vehicle device 4 when it is determined that the authentication is established.
- the verification ECU 5 permits locking / unlocking of the door lock and starting of the engine.
- step S201 when the vehicle 1 and the mobile terminal 2 are connected via short-distance communication and ID verification is established, the terminal control unit 20 proceeds to step S202.
- step S202 the terminal control unit 20 accepts data input to the second input unit 32.
- the terminal control unit 20 notifies the user of the input request of the authentication information Dc by the user interface application and causes the second input unit 32 to input the authentication information Dc.
- the terminal control unit 20 proceeds to step S203.
- the terminal control unit 20 accepts an input to the second input unit 32 until the verification ECU 5 completes the authentication process.
- step S203 the second calculation unit 34 of the terminal control unit 20 performs a calculation based on the authentication information Dc and the authentication parameter B input to the second input unit 32 to obtain a calculation result B ′.
- the calculation result B ′ is stored in the memory 23.
- step S204 the terminal control unit 20 transmits to the vehicle 1 an ACK signal that notifies the second input unit 32 that the authentication information Dc has been input.
- step S205 the authentication units 41 and 42 start authentication using the calculation result. Authentication using the calculation result corresponds to steps S106 to S111 in FIG.
- the authentication unit 42 transmits to the vehicle 1 a response signal including the response code on the mobile terminal 2 side calculated using the calculation result B ′.
- the authentication unit 41 confirms whether the response code on the vehicle 1 side calculated using the authentication parameter A and the response code on the portable terminal 2 side match.
- the authentication unit 41 determines that the authentication is established when the response code on the vehicle 1 side matches the response code on the mobile terminal 2 side.
- the authentication system 3 calculates the calculation result A ′ based on the first input unit 31, the second input unit 32, the authentication information Dc and the authentication parameter A input to the first input unit 31. And a second calculation unit 34 that calculates a calculation result B ′ based on the authentication information Dc and the authentication parameter B input to the second input unit 32. Moreover, when the authentication information Dc is input to the first input unit 31, the authentication system 3 performs authentication based on the calculation result A ′ and the authentication parameter B, and the authentication information Dc is input to the second input unit 32. In this case, the authentication unit 40 that performs authentication based on the calculation result B ′ and the authentication parameter A is provided.
- the authentication is not established by a third party who does not know the authentic authentication information Dc. Further, the user only needs to input the authentication information Dc into either the first input unit 31 or the second input unit 32, which is more convenient than the case where input is required in a predetermined input unit. Is improved. Therefore, both security and convenience can be achieved.
- the authentication unit 40 when the authentication information Dc is input to the first input unit 31, the authentication unit 40 confirms that the calculation result A ′ matches the authentication parameter B. Further, when the authentication information Dc is input to the second input unit 32, the authentication unit 40 confirms that the calculation result B ′ matches the authentication parameter A. According to this configuration, in order to establish the authentication, it is necessary to perform the calculation with the calculation formulas determined on both the vehicle 1 side and the mobile terminal 2 side. Therefore, it contributes to the improvement of security.
- the constitution is such that the coincidence of the response codes calculated on the vehicle 1 side and the portable terminal 2 side is confirmed. .. According to this configuration, it is not necessary to transmit / receive the calculation results A ′ and B ′ and the authentication parameters A and B between the vehicle 1 and the mobile terminal 2, which contributes to the improvement of security.
- the first input unit 31 is provided in the vehicle 1 and the second input unit 32 is provided in the mobile terminal 2.
- the vehicle 1 can be operated by inputting the authentication information Dc to either the vehicle 1 side or the mobile terminal 2 side. This contributes to improvement of user convenience.
- the second embodiment is different from the first embodiment in that it has a plurality of different authentication information. Therefore, the same reference numerals are given to the same member configurations as those of the first embodiment, detailed description thereof will be omitted, and only different portions will be described in detail.
- the vehicle 1 includes a door lock device 10 and an engine 11 used as the vehicle-mounted device 4.
- the vehicle 1 also includes a body ECU 12 that controls the door lock device 10 and an engine ECU 13 that controls the engine 11.
- These ECUs are connected to the verification ECU 5 through a communication line 6 inside the vehicle.
- the vehicle 1 includes a vehicle door 14 and an exterior door handle 15 that is provided on the vehicle door 14 and that operates the opening and closing of the vehicle door 14.
- the door lock device 10 is a mechanical mechanism configured to lock and unlock the vehicle door 14.
- the exterior door handle 15 includes a touch sensor 16 and a lock button 17.
- the touch sensor 16 detects a user's touch operation on the exterior door handle 15 as a trigger for unlocking the door.
- the lock button 17 detects a user's touch operation on the vehicle exterior door handle 15 as a trigger for locking the door.
- the body ECU 12 controls the operation of the door lock device 10 based on the detection signals of the touch sensor 16 and the lock button 17 when the ID verification is established and the authentication is established.
- the operation of the door lock device 10 corresponds to the first operation of the vehicle 1.
- the vehicle 1 includes an engine switch 18 for operating the power transition of the engine 11.
- the engine switch 18 may be, for example, a push-type switch.
- the engine ECU 13 controls the transition of the engine 11 by operating the engine switch 18 under a predetermined condition.
- the predetermined condition for starting the engine 11 is that ID verification is established, authentication is established, a brake pedal (not shown) of the vehicle 1 is stepped on, a transmission of the vehicle 1 is transmitted. Is in the parking range and a combination of two or more of these.
- the transition of the engine 11 corresponds to the second operation of the vehicle 1.
- the authentication unit 40 performs the first authentication or the second authentication for each function of vehicle operation (locking / unlocking operation of the vehicle door 14, power supply transition operation of the vehicle 1) as the above-mentioned authentication.
- the authentication unit 40 performs different arithmetic processing in the first authentication or the second authentication.
- the first authentication is performed when the vehicle door 14 is locked and unlocked
- the second authentication is performed when the power supply transition operation of the vehicle 1 is performed.
- the authentication unit 41 includes a first authentication unit 41a that performs the first authentication and a second authentication unit 41b that performs the second authentication.
- the authentication unit 42 also includes a first authentication unit 42a that performs the first authentication and a second authentication unit 42b that performs the second authentication.
- the memory 7 of the vehicle 1 stores the first authentication parameter A1 used in the first authentication and the second authentication parameter A2 used in the second authentication.
- the memory 23 of the mobile terminal 2 also stores the first authentication parameter B1 used in the first authentication and the second authentication parameter B2 used in the second authentication.
- the authentication information Dc includes first authentication information Dc1 and second authentication information Dc2 which are different from each other.
- the first authentication information Dc1 is used for the first authentication.
- the second authentication information Dc2 is used for the second authentication.
- the first authentication parameter A1 and the first authentication parameter B1 are generated in association with the first authentication information Dc1. Further, the second authentication parameter A2 and the second authentication parameter B2 are generated in association with the second authentication information Dc2.
- the first calculation unit 33 calculates the calculation result A1 ′ based on the authentication information Dc and the first authentication parameter A1, and the authentication information Dc and the second authentication parameter.
- a calculation result A2 ′ calculated based on A2 is obtained.
- the second calculation unit 34 calculates the calculation result B1 ′ based on the authentication information Dc and the first authentication parameter B1, and the authentication information Dc and the second authentication parameter.
- a calculation result B2 ′ calculated based on B2 is obtained.
- the first authentication units 41a and 42a determine that the first authentication is established when the calculation result A1 ′ and the first authentication parameter B1 or the calculation result B1 ′ and the first authentication parameter A1 match.
- the second authentication units 41b and 42b determine that the second authentication is established when the calculation result A2 ′ and the second authentication parameter B2 or the calculation result B2 ′ and the second authentication parameter A2 match.
- the first authentication information Dc1 is input to the first input unit 31
- the calculation result A1 ′ and the first authentication parameter B1 match.
- the calculation result B1 ′ and the first authentication parameter A1 match.
- the calculation result A2 ′ and the second authentication parameter B2 match. Furthermore, when the second authentication information Dc2 is input to the second input unit 32, the calculation result B2 ′ and the second authentication parameter A2 match.
- step S301 the authentication process is started.
- step S302 the verification ECU 5 proceeds to step S303 when the authentication information Dc is input to the first input unit 31.
- the first calculation unit 33 obtains a calculation result A1 ′ by a predetermined calculation formula using the authentication information Dc and the first authentication parameter A1.
- the first calculation unit 33 obtains a calculation result A2 ′ by a predetermined calculation formula using the authentication information Dc and the second authentication parameter A2.
- step S304 the authentication unit 41 generates a challenge code composed of random numbers having different values each time it is transmitted.
- the authentication unit 41 transmits a challenge signal including the challenge code to the mobile terminal 2.
- step S305 the first authentication unit 41a calculates a challenge code using the calculation result A1 ′ to generate a first response code on the vehicle 1 side. Moreover, the 2nd authentication part 41b calculates a challenge code using the calculation result A2 ', and produces
- step S306 when the challenge signal is received, the first authentication unit 42a calculates the challenge code using the first authentication parameter B1 and generates the first response code on the mobile terminal 2 side.
- the second authentication unit 42b also calculates a challenge code using the second authentication parameter B2 to generate a second response code on the mobile terminal 2 side.
- step S307 the first authenticating unit 42a and the second authenticating unit 42b transmit the first response code and the second response code on the mobile terminal 2 side to the vehicle 1.
- step S308 the first authentication unit 41a determines whether the first response codes on the vehicle 1 side and the mobile terminal 2 side match.
- step S302 when the first authentication information Dc1 is input to the first input unit 31, the calculation result A1 ′ and the first authentication parameter B1 match, so the first response code on the vehicle 1 side and the mobile terminal 2 side Also matches.
- the first authentication unit 41a determines that the first authentication has been established.
- the verification ECU 5 moves to step S308.
- the verification ECU 5 proceeds to step S307 if the first authentication is not established.
- step S309 the second authentication unit 41b determines whether the second response codes on the vehicle 1 side and the portable terminal 2 side match.
- the second authentication information Dc2 is input to the first input unit 31 in step S302
- the calculation result A2 ′ and the second authentication parameter B2 match, so the second response code on the vehicle 1 side and the mobile terminal 2 side Also matches.
- the second authentication unit 41b determines that the second authentication has been established.
- the verification ECU 5 moves to step S309. On the other hand, the verification ECU 5 ends the process when the second authentication is not established.
- step S310 if the first authentication is established, the verification ECU 5 allows the body ECU 12 to operate the door lock device 10. Thereby, the body ECU 12 controls the operation of the door lock device 10 based on the detection signals of the touch sensor 16 and the lock button 17.
- step S311 the verification ECU 5 allows the engine ECU 13 to start the engine 11. As a result, the engine ECU 13 controls the starting of the engine 11 by operating the engine switch 18 under predetermined conditions.
- the second calculation unit 34 calculates the calculation results B1 ′ and B2 ′. Then, the first authentication is performed by confirming the match between the calculation result B1 ′ and the first authentication parameter A1 by transmitting and receiving the challenge signal and the response signal described above, and the calculation result B2 ′ and the second authentication parameter A2 match. The second authentication is performed by confirming.
- the authentication information Dc includes the first authentication information Dc1 and the second authentication information Dc2 that are different from each other.
- the verification ECU 5 permits the operation of the door lock device 10 of the vehicle 1
- the second authentication is permitted based on the second authentication information Dc2. If so, the verification ECU 5 permits the start of the engine 11 of the vehicle 1.
- different first authentication information Dc1 and second authentication information Dc2 need to be input to establish the first authentication and the second authentication, respectively. That is, the authentication system 3 inputs different authentication information Dc when the door lock device 10 of the vehicle 1 is operated and when the engine 11 is changed.
- Only one of the first authentication information Dc1 and the second authentication information Dc2 does not permit all operations of the vehicle 1, which contributes to the improvement of security.
- the vehicle 1 is remotely operated by using the user interface application of the mobile terminal 2 or the like, it is possible to suppress an erroneous operation.
- the authentication system 3 includes a parameter updating unit 50 that updates the authentication parameters A and B with new values.
- the parameter updating unit 50 includes a parameter updating unit 51 and a parameter updating unit 52.
- the parameter updating unit 51 is provided in the verification ECU 5 and updates the authentication parameter A.
- the parameter updating unit 52 is provided in the terminal control unit 20 and updates the authentication parameter B.
- the parameter updating units 51 and 52 update the authentication parameters A and B when the authentication is successful.
- the parameter updating units 51 and 52 are configured to confirm all the authentication parameters when the authentication is established based on any one of the plurality of authentication parameters. To update. It is assumed that the vehicle 1 and the mobile terminal 2 have first authentication parameters A1 and B1 used for the first authentication and second authentication parameters A2 and B2 used for the second authentication, for example. In this case, the parameter updating units 51 and 52 update all of the first authentication parameters A1 and B1 and the second authentication parameters A2 and B2 when either the first authentication or the second authentication is established.
- the authentication system 3 includes the parameter updating unit that updates the authentication parameter A on the vehicle 1 side and the authentication parameter B on the mobile terminal 2 side to new values when the authentication is successful.
- the authentication parameters A and B can be updated each time authentication is performed, which contributes to improvement in security.
- the present embodiment can be modified and implemented as follows.
- the present embodiment and the following modified examples can be implemented in combination with each other within a technically consistent range.
- the arithmetic expressions (arithmetic algorithms) of the first arithmetic unit 33 and the second arithmetic unit 34 are not limited to exclusive ethics, but addition and subtraction, multiplication and division, and exponentiation are used. May be calculated, or an elliptic curve point may be calculated.
- the confidentiality of the authentication information Dc can be secured by setting the arithmetic expression so that the authentication information Dc is not estimated from the authentication parameters A and B.
- the authentication parameters to be updated may be only the authentication parameters used for the authentication, or the authentication parameters that have passed a certain period since the last update.
- the first authentication and the second authentication may be performed in association with each other.
- the second authentication may be performed only within a certain time after the first authentication is established.
- the plurality of pieces of authentication information Dc are not limited to two, and may be three or more, and may be any number as long as they are plural. This can be changed appropriately according to the specifications.
- the authentication information Dc may be a password using alphanumeric symbols, a personal identification number, a hieroglyphic pattern, biometric information of the user, or a combination thereof. May be.
- the biometric information includes fingerprints, faces, veins, palm shapes, irises, retinas, and the like.
- the authentication information Dc input to the first input unit 31 and the second input unit 32 may be different.
- the authentication information Dc is a password and biometric information
- the password may be input to the first input unit 31 and the biometric information may be input to the second input unit 32.
- the vehicle 1 and the mobile terminal 2 may be provided with authentication parameters for password and biometric information for authentication.
- the calculation result A ′ obtained by calculating the authentication parameter A and the authentication parameter B may match.
- the calculation result B ′ obtained by calculating the authentication parameter B and the authentication parameter A may match.
- the authentication parameter A and the authentication parameter B may be a plaintext and ciphertext relationship using the authentication information Dc as a common key.
- the arithmetic expressions of the 1st calculating part 33 and the 2nd calculating part 34 may differ, respectively, and may be the same.
- the authentication information Dc can be changed at any timing after the electronic key registration, and for example, when the authentication is successful, the authentication information Dc may be changed by the user's operation. When the authentication information Dc is changed, the authentication parameters A and B associated with the authentication information Dc are also changed.
- the authentication unit 42 may generate a challenge code and the authentication unit 42 may confirm that the response codes match when authenticating the calculation result and the authentication parameter.
- the vehicle 1 and the mobile terminal 2 may be authenticated by one-way authentication or mutual authentication.
- the mutual authentication for example, the challenge code is transmitted from the vehicle 1 to the mobile terminal 2, the response code generated by both sides is confirmed by the vehicle 1, and the challenge code is transmitted from the mobile terminal 2 to the vehicle 1 so that both sides can transmit the challenge code.
- the mobile terminal 2 confirms that the generated response codes match.
- the authentication unit 40 may confirm these matches by simply comparing the calculation result and the authentication parameter.
- the match may be confirmed by using a ciphertext obtained by encrypting the operation result and the authentication parameter, or the match may be confirmed by using a hash value obtained by hashing the operation result and the authentication parameter.
- the hash value may be a hashed version of the challenge code and the operation result, and the challenge code and the authentication parameter, or may be a hashed version of the operation result and the authentication parameter.
- the determination as to whether or not the authentication is established may be performed by either the vehicle 1 or the mobile terminal 2.
- short-distance wireless communication is not limited to Bluetooth communication, and may be changed to another communication method.
- the mobile terminal 2 is not limited to a high-performance mobile phone, and may be various terminals.
- the electronic key of the vehicle 1 may be used.
- the communication partner is not limited to the vehicle 1 and may be applied to other members such as a door of an accommodation facility, a gate machine of a coin parking, and a locker of a delivery box.
- each of the verification ECU, the terminal control unit, the calculation unit, the authentication unit, and the parameter updating unit can be configured by using one or more dedicated circuits or one or more processors.
- each of the vehicle 1 and the mobile terminal 2 may be provided with a memory (computer-readable non-transitory storage medium) connected to one or more processors.
- the memory may store one or more programs that include instructions executable by one or more processors.
- the instruction group causes the processor to execute the key information generation processing according to the present disclosure when they are executed.
- the program executes the processes of steps 101 to 111 of the sequence shown in FIG. 2, the processes of steps 201 to 205 of the sequence shown in FIG. 3, and the processes of steps 301 to 311 of the sequence shown in FIG. 5 to the processor. It includes a group of instructions to be executed. Therefore, the present disclosure can also provide a computer-readable non-transitory storage medium storing such a program.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- Mechanical Engineering (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Lock And Its Accessories (AREA)
Abstract
携帯端末(2)と通信相手(1)との間で無線を通じて認証を行い、その認証結果に基づき通信相手の作動を許可する認証システム(3)は、互いに別の場所に設けられ、認証に用いられる認証情報を入力可能な第1入力部(31)及び第2入力部(32)と、第1入力部(31)に入力された認証情報及び通信相手(1)に登録された通信相手側認証パラメータを基に演算を行う第1演算部(33)と、第2入力部(32)に入力された認証情報及び携帯端末(2)に登録された携帯端末側認証パラメータを基に演算を行う第2演算部(34)と、第1入力部(31)に認証情報が入力された場合、第1演算部(33)の演算結果及び携帯端末側認証パラメータを基に認証を行い、第2入力部(32)に認証情報が入力された場合、第2演算部(34)の演算結果及び通信相手側認証パラメータを基に認証を行う認証部(40~42)と、を備える。
Description
本発明は、携帯端末とその通信相手との間で無線を通じて認証を行う認証システム及び認証方法に関する。
従来、車両の制御を行うために、ユーザに所持される携帯端末と車両に搭載される車載機との間の無線通信を通じて認証を行う認証システムが知られている。認証システムとしては、スマート照合システムが知られている。スマート照合システムのID照合(スマート照合)では、携帯端末が、車載機からの送信電波に自動で応答して車載機と無線通信を行う。
この種のスマート照合システムに関して、中継器を使用した不正行為が存在する。このような不正行為では、例えば携帯端末が車載機から遠い場所に位置する場合に、中継器が、携帯端末から車載機への通信を中継する。
特許文献1は、車両に設けられた入力部に入力された認証情報を用いて認証を行う認証システムを開示する。認証システムは、入力部に入力された認証情報が予め登録された認証情報と一致するか否かを判定する。
スマート照合システムに特許文献1の認証システムが適用された場合、スマート照合システムは、ユーザに認証情報の認証を課してセキュリティ性を向上させることができる。しかし、この種の認証システムでは、予め決められた入力部へ認証情報を入力する作業が認証の度に必要となり、ユーザにとって利便性が悪くなってしまうという問題があった。
本開示の一側面の認証システムは、携帯端末とその通信相手との間で無線を通じて認証を行い、その認証結果に基づき前記通信相手の作動を許可する認証システムであって、互いに別の場所に設けられ、前記認証に用いられる認証情報を入力可能な第1入力部及び第2入力部と、前記第1入力部に入力された前記認証情報及び前記通信相手に登録された通信相手側認証パラメータを基に演算を行う第1演算部と、前記第2入力部に入力された前記認証情報及び前記携帯端末に登録された携帯端末側認証パラメータを基に演算を行う第2演算部と、前記第1入力部に前記認証情報が入力された場合、前記第1演算部の演算結果及び前記携帯端末側認証パラメータを基に前記認証を行い、前記第2入力部に前記認証情報が入力された場合、前記第2演算部の演算結果及び前記通信相手側認証パラメータを基に前記認証を行う認証部と、を備える。
本開示の他の側面の認証方法は、携帯端末とその通信相手との間で無線を通じて認証を行い、その認証結果に基づき前記通信相手の作動を許可する認証方法であって、互いに別の場所に設けられた第1入力部及び第2入力部の少なくとも一方に入力された前記認証に用いられる認証情報を受け取ることと、前記第1入力部に入力された前記認証情報、及び前記通信相手に登録された通信相手側認証パラメータを基に演算を行うことと、前記第2入力部に入力された前記認証情報、及び前記携帯端末に登録された携帯端末側認証パラメータを基に演算を行うことと、前記第1入力部に前記認証情報が入力された場合、前記通信相手側認証パラメータを基に演算した演算結果及び前記携帯端末側認証パラメータを基に前記認証を行い、前記第2入力部に前記認証情報が入力された場合、前記携帯端末側認証パラメータを基に演算した演算結果及び前記通信相手側認証パラメータを基に前記認証を行うことと、を備える。
本発明の目的は、セキュリティ性及び利便性の両立を可能とした認証システム及び認証方法を提供することにある。
<第1実施形態>
通信相手の制御を行うための認証を行う認証システム及び認証方法の第1実施形態について、図1~図3を用いて説明する。
通信相手の制御を行うための認証を行う認証システム及び認証方法の第1実施形態について、図1~図3を用いて説明する。
第1実施形態では、認証システム3は、通信相手として車両1に適用されている。認証システム3は、車両1および携帯端末2を備える。車両1は、車載機器4、照合ECU(Electronic Control Unit)5、および車両側通信部8を含む。例えば、車載機器4は、ドアロック装置、エンジン、又はこれらの両方を含む。認証システム3は、その認証結果に基づき、車載機器4の作動を許可又は実行する。携帯端末2は、電話機能を有し、近距離無線通信を用いて車両1と通信可能な高機能携帯電話であることが好ましい。一例では、認証システム3は、車両1からの近距離無線通信を契機に近距離無線通信によってID照合を実行する近距離無線照合システムである。例えば、近距離無線通信は、ブルートゥース(Bluetooth:登録商標)通信である。
照合ECU5は、ID照合を行うように構成されている。照合ECU5は、車内の通信線6を通じて車載機器4に接続されている。通信線6は、例えばCAN(Controller Area Network)またはLIN(Local Interconnect Network)からなる。
照合ECU5は、データを書き込み及び書き替え可能なメモリ7を含む。メモリ7は、車両1に登録された少なくとも1つの携帯端末2の電子キーIDを保存している。一例では、ID照合は、電子キーIDの正否を確認する電子キーID照合である。認証システム3では、電子キーID照合の成立は、車載機器4の作動を許可又は実行するための複数の条件のうちの一条件である。
メモリ7は、車両1及び携帯端末2の間の認証で用いる認証パラメータAを保存している。認証システム3では、認証パラメータAを用いた認証の成立が、車載機器4の作動を許可又は実行するための複数の条件のうちの一条件である。なお、認証パラメータAが通信相手側認証パラメータに相当する。
車両側通信部8は、携帯端末2との間で近距離無線通信を行う。例えば、車両側通信部8は、近距離無線通信として、携帯端末2との間でBLE(Bluetooth Low Energy)通信を行う。近距離無線通信において、携帯端末2がマスタであり、車両1がスレーブである。他の例では、近距離無線通信において、携帯端末2がスレーブであり、車両1がマスタでもよい。車両側通信部8は、車両1の近傍エリアに定期的にアドバタイズメッセージを送信する。
携帯端末2は、携帯端末2の作動を制御する端末制御部20と、携帯端末2においてネットワーク通信を行なうネットワーク通信モジュール21と、携帯端末2において近距離無線通信を行う端末通信部22と、データを書き込み及び書き換え可能なメモリ23と、を備えている。例えば、端末通信部22は、近距離無線通信としてBLE通信を行う。
メモリ23は、携帯端末2の電子キーID、及び認証パラメータBを保存している。一例では、携帯端末2は、携帯端末2を車両1に登録(電子キー登録)する際に、携帯端末2の電子キーIDをネットワーク通信を通じてサーバ(図示略)から取得する。携帯端末2は、取得された携帯端末2の電子キーIDを、無線通信を介して車両1に登録する。認証パラメータBは、車両1と携帯端末2との間の認証に使用される。なお、認証パラメータBが携帯端末側認証パラメータに相当する。
一例では、携帯端末2の端末制御部20は、携帯端末2において認証システム3の作動を管理するユーザインタフェースアプリケーション(図示略)を実装している。端末制御部20は、ユーザインタフェースアプリケーションを用いて、車両1への携帯端末2の登録(電子キー登録)、車両ドアの施解錠操作、車両1のエンジンの始動操作、または任意の2つ以上の組み合わせを含む種々の処理を実行する。
携帯端末2が車両1からのアドバタイズメッセージを受信して携帯端末2と車両1との間で近距離無線通信の接続が確立されると、携帯端末2は、車両1と相互に近距離無線通信を行って自動的にID照合を実行する。例えば、携帯端末2の電子キー登録が完了し、かつ車両1と携帯端末2との間で近距離無線通信の接続が確立している場合、電子キーIDが照合ECU5と端末制御部20との間で送受信されて電子キーIDの照合を行う。なお、これら一連のID照合では、ユーザが携帯端末2を操作することなく、また、ユーザが車両1を操作することなく自動的に処理が実行される。
認証システム3は、車両1及び携帯端末2の間の通信を通じて認証パラメータA及び認証パラメータBを用いた認証を行う。認証システム3は、ユーザによって入力された認証情報Dcを受け取り、入力された認証情報Dc、認証パラメータA、及び認証パラメータBに基づいて認証の判定を行う。例えば、認証情報Dcは、認証システム3に予め登録しておいたパスワードである。なお、認証システム3は、ID照合の前、ID照合の後、及びID照合の途中のいずれのタイミングでこのような認証を実施してもよい。
一例では、車両1は、データ入力可能な第1入力部31を含む。例えば、第1入力部31は、車両1の室内に設けられたカーナビゲーションシステム、車外ドアハンドル、車外ドアハンドルのロックボタン、車両1の室外に設けられたその他の入力装置、またはこれら任意の2つ以上の組み合わせを含む。携帯端末2は、データ入力可能な第2入力部32を含む。例えば、第2入力部32は、携帯端末2のタッチパネルディスプレイである。他の例では、第1入力部31は、車両1とは別個に設けられてもよく、また、第2入力部32は、携帯端末2とは別個に設けられてもよい。また他の例では、第1入力部31及び第2入力部32は、指紋センサや虹彩センサ、カメラでもよい。
車両1は、第1入力部31に入力された認証情報Dc及び認証パラメータAを基に演算を行う第1演算部33を含む。例えば、第1演算部33は、車両1の照合ECU5に設けられている。第1演算部33は、第1入力部31に入力された認証情報Dc及び認証パラメータAを用いて所定の演算式(演算アルゴリズム)により演算された演算結果A´を求める。
携帯端末2は、第2入力部32に入力された認証情報Dc及び認証パラメータBを基に演算を行う第2演算部34を含む。例えば、第2演算部34は、携帯端末2の端末制御部20に設けられている。第2演算部34は、第2入力部32に入力された認証情報Dc及び認証パラメータBを用いて所定の演算式(演算アルゴリズム)により演算された演算結果B´を求める。
認証システム3は、車両1及び携帯端末2の間の認証を実行する認証部40を備えている。認証部40は、第1入力部31に認証情報Dcが入力された場合、第1演算部33の演算結果及び認証パラメータAを基に認証を行い、第2入力部32に認証情報Dcが入力された場合、第2演算部34の演算結果及び認証パラメータBを基に認証を行う。一例では、認証部40は、照合ECU5に設けられた認証部41と、端末制御部20に設けられた認証部42とを含む。第1入力部31に認証情報Dcが入力された場合、認証部41,42は、第1演算部33の演算結果A´及び認証パラメータBを基に認証を行う。一方、認証部41,42は、第2入力部32に認証情報Dcが入力された場合、第2演算部34の演算結果B´及び認証パラメータAを基に認証を行う。
認証に用いられる認証情報Dcは、例えば電子キー登録時に設定される。また、認証パラメータA及び認証パラメータBは、電子キー登録時に、認証情報Dcに紐付けられて生成され、車両1及び携帯端末2にそれぞれ登録される。さらに、演算結果A´,B´を求める演算式(演算アルゴリズム)は、例えば電子キー登録時に、照合ECU5及び端末制御部20のユーザインターフェースアプリケーションに付与されている。
一例では、認証部41,42は、第1入力部31に認証情報Dcが入力された場合、演算結果A´及び認証パラメータBの一致を確認する。また、認証部41,42は、第2入力部32に認証情報Dcが入力された場合、演算結果B´及び認証パラメータAの一致を確認する。
次に、図2及び図3を用いて、第1実施形態の認証システムの作用及び効果について説明する。まず、図2を用いて認証において第1入力部31に認証情報Dcが入力された場合を説明する。
図2に示すように、ステップS101において、車両1の照合ECU5は、携帯端末2との近距離通信の接続を確立するために、車両側通信部8からアドバタイズメッセージを車両1の近傍エリアに定期的に送信する。携帯端末2の端末制御部20は、車両1の近傍エリアに進入し、アドバタイズメッセージを受信すると、車両側通信部8との間で車両1との近距離通信の接続を開始する。
ステップS102において、車両1及び携帯端末2は、アドバタイズメッセージに連なる一連の通信接続の処理に従って動作し、機器認証(例えばアドレス認証等)が成立すると、自動で通信接続する。両者の通信接続は、携帯端末2が車両1との近距離無線通信の範囲外へ移動するまで継続される。
ステップS103において、車両1及び携帯端末2は、近距離通信の接続が確立されると、電子キーIDの正否を確認するID照合を開始する。ID照合には、電子キーIDの送受信が含まれる。照合ECU5は、ID照合が不成立の場合、車両1の作動を禁止する。照合ECU5は、ID照合が成立した場合、認証情報Dcを用いた認証を開始する。
ステップS104において、照合ECU5は、ID照合が成立した場合、第1入力部31へのデータ入力を受け付ける。このとき、照合ECU5は、認証情報Dcの入力要求をユーザに通知し、第1入力部31に認証情報Dcを入力させる。例えば、認証情報Dcの入力要求は、音声または表示等によってユーザに通知される。照合ECU5は、第1入力部31へ認証情報Dcが入力された場合、ステップS105へ移行する。照合ECU5は、第1入力部31及び第2入力部32のどちらにも認証情報Dcが入力されなかった場合、処理を終了する。
ステップS105において、照合ECU5の第1演算部33は、第1入力部31へ入力された認証情報Dc及び認証パラメータAを基に演算を行い演算結果A´を求める。第1入力部31の演算結果A´は、メモリ7に書き込み保存される。
ステップS106において、認証部41は、送信の度に値の異なる乱数からなるチャレンジコードを生成する。認証部41は、生成されたチャレンジコードを含むチャレンジ信号を、携帯端末2へ送信する。
ステップS107において、認証部41は、演算結果A´を用いてチャレンジコードを演算して、車両1側のレスポンスコードを生成する。
ステップS108において、端末制御部20の認証部42は、チャレンジ信号を受信すると、携帯端末2に登録された認証パラメータBを用いてチャレンジ信号に含まれるチャレンジコードを演算して、携帯端末2側のレスポンスコードを生成する。
ステップS108において、端末制御部20の認証部42は、チャレンジ信号を受信すると、携帯端末2に登録された認証パラメータBを用いてチャレンジ信号に含まれるチャレンジコードを演算して、携帯端末2側のレスポンスコードを生成する。
ステップS109において、認証部42は、生成した携帯端末2側のレスポンスコードを含むレスポンス信号を、車両1へ送信する。
ステップS110において、認証部41は、携帯端末2からレスポンス信号を受信すると、車両1側及び携帯端末2側のレスポンスコードが一致しているか否かを確認する。認証部41は、車両1側及び携帯端末2側のレスポンスコードが一致している場合、認証が成立したと判定する。一方、認証部41は、車両1側及び携帯端末2側のレスポンスコードが一致しない場合、認証を不成立と判定する。
ステップS110において、認証部41は、携帯端末2からレスポンス信号を受信すると、車両1側及び携帯端末2側のレスポンスコードが一致しているか否かを確認する。認証部41は、車両1側及び携帯端末2側のレスポンスコードが一致している場合、認証が成立したと判定する。一方、認証部41は、車両1側及び携帯端末2側のレスポンスコードが一致しない場合、認証を不成立と判定する。
認証パラメータA,Bと、演算結果A´,B´との関係について説明する。ここでは、第1演算部33及び第2演算部34の演算式(演算アルゴリズム)の一例として、排他的倫理和(XOR)が用いられる。すなわち、第1入力部31に認証情報Dcが入力された場合、第1演算部33は、「A XOR Dc」を、演算結果A´として算出する。なお、「A XOR Dc」は、認証パラメータA及び認証情報Dcの排他的倫理和を示す。第1入力部31に正規の認証情報Dcが入力された場合、「A XOR Dc=B」の関係が成り立つようになっている。すなわち、演算結果A´及び認証パラメータBが一致する。演算結果A´及び認証パラメータBが一致する場合、演算結果A´を用いて演算したレスポンスコードは、認証パラメータBを用いて演算したレスポンスコードと一致する。また、第2入力部32に認証情報Dcが入力された場合、第2演算部34は、「B XOR Dc」を、演算結果B´として算出する。なお、「B XOR Dc」は、認証パラメータB及び認証情報Dcの排他的倫理和を示す。第2入力部32に正規の認証情報Dcが入力された場合、「B XOR Dc=A」の関係が成り立つようになっている。すなわち、演算結果B´及び認証パラメータAが一致する。演算結果B´及び認証パラメータAが一致する場合、演算結果B´を用いて演算したレスポンスコードは、認証パラメータAを用いて演算したレスポンスコードと一致する。つまり、第1演算部33の演算式は、正規な認証情報Dcおよび認証パラメータAを用いて演算された場合に認証パラメータBと一致する演算結果A´を生成するように構成される。第2演算部34の演算式は、正規な認証情報Dcおよび認証パラメータBを用いて演算された場合に認証パラメータAと一致する演算結果B´を生成するように構成される。
ステップS111において、照合ECU5は、認証が成立したと判定された場合、車載機器4の作動を許可する。例えば、照合ECU5は、ドアロックの施解錠やエンジンの始動を許可する。
次に、図3を用いて、第2入力部32へ認証情報Dcが入力された場合について説明する。
図3に示すように、ステップS201において、車両1及び携帯端末2が近距離通信接続され、かつID照合が成立すると、端末制御部20は、ステップS202へ移行する。
図3に示すように、ステップS201において、車両1及び携帯端末2が近距離通信接続され、かつID照合が成立すると、端末制御部20は、ステップS202へ移行する。
ステップS202において、端末制御部20は、第2入力部32へのデータ入力を受け付ける。このとき、端末制御部20は、ユーザインタフェースアプリケーションにより、ユーザへ認証情報Dcの入力要求を通知し、第2入力部32へ認証情報Dcを入力させる。端末制御部20は、第2入力部32へ認証情報Dcが入力された場合、ステップS203へ移行する。なお、端末制御部20は、照合ECU5によって認証の処理が終了されるまで、第2入力部32への入力を受け付ける。
ステップS203において、端末制御部20の第2演算部34は、第2入力部32へ入力された認証情報Dc及び認証パラメータBを基に演算を行い演算結果B´を求める。演算結果B´は、メモリ23に保存される。
ステップS204において、端末制御部20は、第2入力部32に認証情報Dcの入力があったことを通知するアック信号を、車両1へ送信する。
ステップS205において、認証部41,42は、演算結果を用いた認証を開始する。演算結果を用いた認証とは、図2のステップS106~S111に相当する。ここでは、認証部42は、演算結果B´を用いて演算した携帯端末2側のレスポンスコードを含むレスポンス信号を車両1へ送信する。認証部41は、認証パラメータAを用いて演算した車両1側のレスポンスコードと、携帯端末2側のレスポンスコードとが一致するかを確認する。認証部41は、車両1側のレスポンスコードが携帯端末2側のレスポンスコードと一致する場合、認証が成立したと判定する。
ステップS205において、認証部41,42は、演算結果を用いた認証を開始する。演算結果を用いた認証とは、図2のステップS106~S111に相当する。ここでは、認証部42は、演算結果B´を用いて演算した携帯端末2側のレスポンスコードを含むレスポンス信号を車両1へ送信する。認証部41は、認証パラメータAを用いて演算した車両1側のレスポンスコードと、携帯端末2側のレスポンスコードとが一致するかを確認する。認証部41は、車両1側のレスポンスコードが携帯端末2側のレスポンスコードと一致する場合、認証が成立したと判定する。
このように、本例では、認証システム3は、第1入力部31と、第2入力部32と、第1入力部31に入力された認証情報Dc及び認証パラメータAを基に演算結果A´を求める第1演算部33と、第2入力部32に入力された認証情報Dc及び認証パラメータBを基に演算結果B´を求める第2演算部34とを備えた。また、認証システム3は、第1入力部31に認証情報Dcが入力された場合、演算結果A´及び認証パラメータBを基に認証を行い、第2入力部32に認証情報Dcが入力された場合、演算結果B´及び認証パラメータAを基に認証を行う認証部40を備えた。この構成によれば、認証の過程において、ユーザに認証情報Dcを入力させるので、正規の認証情報Dcを知らない第三者に認証を成立されることがない。さらに、ユーザにとっては、第1入力部31及び第2入力部32のどちらか一方に認証情報Dcを入力すればよいので、予め決められた入力部に入力が必要な場合と比較して利便性が向上する。したがって、セキュリティ性及び利便性の両立が可能となる。
一例では、認証部40は、第1入力部31に認証情報Dcが入力された場合、演算結果A´と、認証パラメータBとの一致を確認する。また、認証部40は、第2入力部32に認証情報Dcが入力された場合、演算結果B´と、認証パラメータAとの一致を確認する。この構成によれば、認証の成立のためには、車両1側及び携帯端末2側の双方に決められた演算式で演算を行う必要がある。したがって、セキュリティ性の向上に寄与する。
また、これら演算結果A´,B´と認証パラメータA,Bとの一致を確認する際に、それぞれを用いて演算した車両1側及び携帯端末2側のレスポンスコードの一致を確認する構成とした。この構成によれば、演算結果A´,B´及び認証パラメータA,Bを車両1及び携帯端末2の間で送受信する必要がないため、セキュリティ性の向上に寄与する。
一例では、第1入力部31は、車両1に設けられ、第2入力部32は、携帯端末2に設けられた。この構成によれば、車両1側及び携帯端末2側のどちらかへの認証情報Dcの入力により、車両1を作動させることができる。これは、ユーザの利便性の向上に寄与する。
<第2実施形態>
次に、認証システム及び認証方法の第2実施形態について、図4及び図5を用いて説明する。第2実施形態では、互いに異なる複数の認証情報を有している点で、第1実施形態と異なる。従って、第1実施形態と同一の部材構成については、同一の符号を付し、その詳細な説明を省略し、異なる部分のみ詳述する。
次に、認証システム及び認証方法の第2実施形態について、図4及び図5を用いて説明する。第2実施形態では、互いに異なる複数の認証情報を有している点で、第1実施形態と異なる。従って、第1実施形態と同一の部材構成については、同一の符号を付し、その詳細な説明を省略し、異なる部分のみ詳述する。
図4に示すように、車両1は、車載機器4として用いられるドアロック装置10及びエンジン11を含む。また、車両1は、ドアロック装置10を制御するボディECU12と、エンジン11を制御するエンジンECU13と、を含む。これらECUは、車内の通信線6を通じて照合ECU5と接続されている。
車両1は、車両ドア14と、該車両ドア14に設けられかつ車両ドア14の開閉を操作するための車外ドアハンドル15と、を含む。ドアロック装置10は、車両ドア14を施解錠するように構成された機械的な機構である。車外ドアハンドル15は、タッチセンサ16と、ロックボタン17と、を含む。タッチセンサ16は、ドア解錠するときなどのトリガとして車外ドアハンドル15に対するユーザのタッチ操作を検出する。ロックボタン17は、ドア施錠するときなどのトリガとして車外ドアハンドル15に対するユーザのタッチ操作を検出する。ボディECU12は、ID照合が成立し、かつ認証が成立しているときに、タッチセンサ16及びロックボタン17の検出信号を基に、ドアロック装置10の作動を制御する。ドアロック装置10の作動が車両1の第1の作動に該当する。
車両1は、エンジン11の電源遷移を操作するためのエンジンスイッチ18を含む。エンジンスイッチ18は、例えばプッシュ式のスイッチでもよい。エンジンECU13は、所定の条件下でエンジンスイッチ18が操作されることでエンジン11の遷移を制御する。なお、エンジン11の始動の所定の条件とは、ID照合が成立していること、認証が成立していること、車両1のブレーキペダル(図示略)が踏まれていること、車両1のトランスミッションがパーキングレンジに入っていること、及びこれらの2つ以上の組み合わせが挙げられる。エンジン11の遷移が車両1の第2の作動に該当する。
一例では、認証部40は、前述の認証として、車両操作の機能(車両ドア14の施解錠操作、車両1の電源遷移操作)ごとに第1認証又は第2認証を行う。認証部40は、第1認証又は第2認証において異なる演算処理を行う。本例の場合、車両ドア14の施解錠操作の際に第1認証が実行され、車両1の電源遷移操作の際に第2認証が実行される。認証部41は、第1認証を行う第1認証部41aと、第2認証を行う第2認証部41bとを有している。また、認証部42は、第1認証を行う第1認証部42aと、第2認証を行う第2認証部42bとを有している。
車両1のメモリ7は、第1認証で用いられる第1認証パラメータA1と、第2認証で用いられる第2認証パラメータA2とを保存している。また、携帯端末2のメモリ23は、第1認証で用いられる第1認証パラメータB1と、第2認証で用いられる第2認証パラメータB2とを保存している。
認証情報Dcは、互いに異なる第1認証情報Dc1と、第2認証情報Dc2とを含む。第1認証情報Dc1は、第1認証に用いられる。第2認証情報Dc2は、第2認証に用いられる。第1認証パラメータA1及び第1認証パラメータB1は、第1認証情報Dc1に紐づけられて生成されている。また、第2認証パラメータA2及び第2認証パラメータB2は、第2認証情報Dc2に紐づけられて生成されている。
第1演算部33は、第1入力部31に認証情報Dcが入力されると、認証情報Dc及び第1認証パラメータA1を基に演算した演算結果A1´と、認証情報Dc及び第2認証パラメータA2を基に演算した演算結果A2´とを求める。第2演算部34は、第2入力部32に認証情報Dcが入力されると、認証情報Dc及び第1認証パラメータB1を基に演算した演算結果B1´と、認証情報Dc及び第2認証パラメータB2を基に演算した演算結果B2´とを求める。
第1認証部41a,42aは、演算結果A1´及び第1認証パラメータB1、又は演算結果B1´及び第1認証パラメータA1が一致する場合に、第1認証を成立と判定する。第2認証部41b,42bは、演算結果A2´及び第2認証パラメータB2、又は演算結果B2´及び第2認証パラメータA2が一致する場合に、第2認証を成立と判定する。ここで、第1入力部31に第1認証情報Dc1が入力された場合、演算結果A1´及び第1認証パラメータB1が一致する。また、第2入力部32に第1認証情報Dc1が入力された場合、演算結果B1´及び第1認証パラメータA1が一致する。また、第1入力部31に第2認証情報Dc2が入力された場合、演算結果A2´及び第2認証パラメータB2が一致する。さらに、第2入力部32に第2認証情報Dc2が入力された場合、演算結果B2´及び第2認証パラメータA2が一致する。
次に、図5を用いて、第2実施形態の認証システムの作用及び効果を説明する。ここでは、第1入力部31に認証情報Dcが入力された場合について説明する。
図5に示すように、ステップS301において、ID照合が完了すると、認証の処理が開始される。
図5に示すように、ステップS301において、ID照合が完了すると、認証の処理が開始される。
ステップS302において、照合ECU5は、第1入力部31に認証情報Dcが入力されると、ステップS303へ移行する。
ステップS303において、第1演算部33は、認証情報Dc及び第1認証パラメータA1を用いて所定の演算式により演算結果A1´を求める。また、第1演算部33は、認証情報Dc及び第2認証パラメータA2を用いて所定の演算式により演算結果A2´を求める。
ステップS303において、第1演算部33は、認証情報Dc及び第1認証パラメータA1を用いて所定の演算式により演算結果A1´を求める。また、第1演算部33は、認証情報Dc及び第2認証パラメータA2を用いて所定の演算式により演算結果A2´を求める。
ステップS304において、認証部41は、送信の度に値の異なる乱数からなるチャレンジコードを生成する。認証部41は、チャレンジコードを含むチャレンジ信号を、携帯端末2へ送信する。
ステップS305において、第1認証部41aは、演算結果A1´を用いてチャレンジコードを演算して、車両1側の第1レスポンスコードを生成する。また、第2認証部41bは、演算結果A2´を用いてチャレンジコードを演算して、車両1側の第2レスポンスコードを生成する。
ステップS306において、チャレンジ信号を受信すると、第1認証部42aは、第1認証パラメータB1を用いてチャレンジコードを演算して、携帯端末2側の第1レスポンスコードを生成する。また、第2認証部42bは、第2認証パラメータB2を用いてチャレンジコードを演算して、携帯端末2側の第2レスポンスコードを生成する。
ステップS307において、第1認証部42a及び第2認証部42bは、携帯端末2側の第1レスポンスコード及び第2レスポンスコードを、車両1へ送信する。
ステップS308において、第1認証部41aは、車両1側及び携帯端末2側の第1レスポンスコードが一致するか否かを判定する。ステップS302で、第1入力部31に第1認証情報Dc1が入力された場合は、演算結果A1´及び第1認証パラメータB1が一致するので、車両1側及び携帯端末2側の第1レスポンスコードも一致する。車両1側及び携帯端末2側の第1レスポンスコードが一致する場合、第1認証部41aは、第1認証が成立したと判定する。照合ECU5は、第1認証が成立した場合、ステップS308へ移行する。一方、照合ECU5は、第1認証が不成立の場合、ステップS307へ移行する。
ステップS308において、第1認証部41aは、車両1側及び携帯端末2側の第1レスポンスコードが一致するか否かを判定する。ステップS302で、第1入力部31に第1認証情報Dc1が入力された場合は、演算結果A1´及び第1認証パラメータB1が一致するので、車両1側及び携帯端末2側の第1レスポンスコードも一致する。車両1側及び携帯端末2側の第1レスポンスコードが一致する場合、第1認証部41aは、第1認証が成立したと判定する。照合ECU5は、第1認証が成立した場合、ステップS308へ移行する。一方、照合ECU5は、第1認証が不成立の場合、ステップS307へ移行する。
ステップS309において、第2認証部41bは、車両1側及び携帯端末2側の第2レスポンスコードが一致するか否かを判定する。ステップS302で、第1入力部31に第2認証情報Dc2が入力された場合は、演算結果A2´及び第2認証パラメータB2が一致するので、車両1側及び携帯端末2側の第2レスポンスコードも一致する。車両1側及び携帯端末2側の第2レスポンスコードが一致する場合、第2認証部41bは、第2認証が成立したと判定する。照合ECU5は、第2認証が成立した場合、ステップS309へ移行する。一方、照合ECU5は、第2認証が不成立の場合、処理を終了する。
ステップS310において、第1認証が成立した場合、照合ECU5は、ボディECU12にドアロック装置10の作動を許可する。これにより、ボディECU12は、タッチセンサ16及びロックボタン17の検出信号を基に、ドアロック装置10の作動を制御する。
ステップS311において、第2認証が成立した場合、照合ECU5は、エンジンECU13にエンジン11の始動を許可する。これにより、エンジンECU13は、所定の条件下でエンジンスイッチ18が操作されることでエンジン11の始動を制御する。
なお、本例において、第2入力部32に認証情報Dcが入力された場合、第2演算部34によって演算結果B1´,B2´が演算される。そして、上述のチャレンジ信号及びレスポンス信号の送受信によって、演算結果B1´及び第1認証パラメータA1の一致を確認することで、第1認証が行われ、演算結果B2´及び第2認証パラメータA2の一致を確認することで第2認証が行われる。
このように、本例では、認証情報Dcに、互いに異なる第1認証情報Dc1及び第2認証情報Dc2が含まれている。また、第1認証情報Dc1を基に第1認証が許可された場合、照合ECU5は、車両1のドアロック装置10の作動を許可し、第2認証情報Dc2を基に第2認証が許可された場合、照合ECU5は、車両1のエンジン11の始動を許可する。この構成によれば、第1認証及び第2認証の成立には、それぞれ異なる第1認証情報Dc1及び第2認証情報Dc2が入力される必要がある。すなわち、認証システム3は、車両1のドアロック装置10を作動させるときと、エンジン11を遷移させるときとで、別の認証情報Dcを入力させる。第1認証情報Dc1及び第2認証情報Dc2の一方だけでは、車両1の全ての作動が許可されないので、セキュリティ性の向上に寄与する。また、例えば携帯端末2のユーザインタフェースアプリケーションなどを用いて、車両1を遠隔で操作する場合に、誤操作を抑制できる。
<第3実施形態>
次に、認証システムの第3実施形態を、図6を用いて説明する。第3実施形態についても第1実施形態と異なる部分のみ詳述する。
次に、認証システムの第3実施形態を、図6を用いて説明する。第3実施形態についても第1実施形態と異なる部分のみ詳述する。
図6に示すように、認証システム3は、認証パラメータA,Bを新たな値に更新するパラメータ更新部50を備えている。パラメータ更新部50は、パラメータ更新部51と、パラメータ更新部52と、を含む。パラメータ更新部51は、照合ECU5に設けられ、認証パラメータAを更新する。パラメータ更新部52は、端末制御部20に設けられ、認証パラメータBを更新する。パラメータ更新部51,52は、認証が成立した場合に、認証パラメータA,Bを更新する。
パラメータ更新部51,52は、例えば車両1及び携帯端末2に複数の認証パラメータを有する場合、複数の認証パラメータのうちのいずれかの認証パラメータを基に認証が成立した際に、全ての認証パラメータを更新する。仮に、車両1及び携帯端末2が、例えば第1認証に用いられる第1認証パラメータA1,B1及び第2認証に用いられる第2認証パラメータA2,B2を有すると仮定する。この場合、パラメータ更新部51,52は、第1認証及び第2認証のいずれかが成立した際に、第1認証パラメータA1,B1及び第2認証パラメータA2,B2の全てを更新する。
このように、本例では、認証システム3は、認証が成立した場合に、車両1側の認証パラメータA及び携帯端末2側の認証パラメータBを新たな値に更新するパラメータ更新部を備えた。この構成によれば、認証のたびに認証パラメータA,Bを更新できるので、セキュリティ性の向上に寄与する。
なお、本実施形態は、以下のように変更して実施することができる。本実施形態及び以下の変更例は、技術的に矛盾しない範囲で互いに組み合わせて実施することができる。
・各実施形態において、第1演算部33及び第2演算部34の演算式(演算アルゴリズム)は、排他的倫理和に限定されず、加法や減法を用いたり、乗法や除法を用いたり、べき乗を計算したり、楕円曲線状の点を計算したりするものでもよい。認証パラメータA,Bから認証情報Dcが推測されないように演算式を設定することで、認証情報Dcの秘匿性を確保できる。
・各実施形態において、第1演算部33及び第2演算部34の演算式(演算アルゴリズム)は、排他的倫理和に限定されず、加法や減法を用いたり、乗法や除法を用いたり、べき乗を計算したり、楕円曲線状の点を計算したりするものでもよい。認証パラメータA,Bから認証情報Dcが推測されないように演算式を設定することで、認証情報Dcの秘匿性を確保できる。
・第3実施形態において、更新される認証パラメータは、認証に用いられた認証パラメータだけとしてもよいし、前回更新されてから一定の期間が経った認証パラメータを更新することとしてもよい。
・第2実施形態において、第1認証及び第2認証を、関連付けて行ってもよい。例えば、第1認証の成立後、一定時間以内のみ第2認証を実行する態様としてもよい。
・第2実施形態において、複数の認証情報Dcは、2つに限定されず、3つ以上であってもよく、複数であればいくつでもよい。これは、仕様に応じて適宜変更可能である。
・第2実施形態において、複数の認証情報Dcは、2つに限定されず、3つ以上であってもよく、複数であればいくつでもよい。これは、仕様に応じて適宜変更可能である。
・各実施形態において、認証情報Dcは、英数記号を用いたパスワードでもよいし、暗証番号でもよいし、象形パターンでもよいし、ユーザの生体情報であってもよいし、これらの組み合わせであってもよい。なお、生体情報には、指紋、顔、静脈、掌形、虹彩、網膜などが含まれる。
・各実施形態において、第1入力部31及び第2入力部32に入力される認証情報Dcは、異なっていてもよい。例えば、認証情報Dcがパスワード及び生体情報である場合、第1入力部31にはパスワードが入力され、第2入力部32には、生体情報が入力されるようにしてもよい。この場合、車両1及び携帯端末2にパスワード用及び生体情報用の認証パラメータが設けられて認証が行われればよい。
・各実施形態において、第1入力部31に正規の認証情報Dcが入力された場合、認証パラメータAを演算して得られた演算結果A´と、認証パラメータBとが一致してもよい。また、第2入力部32に正規の認証情報Dcが入力された場合、認証パラメータBを演算して得られた演算結果B´と、認証パラメータAとが一致してもよい。さらに、認証パラメータA及び認証パラメータBは、認証情報Dcを共通鍵とした平文及び暗号文の関係であってもよい。
・各実施形態において、第1演算部33及び第2演算部34の演算式は、それぞれ異なっていてもよいし、同じでもよい。
・各実施形態において、認証情報Dcは、電子キー登録後の任意のタイミングで、変更可能であり、例えば認証が成立した場合に、ユーザの操作により認証情報Dcを変更してもよい。なお、認証情報Dcが変更されると、認証情報Dcに紐付けられた認証パラメータA,Bも変更される。
・各実施形態において、認証情報Dcは、電子キー登録後の任意のタイミングで、変更可能であり、例えば認証が成立した場合に、ユーザの操作により認証情報Dcを変更してもよい。なお、認証情報Dcが変更されると、認証情報Dcに紐付けられた認証パラメータA,Bも変更される。
・各実施形態において、演算結果及び認証パラメータの認証の際に、認証部42がチャレンジコードを生成し、認証部42がレスポンスコードの一致を確認する態様としてもよい。
・各実施形態において、車両1及び携帯端末2の認証は、片方向認証でもよいし、相互認証でもよい。相互認証では、例えば、車両1から携帯端末2へチャレンジコードを送信し、双方で生成したレスポンスコードの一致を車両1で確認するとともに、携帯端末2から車両1へチャレンジコードを送信し、双方で生成したレスポンスコードの一致を携帯端末2で確認する。
・各実施形態において、認証部40は、演算結果及び認証パラメータを単に比較することにより、これらの一致を確認してもよい。
・各実施形態において、演算結果及び認証パラメータを暗号化した暗号文を用いてこれらの一致を確認してもよいし、演算結果及び認証パラメータをハッシュ化したハッシュ値を用いてこれらの一致を確認してもよい。なお、ハッシュ値は、チャレンジコード及び演算結果と、チャレンジコード及び認証パラメータとをそれぞれハッシュ化したものでもよいし、演算結果及び認証パラメータをそれぞれハッシュ化したものでもよい。
・各実施形態において、演算結果及び認証パラメータを暗号化した暗号文を用いてこれらの一致を確認してもよいし、演算結果及び認証パラメータをハッシュ化したハッシュ値を用いてこれらの一致を確認してもよい。なお、ハッシュ値は、チャレンジコード及び演算結果と、チャレンジコード及び認証パラメータとをそれぞれハッシュ化したものでもよいし、演算結果及び認証パラメータをそれぞれハッシュ化したものでもよい。
・各実施形態において、車両1側及び携帯端末2側で求めた演算値の一致を確認する場合、演算結果A´及び認証パラメータB、演算結果B´及び認証パラメータAが一致することは、構成要素から省略できる。すなわち、演算結果A´,B´及び認証パラメータA,Bを用いて認証情報Dcの正否が判定できればよい。
・各実施形態において、認証の成立可否の判定は、車両1及び携帯端末2のどちらで行ってもよい。
・各実施形態において、近距離無線通信は、ブルートゥース通信に限定されず、他の通信方式に変更してもよい。
・各実施形態において、近距離無線通信は、ブルートゥース通信に限定されず、他の通信方式に変更してもよい。
・各実施形態において、携帯端末2は、高機能携帯電話に限定されず、種々の端末であってもよい。例えば、車両1の電子キーでもよい。
・各実施形態において、通信相手は、車両1に限定されず、例えば宿泊施設のドア、コインパーキングのゲート機、宅配ボックスのロッカーなど、他の部材に適用されてもよい。
・各実施形態において、通信相手は、車両1に限定されず、例えば宿泊施設のドア、コインパーキングのゲート機、宅配ボックスのロッカーなど、他の部材に適用されてもよい。
明細書及び/又は特許請求の範囲に開示された全ての特徴は、当初の開示の目的のために、ならびに、実施形態及び/又は特許請求の範囲における特徴の組み合わせから独立して特許請求の範囲に記載の発明を限定する目的のために、互いに別個にかつ独立して開示されることを意図したものである。全ての数値範囲又は構成要素の集合を表す記載は、当初の開示の目的のため、ならびに特許請求の範囲に記載の発明を限定する目的のために、特に数値範囲の限定として、全ての可能な中間値又は中間的構成要素を開示するものである。
上記実施形態では、照合ECU、端末制御部、演算部、認証部、およびパラメータ更新部の各々は、1つ以上の専用回路または1つ以上のプロセッサを用いて構成することができる。また、車両1および携帯端末2の各々には、1つ以上のプロセッサに接続されたメモリ(コンピュータ読み取り可能な非一時的記憶媒体)が設けられてもよい。メモリは、1つ以上のプロセッサによって実行可能な命令群を含む1つ以上のプログラムを記憶してもよい。命令群は、それらが実行されたときに、本開示による鍵情報生成処理をプロセッサに実行させる。たとえば、プログラムは、図2に示すシーケンスのステップ101~ステップ111の処理、図3に示すシーケンスのステップ201~ステップ205の処理、図5に示すシーケンスのステップ301~ステップ311の処理をプロセッサに実行させる命令群を含む。従って、本開示により、このようなプログラムを記憶したコンピュータ読み取り可能な非一時的記憶媒体を提供することもできる。
1…車両、10…ドアロック装置、11…エンジン、2…携帯端末、20…端末制御部、3…認証システム、31…第1入力部、32…第2入力部、33…第1演算部、34…第2演算部、4…車載機器、40…認証部、41…認証部、42…認証部、5…照合ECU、50…パラメータ更新部、A…認証パラメータ、B…認証パラメータ、Dc…認証情報。
Claims (6)
- 携帯端末と通信相手との間で無線を通じて認証を行い、その認証結果に基づき前記通信相手の作動を許可する認証システムであって、
互いに別の場所に設けられ、前記認証に用いられる認証情報を入力可能な第1入力部及び第2入力部と、
前記第1入力部に入力された前記認証情報及び前記通信相手に登録された通信相手側認証パラメータを基に演算を行う第1演算部と、
前記第2入力部に入力された前記認証情報及び前記携帯端末に登録された携帯端末側認証パラメータを基に演算を行う第2演算部と、
前記第1入力部に前記認証情報が入力された場合、前記第1演算部の演算結果及び前記携帯端末側認証パラメータを基に前記認証を行い、前記第2入力部に前記認証情報が入力された場合、前記第2演算部の演算結果及び前記通信相手側認証パラメータを基に前記認証を行う認証部と、を備える認証システム。 - 前記認証部は、
前記第1入力部に前記認証情報が入力された場合、前記認証として、前記第1演算部の演算結果と前記携帯端末側認証パラメータとの一致を確認し、
前記第2入力部に前記認証情報が入力された場合、前記認証として、前記第2演算部の演算結果と前記通信相手側認証パラメータとの一致を確認する、請求項1に記載の認証システム。 - 前記第1入力部は、前記通信相手に設けられ、
前記第2入力部は、前記携帯端末に設けられている、請求項1又は請求項2に記載の認証システム。 - 前記認証情報は、互いに異なる第1認証情報及び第2認証情報を含み、
前記認証部は、前記第1認証情報を基に前記認証を行う第1認証と、前記第2認証情報を基に前記認証を行う第2認証とを実行し、
前記第1認証が成立した場合、前記通信相手の第1の作動を許可し、前記第2認証が成立した場合、前記通信相手の第2の作動を許可する、請求項1から請求項3のうちいずれか一項に記載の認証システム。 - 前記認証部による前記認証が成立した場合に、前記通信相手側認証パラメータ及び前記携帯端末側認証パラメータを新たな値に更新するパラメータ更新部をさらに備える請求項1から請求項4のうちいずれか一項に記載の認証システム。
- 携帯端末とその通信相手との間で無線を通じて認証を行い、その認証結果に基づき前記通信相手の作動を許可する認証方法であって、
互いに別の場所に設けられた第1入力部及び第2入力部の少なくとも一方に入力された前記認証に用いられる認証情報を受け取ることと、
前記第1入力部に入力された前記認証情報、及び前記通信相手に登録された通信相手側認証パラメータを基に演算を行うことと、
前記第2入力部に入力された前記認証情報、及び前記携帯端末に登録された携帯端末側認証パラメータを基に演算を行うことと、
前記第1入力部に前記認証情報が入力された場合、前記通信相手側認証パラメータを基に演算した演算結果及び前記携帯端末側認証パラメータを基に前記認証を行い、前記第2入力部に前記認証情報が入力された場合、前記携帯端末側認証パラメータを基に演算した演算結果及び前記通信相手側認証パラメータを基に前記認証を行うことと、を備える認証方法。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US17/291,044 US11812259B2 (en) | 2018-11-15 | 2019-11-13 | Authentication system and authentication method |
| CN201980074308.1A CN113039747B (zh) | 2018-11-15 | 2019-11-13 | 认证系统及认证方法 |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2018214331A JP7057944B2 (ja) | 2018-11-15 | 2018-11-15 | 認証システム及び認証方法 |
| JP2018-214331 | 2018-11-15 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020100929A1 true WO2020100929A1 (ja) | 2020-05-22 |
Family
ID=70731827
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2019/044488 Ceased WO2020100929A1 (ja) | 2018-11-15 | 2019-11-13 | 認証システム及び認証方法 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US11812259B2 (ja) |
| JP (1) | JP7057944B2 (ja) |
| CN (1) | CN113039747B (ja) |
| WO (1) | WO2020100929A1 (ja) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP7322732B2 (ja) * | 2020-02-03 | 2023-08-08 | トヨタ自動車株式会社 | 認証システム |
| JP7445528B2 (ja) * | 2020-06-09 | 2024-03-07 | 株式会社東海理化電機製作所 | システム、端末装置及び制御装置 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2005041474A1 (ja) * | 2003-10-28 | 2005-05-06 | The Foundation For The Promotion Of Industrial Science | 認証システム及び遠隔分散保存システム |
| JP2005252702A (ja) * | 2004-03-04 | 2005-09-15 | Komu Square:Kk | 資格認証システム、資格認証方法、および情報処理装置 |
| JP2012193499A (ja) * | 2011-03-15 | 2012-10-11 | Mitsubishi Electric Corp | 電子キー装置 |
| JP2017076874A (ja) * | 2015-10-14 | 2017-04-20 | 株式会社東海理化電機製作所 | ユーザ認証装置及び暗号鍵格納方法 |
Family Cites Families (37)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2001262891A (ja) * | 2000-03-21 | 2001-09-26 | Mitsubishi Electric Corp | 車両キーシステム |
| JP4156493B2 (ja) * | 2003-11-04 | 2008-09-24 | 株式会社東海理化電機製作所 | 車両用セキュリティ装置及びidコード管理装置 |
| CN101923613A (zh) * | 2004-10-08 | 2010-12-22 | 松下电器产业株式会社 | 认证系统 |
| JP4736398B2 (ja) * | 2004-10-22 | 2011-07-27 | 日本電気株式会社 | 近接する端末間における認証方法、秘匿情報の配送方法、装置、システム、及び、プログラム |
| JP4673251B2 (ja) * | 2006-05-11 | 2011-04-20 | アルプス電気株式会社 | キーレスエントリー装置 |
| JP4636171B2 (ja) * | 2008-12-17 | 2011-02-23 | トヨタ自動車株式会社 | 車両用生体認証システム |
| JP2010195061A (ja) * | 2009-02-23 | 2010-09-09 | Hitachi Automotive Systems Ltd | 車両盗難防止システムおよび方法 |
| JP5173891B2 (ja) * | 2009-03-02 | 2013-04-03 | 株式会社東海理化電機製作所 | 秘密鍵登録システム及び秘密鍵登録方法 |
| FR2965434B1 (fr) * | 2010-09-28 | 2015-12-11 | Valeo Securite Habitacle | Procede d'appairage d'un telephone mobile avec un vehicule automobile et ensemble de verrouillage/deverrouillage |
| US8880027B1 (en) * | 2011-12-29 | 2014-11-04 | Emc Corporation | Authenticating to a computing device with a near-field communications card |
| JP5730262B2 (ja) * | 2012-10-18 | 2015-06-03 | オムロンオートモーティブエレクトロニクス株式会社 | 車載システム、車両制御方法、及び、車両制御システム |
| WO2014146186A1 (en) * | 2013-03-22 | 2014-09-25 | Keyfree Technologies Inc. | Managing access to a restricted area |
| EP2995061B1 (en) * | 2013-05-10 | 2018-04-18 | OLogN Technologies AG | Ensuring proximity of wifi communication devices |
| KR102091161B1 (ko) * | 2013-12-05 | 2020-03-19 | 엘지전자 주식회사 | 이동 단말기 및 그것의 제어방법 |
| CN104184734B (zh) * | 2014-08-25 | 2018-02-16 | 广州优逸网络科技有限公司 | 无线认证方法、系统及装置 |
| US9424451B2 (en) * | 2014-10-20 | 2016-08-23 | GM Global Technology Operations LLC | Low-energy radio frequency tag for performing a vehicle function |
| US10101433B2 (en) * | 2015-05-01 | 2018-10-16 | GM Global Technology Operations LLC | Methods for locating a vehicle key fob |
| US9800610B1 (en) * | 2015-09-11 | 2017-10-24 | Symantec Corporation | Systems and methods for defeating relay attacks |
| JP6561762B2 (ja) * | 2015-10-21 | 2019-08-21 | 住友電気工業株式会社 | 車両用通信システム及び車載機 |
| US10231123B2 (en) * | 2015-12-07 | 2019-03-12 | GM Global Technology Operations LLC | Bluetooth low energy (BLE) communication between a mobile device and a vehicle |
| US9990783B2 (en) * | 2016-02-16 | 2018-06-05 | GM Global Technology Operations LLC | Regulating vehicle access using cryptographic methods |
| KR102098137B1 (ko) * | 2016-04-15 | 2020-04-08 | 가부시키가이샤 덴소 | 실시간 로케이션을 설정하기 위한 시스템 및 방법 |
| JP6477589B2 (ja) * | 2016-05-06 | 2019-03-06 | 株式会社デンソー | 車両用電子キーシステム |
| US9855918B1 (en) * | 2016-08-04 | 2018-01-02 | GM Global Technology Operations LLC | Proximity confirming passive access system for vehicle |
| CN106330910B (zh) * | 2016-08-25 | 2019-07-19 | 重庆邮电大学 | 车联网中基于节点身份和信誉的强隐私保护双重认证方法 |
| CN108076016B (zh) * | 2016-11-15 | 2021-07-02 | 中国移动通信有限公司研究院 | 车载设备之间的认证方法及装置 |
| JP6585664B2 (ja) * | 2017-06-29 | 2019-10-02 | 株式会社東海理化電機製作所 | カーシェアリングシステム |
| JP6670801B2 (ja) * | 2017-06-29 | 2020-03-25 | 株式会社東海理化電機製作所 | カーシェアリングシステム及びカーシェアリング用プログラム |
| US10415528B2 (en) * | 2017-06-30 | 2019-09-17 | GM Global Technology Operations LLC | Vehicle PEPS system calibration using a mobile device |
| JP6717793B2 (ja) * | 2017-10-10 | 2020-07-08 | 株式会社東海理化電機製作所 | カーシェアリングシステム及びカーシェア装置 |
| JP6525042B1 (ja) * | 2017-11-20 | 2019-06-05 | トヨタ自動車株式会社 | 施解錠システム |
| JP7210881B2 (ja) * | 2018-01-30 | 2023-01-24 | 株式会社デンソー | 車両用認証システム |
| US10391975B2 (en) * | 2018-01-30 | 2019-08-27 | Toyota Motor Engineering & Manufacturing North America, Inc. | Method to provide warning to relay attacks on keyless entry and start systems |
| US10911949B2 (en) * | 2018-07-23 | 2021-02-02 | Byton Limited | Systems and methods for a vehicle authenticating and enrolling a wireless device |
| US10733819B2 (en) * | 2018-12-21 | 2020-08-04 | 2162256 Alberta Ltd. | Secure and automated vehicular control using multi-factor authentication |
| US10924924B1 (en) * | 2019-09-09 | 2021-02-16 | Ford Global Technologies, Llc | Out-of-band key sharing using near-field communication |
| US20220180679A1 (en) * | 2019-12-28 | 2022-06-09 | Light Wave Technology Inc. | Vehicle control system |
-
2018
- 2018-11-15 JP JP2018214331A patent/JP7057944B2/ja active Active
-
2019
- 2019-11-13 US US17/291,044 patent/US11812259B2/en active Active
- 2019-11-13 WO PCT/JP2019/044488 patent/WO2020100929A1/ja not_active Ceased
- 2019-11-13 CN CN201980074308.1A patent/CN113039747B/zh active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2005041474A1 (ja) * | 2003-10-28 | 2005-05-06 | The Foundation For The Promotion Of Industrial Science | 認証システム及び遠隔分散保存システム |
| JP2005252702A (ja) * | 2004-03-04 | 2005-09-15 | Komu Square:Kk | 資格認証システム、資格認証方法、および情報処理装置 |
| JP2012193499A (ja) * | 2011-03-15 | 2012-10-11 | Mitsubishi Electric Corp | 電子キー装置 |
| JP2017076874A (ja) * | 2015-10-14 | 2017-04-20 | 株式会社東海理化電機製作所 | ユーザ認証装置及び暗号鍵格納方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| US11812259B2 (en) | 2023-11-07 |
| US20210400478A1 (en) | 2021-12-23 |
| CN113039747A (zh) | 2021-06-25 |
| CN113039747B (zh) | 2024-02-20 |
| JP7057944B2 (ja) | 2022-04-21 |
| JP2020088408A (ja) | 2020-06-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN109649332B (zh) | 车辆共享系统 | |
| JP6147983B2 (ja) | 電子キー登録システム | |
| JP5730262B2 (ja) | 車載システム、車両制御方法、及び、車両制御システム | |
| CN110011811B (zh) | 基于终端设备的车辆解锁认证方法及装置 | |
| US9020147B2 (en) | Electronic key registration method, electronic key registration system, and controller | |
| CN109389709B (zh) | 开锁控制系统及开锁控制方法 | |
| US10938829B2 (en) | Car sharing system | |
| JP2013166447A (ja) | 認証システム及び認証装置 | |
| WO2016031607A1 (ja) | 電子キーシステム及び照合装置 | |
| JP2014145200A (ja) | 施開錠権限付与システム、認証装置、携帯端末、およびプログラム | |
| JP2020170993A (ja) | 通信システム及び通信方法 | |
| JP7198682B2 (ja) | 認証システム及び認証方法 | |
| CN113039747B (zh) | 认证系统及认证方法 | |
| JP7428995B2 (ja) | 認証システム、及び認証方法 | |
| JP2010250748A (ja) | 認証システム及び認証方法 | |
| JP6901307B2 (ja) | ユーザ認証システム及びユーザ認証方法 | |
| EP3462669B1 (en) | Method and system for authentication with side-channel attack protection using pre-calculated ciphers | |
| JP5313754B2 (ja) | 認証システム及び認証方法 | |
| JP2021129158A (ja) | 認証システム及び認証方法 | |
| KR20210064584A (ko) | 스마트폰을 이용한 자동차용 스마트키장치 | |
| JP6212437B2 (ja) | 電子キーシステム | |
| US20250010815A1 (en) | Vehicle control device and vehicle control method | |
| JP2022042102A (ja) | 登録装置、端末機及び登録方法 | |
| JP2023123140A (ja) | 暗号鍵登録システム、暗号鍵登録方法、及び搭載装置 | |
| JP2021075232A (ja) | セキュリティ装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 19884178 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 19884178 Country of ref document: EP Kind code of ref document: A1 |