WO2022085243A1 - 車載装置、暗号化通信方法および暗号化通信プログラム - Google Patents
車載装置、暗号化通信方法および暗号化通信プログラム Download PDFInfo
- Publication number
- WO2022085243A1 WO2022085243A1 PCT/JP2021/025351 JP2021025351W WO2022085243A1 WO 2022085243 A1 WO2022085243 A1 WO 2022085243A1 JP 2021025351 W JP2021025351 W JP 2021025351W WO 2022085243 A1 WO2022085243 A1 WO 2022085243A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- key
- vehicle
- information
- packet
- processing unit
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/088—Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0825—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/64—Protecting data integrity, e.g. using checksums, certificates or signatures
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3236—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
- H04L9/3242—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving keyed hash functions, e.g. message authentication codes [MACs], CBC-MAC or HMAC
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/84—Vehicles
Definitions
- the present disclosure relates to in-vehicle devices, encrypted communication methods and encrypted communication programs.
- This application claims priority on the basis of Japanese Application Japanese Patent Application No. 2020-177070 filed on October 22, 2020 and incorporates all of its disclosures herein.
- Non-Patent Document 1 Korean Organic Chemical Networks, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc
- the in-vehicle device of the present disclosure is an in-vehicle device mounted on a vehicle, generates a first key derivation information according to the first method, and uses the first key derivation information to generate a first key information.
- the processing unit includes a processing unit that is generated and encrypts a packet using the first key information, and a communication unit that transmits the packet encrypted by the processing unit to another vehicle.
- the second key derivation information is generated according to the second method in which the key information generation time is shorter than that of the first method, and the second key information is generated.
- the second key information is generated using the key derivation information, and the second key information is used instead of the first key information to encrypt a packet newly transmitted by the communication unit.
- the encrypted communication method of the present disclosure is an encrypted communication method in an in-vehicle device mounted on a vehicle, in which the first key derivation information is generated according to the first method, and the first key derivation information is used.
- a step of generating a first key information and encrypting a packet using the first key information a step of transmitting the encrypted packet to another vehicle, and a step of using the first key information.
- the second key derivation information is generated according to the second method in which the key information generation time is shorter than that of the first method, and the second key derivation information is used. 2.
- the key information is generated, and the second key information is used instead of the first key information to encrypt a newly transmitted packet.
- the encrypted communication program of the present disclosure is an encrypted communication program used for an in-vehicle device mounted on a vehicle, and a computer generates a first key derivation information according to a first method, and the first key derivation information is generated.
- a processing unit that generates the first key information using the key derivation information and encrypts the packet using the first key information, and transmits the packet encrypted by the processing unit to another vehicle. It is a program for functioning as a communication unit, and the processing unit uses the first key information to encrypt the packet, and then the second method has a shorter key information generation time than the first method. According to the method, the second key derivation information is generated, the second key information is generated by using the second key derivation information, and the second key information is used instead of the first key information. , The packet newly transmitted by the communication unit is encrypted.
- One aspect of the present disclosure can be realized not only as an in-vehicle device provided with such a characteristic processing unit, but also as an in-vehicle communication system including the in-vehicle device. Further, one aspect of the present disclosure can be realized as a semiconductor integrated circuit that realizes a part or all of an in-vehicle device.
- FIG. 1 is a diagram showing a configuration of a vehicle management system according to an embodiment of the present disclosure.
- FIG. 2 is a diagram showing a configuration of an in-vehicle communication system according to an embodiment of the present disclosure.
- FIG. 3 is a diagram showing a configuration of an in-vehicle device in the in-vehicle communication system according to the embodiment of the present disclosure.
- FIG. 4 is a diagram showing a configuration of a processing unit in the in-vehicle device according to the embodiment of the present disclosure.
- FIG. 5 is a diagram showing the first half of a sequence showing the processing of encrypted communication in the vehicle management system according to the embodiment of the present disclosure.
- FIG. 6 is a diagram showing the latter half of the sequence showing the processing of encrypted communication in the vehicle management system according to the embodiment of the present disclosure.
- the present disclosure has been made to solve the above-mentioned problems, and an object thereof is to provide an in-vehicle device, an encryption method and a program capable of providing better communication in an in-vehicle network. ..
- the in-vehicle device is an in-vehicle device mounted on a vehicle, generates a first key derivation information according to the first method, and uses the first key derivation information.
- a processing unit that uses the first key information to generate the first key information and encrypts the packet using the first key information, and a communication unit that transmits the packet encrypted by the processing unit to another vehicle.
- the processing unit encrypts the packet using the first key information, and then follows the second method in which the key information generation time is shorter than that of the first method, and the second key derivation information is provided. Is generated, the second key information is generated using the second key derivation information, and the second key information is used instead of the first key information, and is newly transmitted by the communication unit. Encrypt the packet.
- the key information is generated in the vehicle and used for packet encryption, so that it is not necessary to use and manage the unique key stored in advance in each vehicle for a long period of time. Further, for example, by first using an encryption method having a certain degree of security and then switching to an encryption method having a short generation time, encrypted communication can be effectively performed according to the characteristics of each method. Therefore, better communication can be provided in the in-vehicle network.
- the processing unit encrypts the second key derivation information using the first key information
- the communication unit encrypts the second key derivation information encrypted by the processing unit. It may be transmitted to the other vehicle.
- the second key derivation information can be transmitted to another vehicle by using the first method having high security, and the generation time is short while ensuring security by simple processing. Encrypted communication using the second method can be started.
- the processing unit In the first method, the processing unit generates a pair of a private key and a public key as the first key derivation information, and generates a common key as the first key information using the pair. Then, in the second method, the processing unit generates a hash value by using the first cryptographic hash function as the second key derivation information, and the second cryptographic hash is generated from the hash value.
- a common key may be generated using a function, and the communication unit may transmit the hash value generated by the processing unit to the other vehicle.
- a common key using a cryptographic hash function can be generated faster than a pair of private key and public key. Therefore, the data can be encrypted in a short time, and more encrypted packets can be exchanged in the vehicle-to-vehicle communication.
- the processing unit When the predetermined condition is satisfied, the processing unit generates the second key information, and the second key information is newly transmitted by the communication unit in place of the first key information.
- the predetermined condition may be used for encryption of the packet, and is a condition relating to the elapsed time or the amount of communication with the other vehicle after the use of the first key information is started.
- the processing unit When the predetermined condition is satisfied, the processing unit generates the second key information, and the second key information is newly transmitted by the communication unit in place of the first key information.
- the predetermined condition used for encrypting the packet may be a condition relating to the traveling state of the vehicle.
- the encrypted communication using the first key information is encrypted using the second key information. Switching to communication can be performed at an appropriate timing.
- the processing unit may update the second key information.
- the subsequent encrypted communication can use the updated second key information, so that the encryption is performed.
- the possibility that the communication will be decrypted can be reduced.
- the security of the encrypted communication can be further enhanced.
- the second key information when the second key information is generated when the predetermined condition is satisfied, the second key information can be updated at an appropriate timing according to the predetermined condition.
- the processing unit may use the time information and the random number to generate the key derivation information in at least one of the first method and the second method.
- the key derivation information can be changed with the passage of time. Further, if the key derivation information is generated using only the time information, the time information may be estimated and the key derivation information may be deciphered. However, by using a random number in addition to the time information, it is possible to prevent the key derivation information from being deciphered even if the time information is estimated. Therefore, the security of encrypted communication can be further enhanced.
- the processing unit decodes the encrypted packet received from the other vehicle according to the first method or the second method, and the communication unit is stored in the decrypted packet. Data may be transmitted to the infrastructure side device.
- the vehicle data is uploaded to the infrastructure side device. be able to. Then, on the infrastructure side, the vehicle data can be analyzed in detail, and even if a problem occurs in the vehicle, it can be appropriately dealt with.
- the encrypted communication method is an encrypted communication method in an in-vehicle device mounted on a vehicle, in which the first key derivation information is generated according to the first method and described above.
- the second key derivation information is generated according to the second method in which the key information generation time is shorter than that of the first method.
- the second key information is generated by using the key derivation information of the above, and the second key information is used instead of the first key information to encrypt a newly transmitted packet.
- the key information is generated in the vehicle and used for packet encryption, so that it is not necessary to use and manage the unique key stored in advance in each vehicle for a long period of time. Further, for example, by first using an encryption method having a certain degree of security and then switching to an encryption method having a short generation time, encrypted communication can be effectively performed according to the characteristics of each method. Therefore, better communication can be provided in the in-vehicle network.
- the encrypted communication program according to the embodiment of the present disclosure is an encrypted communication program used for an in-vehicle device mounted on a vehicle, and a computer is subjected to a first key derivation information according to a first method.
- the second key derivation information is generated according to the second method having a short generation time, and the second key information is generated by using the second key derivation information.
- the second key information is used to encrypt a packet newly transmitted by the communication unit.
- the key information is generated in the vehicle and used for packet encryption, so that it is not necessary to use and manage the unique key stored in advance in each vehicle for a long period of time. Further, for example, by first using an encryption method having a certain degree of security and then switching to an encryption method having a short generation time, encrypted communication can be effectively performed according to the characteristics of each method. Therefore, better communication can be provided in the in-vehicle network.
- FIG. 1 is a diagram showing a configuration of a vehicle management system according to an embodiment of the present disclosure.
- the vehicle management system 1 includes a server 11, an infrastructure side device 12, an in-vehicle communication system 13 mounted on the vehicle 10A, and an in-vehicle communication system 14 mounted on another vehicle 10B. It is equipped with MEC (Mobile Edge Computing) 15 of the above.
- MEC Mobile Edge Computing
- the vehicle management system 1 makes it possible to exchange various data between the vehicles 10A and 10B and the server 11.
- the vehicle management system 1 makes it possible to upload camera images, moving images, and the like taken in the vehicles 10A and 10B to the server 11.
- the vehicle management system 1 makes it possible to transmit update programs of various software mounted on the vehicles 10A and 10B from the server 11 to the vehicles 10A and 10B.
- the vehicle 10A uploads log information including logs of various software in the vehicle 10A to the server 11 via the vehicle 10B.
- Vehicle 10A transmits log information to vehicle 10B.
- the vehicle 10B transmits the log information received from the vehicle 10A to the infrastructure side device 12 which is close to the vehicle 10B or has a good communication environment with the vehicle 10B.
- the infrastructure side device 12 is, for example, a radio base station device.
- the infrastructure side device 12 transmits the log information received from the vehicle 10B to the MEC 15.
- the infrastructure side device 12 may be a beacon. Further, the infrastructure side device 12 may include the MEC 15.
- the MEC15 analyzes the log information received from the infrastructure side device 12, shares the log information with other MEC15s, and complements the log information with each other.
- the MEC15 acquires emergency information such as accident information from log information, for example, the MEC15 issues an alarm to the vehicles 10A and 10B.
- the MEC 15 may issue an alarm directly to the vehicles 10A and 10B, may issue an alarm to the vehicle 10A via the vehicle 10B, or may issue an alarm to the vehicle 10B via the vehicle 10A. Further, the MEC 15 transmits the log information to the server 11.
- the server 11 analyzes the log information received from the MEC 15 in more detail and takes necessary measures.
- FIG. 2 is a diagram showing a configuration of an in-vehicle communication system according to an embodiment of the present disclosure.
- FIG. 2 shows the configuration of the vehicle-mounted communication system 13 in the vehicle 10A as an example, but the configuration of the vehicle-mounted communication system 14 in the other vehicle 10B is also the same.
- the vehicle-mounted communication system 13 includes vehicle-mounted devices 131 to 134 and a relay device 135.
- the in-vehicle communication system 13 is not limited to the configuration including four in-vehicle devices 131 to 134, but may be configured to include three or less or five or more in-vehicle devices. Further, the in-vehicle communication system 13 is not limited to the configuration including one relay device 135, and may be configured to include two or more relay devices.
- the in-vehicle device 131 is, for example, a TCU (Telematics Communication Unit).
- TCU Transmission Control Unit
- the in-vehicle device 131 is also referred to as a TCU 131.
- the in-vehicle devices 133 and 134 are, for example, an automatic operation ECU (Electronic Control Unit), a sensor, a navigation device, a human-machine interface, a camera, and the like.
- ECU Electronic Control Unit
- the in-vehicle device 132 will be described later.
- the in-vehicle devices 131 to 134 are connected to the relay device 135 via an Ethernet (registered trademark) cable.
- the relay device 135 is, for example, a switch device.
- the relay device 135 may be a gateway device.
- the relay device 135 relays the Ethernet frame according to the Ethernet communication standard.
- the relay device 135 relays, for example, an Ethernet frame exchanged between the in-vehicle devices 131 to 134. IP packets are stored in the Ethernet frame.
- the in-vehicle communication system 13 is not limited to a configuration in which an Ethernet frame is relayed according to an Ethernet communication standard, for example, CAN (Control Area Protocol) (registered trademark), FlexRay (registered trademark), MOST (Media Oriented Systems Transport). ) (Registered trademark) and LIN (Local Ethernet Protocol) and other communication standards may be used to relay data.
- CAN Control Area Protocol
- FlexRay registered trademark
- MOST Media Oriented Systems Transport
- LIN Local Ethernet Protocol
- the TCU 131 can communicate with the infrastructure side device 12. Specifically, the TCU 131 can communicate with the server 11 via the infrastructure side device 12, for example, according to the IP protocol.
- the TCU 131 can perform wireless communication with the infrastructure side device 12 according to a communication standard such as LTE (Long Term Evolution) or 5G.
- LTE Long Term Evolution
- 5G 5th Generation
- the TCU 131 when the TCU 131 receives a wireless frame containing an IP packet from an IP server from the infrastructure side device 12, it acquires an IP packet from the received wireless frame and converts the acquired IP packet into an Ethernet frame. It is stored and transmitted to the relay device 135.
- the TCU 131 when the TCU 131 receives an Ethernet frame from the relay device 135, it acquires an IP packet from the received Ethernet frame, stores the acquired IP packet in a wireless frame, and transmits the acquired IP packet to the infrastructure side device 12.
- the TCU 131 can wirelessly communicate with the TCU in another vehicle 10B by short-range wireless communication or the like.
- FIG. 3 is a diagram showing a configuration of an in-vehicle device in the in-vehicle communication system according to the embodiment of the present disclosure.
- FIG. 3 shows, as an example, the configuration of the in-vehicle device 132 in the vehicle 10A.
- the in-vehicle device 132 includes a communication unit 1321, a processing unit 1322, and a storage unit 1323.
- the communication unit 1321 is realized by, for example, a communication circuit such as a communication IC (Integrated Circuit).
- the processing unit 1322 is realized by, for example, a processor such as a CPU or a DSP (Digital Signal Processing).
- the storage unit 1323 is, for example, a non-volatile memory.
- the communication unit 1321 exchanges data with the vehicle 10B and the infrastructure side device 12 via the TCU 131. Further, the communication unit 1321 exchanges data with other in-vehicle devices 131, 133, 134 via the relay device 135.
- the processing unit 1322 divides the data into a plurality of IP packets and stores them, and performs processing such as encryption and decryption of the data portion of each IP packet.
- FIG. 4 is a diagram showing a configuration of a processing unit in the in-vehicle device according to the embodiment of the present disclosure.
- FIG. 4 shows, as an example, the configuration of the processing unit 1322 in the vehicle 10A.
- the processing unit 1322 includes a timer 1324, an encryption unit 1325, a decryption unit 1326, and a vehicle information acquisition unit 1327.
- the timer 1324 periodically stores the time information indicating the current time in the storage unit 1323.
- the vehicle information acquisition unit 1327 acquires information indicating a traveling state such as the speed of the vehicle 10A from another in-vehicle device via the relay device 135 and the communication unit 1321 and outputs the information to the encryption unit 1325.
- the encryption unit 1325 receives information indicating a traveling state from the vehicle information acquisition unit 1327, and when the information satisfies a predetermined condition as described later, the encryption unit 1325 acquires time information from the storage unit 1323, and obtains the time information and a random number. Encrypt IP packets using.
- the decryption unit 1326 when the decryption unit 1326 receives an encrypted IP packet from another vehicle 10B via the TCU 131, the relay device 135, and the communication unit 1321, the decryption unit 1326 decodes the IP packet.
- Each device in the vehicle management system 1 includes a computer, and an arithmetic processing unit such as a CPU in the computer reads a program including a part or all of each step of the following sequence diagram or flowchart from a memory (not shown) and executes the program. do.
- the programs of these plurality of devices can be installed from the outside.
- the programs of these plurality of devices are distributed in a state of being stored in a recording medium.
- FIG. 5 is a diagram showing the first half of a sequence showing the processing of encrypted communication in the vehicle management system according to the embodiment of the present disclosure.
- the infrastructure side device 12 periodically transmits time information to the vehicle 10A and another vehicle 10B (step S101).
- the vehicle 10A and the other vehicle 10B receive the time information from the infrastructure side device 12 and synchronize the time.
- time synchronization for example, NTP (Network Time Protocol) is used (step S102).
- NTP Network Time Protocol
- the vehicle 10A and the other vehicle 10B periodically broadcast a communicable notification indicating that the vehicle has entered the communicable range of its own vehicle. Then, when the other vehicle 10B enters the communicable range, the processing unit 1322 in the vehicle 10A receives a communicable notification from the other vehicle 10B via the TCU 131, the relay device 135, and the communication unit 1321 (step S103). ..
- the processing unit 1322 When the processing unit 1322 receives the communicable notification from the other vehicle 10B for the first time, the processing unit 1322 generates the first key derivation information according to the first method, and generates the first key information using the first key derivation information. do.
- the first method is, for example, an encryption method that combines an encryption method using a private key and a public key and an encryption method using a common key.
- the processing unit 1322 generates a pair of a private key and a public key as the first key derivation information by using the time information and the random number stored in the storage unit 1323. ..
- the processing unit 1322 stores the generated private key and public key pair in the storage unit 1323 (steps S104 and S105).
- the processing unit 1322 generates an electronic certificate for the generated public key and stores it in the storage unit 1323 (step S106).
- the processing unit 1322 in the other vehicle 10B also generates a pair of a private key and a public key as the first key derivation information by using the time information and the random number in the first method. do.
- the processing unit 1322 generates an electronic certificate for the generated public key and stores it in the storage unit 1323 (steps S107 to S109).
- the processing unit 1322 in the vehicle 10A transmits the public key and the digital certificate stored in the storage unit 1323 to the other vehicle 10B via the communication unit 1321 and the TCU 131 together with the key exchange request (step S110). ..
- the processing unit 1322 verifies the electronic certificate (step S111). ..
- step S112 when the processing unit 1322 confirms that the received public key is generated in the vehicle 10A, the generated public key and the electronic certificate are sent to the communication unit 1321 together with the key exchange response. And transmission to the vehicle 10A via the TCU 131 (step S112).
- step S113 when the processing unit 1322 in the vehicle 10A receives the public key, the electronic certificate, and the key exchange response from the other vehicle 10B via the TCU 131 and the communication unit 1321, the electronic certificate is verified (step S113).
- Step S114 when the processing unit 1322 in the vehicle 10A confirms that the received public key is generated in the other vehicle 10B, the key exchange result notification to that effect is notified via the communication unit 1321 and the TCU 131.
- the processing unit 1322 generates a common key K1 as the first key information using the generated private key and the public key received from the other vehicle 10B (step S115).
- the processing unit 1322 receives the key exchange result notification from the vehicle 10A via the TCU 131 and the communication unit 1321, the secret key and the vehicle generated in the other vehicle 10B are received.
- a common key K1 is generated using the public key received from 10A (step S116).
- the processing unit 1322 in the other vehicle 10B when the processing unit 1322 in the other vehicle 10B generates the common key K1, the processing unit 1322 transmits a common key confirmation request encrypted using the common key K1 to the vehicle 10A via the communication unit 1321 and the TCU 131 (step S117). ).
- the processing unit 1322 when the processing unit 1322 receives the common key confirmation request via the TCU 131 and the communication unit 1321, the received common key confirmation request is decoded using the common key K1 and the common key confirmation response is communicated. It is transmitted to another vehicle 10B via the unit 1321 and the TCU 131 (step S118).
- the processing unit 1322 encrypts the IP packet storing the data by using the common key K1 which is the first key information. More specifically, the processing unit 1322 divides and stores the log information of various software installed in the in-vehicle devices 131, 133, and 134 into a plurality of IP packets, for example. Then, the processing unit 1322 encrypts the data portion of the IP packet using the common key K1 and outputs the IP packet to the communication unit 1321 (step S119).
- the communication unit 1321 in the vehicle 10A receives the encrypted IP packet from the processing unit 1322 and transmits the IP packet to the other vehicle 10B via the TCU 131 (step S120).
- the processing unit 1322 when the processing unit 1322 receives the encrypted IP packet from the vehicle 10A via the TCU 131 and the communication unit 1321, the data portion of the IP packet is decoded using the common key K1. do.
- the processing unit 1322 transmits an IP packet containing a part of the log information acquired by decryption to the infrastructure side device 12 via the communication unit 1321 and the TCU 131.
- the processing unit 1322 encrypts a part of the log information and transmits it to the infrastructure side device 12.
- the encryption method at this time is not particularly limited, and a well-known encryption method may be used (step S121).
- FIG. 6 is a diagram showing the latter half of the sequence showing the processing of encrypted communication in the vehicle management system according to the embodiment of the present disclosure.
- the processing unit 1322 in the vehicle 10A encrypts the IP packet using the first key information and then satisfies the first predetermined condition
- the key information of the key information is higher than that of the first method.
- the second key derivation information is generated according to the second method having a short generation time, and the second key information is generated by using the second key derivation information.
- the processing unit 1322 uses the second key information instead of the first key information to encrypt the IP packet newly transmitted by the communication unit 1321 containing a part of the log information.
- the first predetermined condition is, for example, a condition relating to the elapsed time or the amount of communication with another vehicle 10B since the start of using the first key information. More specifically, the condition regarding the elapsed time is, for example, the case where the duration of the encrypted communication using the common key K1 is a predetermined time or longer. The condition regarding the communication amount is, for example, the case where the communication amount of the encrypted communication using the common key K1 becomes a predetermined amount or more.
- the first predetermined condition is not limited to the above condition, and may be, for example, a condition relating to the traveling state of the vehicle 10A. More specifically, it is a case where the difference in speed or acceleration between the vehicle 10A and the other vehicle 10B is equal to or larger than a predetermined value.
- the second method is, for example, an encryption method using a cryptographic hash function.
- the processing unit 1322 uses the time information and the random number stored in the storage unit 1323 to obtain the hash value by using the first cryptographic hash function. It is generated as key derivation information, and the common key K2, which is the second key information, is generated from the generated hash value by using the second cryptographic hash function (steps S122 to S124).
- the processing unit 1322 encrypts the hash value, which is the second key derivation information, using the common key K1 which is the first key information (step S125).
- the processing unit 1322 transmits the encrypted second key derivation information together with the key update request to the other vehicle 10B via the communication unit 1321, the relay device 135, and the TCU 131 (step S126).
- the processing unit 1322 in the other vehicle 10B receives the key update request and the encrypted second key derivation information hash value from the vehicle 10A via the TCU 131, the relay device 135, and the communication unit 1321, the processing unit 1322 receives the hash value.
- the hash value is decrypted using the common key K1 which is the first key information (step S127).
- the processing unit 1322 in the other vehicle 10B generates a common key K2 from the hash value which is the decrypted second key derivation information by using the second cryptographic hash function (step S128).
- the processing unit 1322 in the vehicle 10A sends a common key confirmation request to the communication unit 1321, the relay device 135, and the TCU 131 after a predetermined time has elapsed after transmitting the encrypted second key derivation information to the other vehicle 10B. It is transmitted to another vehicle 10B via (step S129).
- the processing unit 1322 in the other vehicle 10B receives the common key confirmation request from the vehicle 10A via, for example, the TCU 131, the relay device 135, and the communication unit 1321, and the generation of the common key K2 is completed.
- the key information used for encrypting the IP packet is switched from the common key K1 to the common key K2.
- the processing unit 1322 transmits the common key confirmation response to the vehicle 10A via the communication unit 1321, the relay device 135, and the TCU 131, and discards the common key K1 which is the first key information (steps S130 and S131).
- the processing unit 1322 in the vehicle 10A receives the common key confirmation response from the other vehicle 10B via the TCU 131 and the communication unit 1321, the key information used for encrypting the IP packet is transferred from the common key K1 to the common key K2. Switch. Then, the processing unit 1322 discards the common key K1 which is the first key information (step S132).
- the processing unit 1322 in the vehicle 10A is, for example, an IP packet that stores a part of the log information divided in step S119 of FIG. 5, and is data of an IP packet that has not yet been transmitted to another vehicle 10B.
- the portion is encrypted using the common key K2, and the IP packet is output to the communication unit 1321 (step S133).
- the communication unit 1321 in the vehicle 10A receives the encrypted IP packet from the processing unit 1322 and transmits the IP packet to the other vehicle 10B via the TCU 131 (step S134).
- the processing unit 1322 when the processing unit 1322 receives the encrypted IP packet from the vehicle 10A via the TCU 131 and the communication unit 1321, the packet reception response is sent to the vehicle 10A via the communication unit 1321 and the TCU 131.
- the data portion of the IP packet is decoded using the common key K2 (steps S135 and S136).
- the processing unit 1322 in the other vehicle 10B transmits a part of the log information acquired by decoding to the infrastructure side device 12 via the communication unit 1321 and the TCU 131.
- the processing unit 1322 encrypts the IP packet storing a part of the log information and transmits it to the infrastructure side device 12.
- the encryption method at this time is not particularly limited, and a well-known encryption method may be used (step S137).
- the processing unit 1322 in the vehicle 10A when the second predetermined condition is satisfied, the processing unit 1322 in the vehicle 10A generates new second key derivation information according to the second method, and uses the new second key derivation information. Generate new second key information. Then, the processing unit 1322 uses the new second key information to encrypt the IP packet newly transmitted by the communication unit 1321 that stores a part of the log information. More specifically, the processing unit 1322 uses, for example, a new cryptographic hash function as the second key derivation information using the time information and the random number when a predetermined time elapses from the start of the encrypted communication using the common key K2. Is generated, a new common key K2 is generated using the generated cryptographic hash function, and encrypted communication with another vehicle 10B using the common key K2 is started.
- the processing unit 1322 discards the old common key K2 after starting the encrypted communication using the new common key K2. In this way, when the second predetermined condition is satisfied, by updating the common key K2, security can be ensured even when the log information increases due to a change in the state of the vehicle 10A, for example. ..
- the second predetermined condition is not limited to the predetermined elapsed time from the start of the encrypted communication using the common key K2, and may be a condition related to the traveling state of the vehicle 10A.
- the processing unit 1322 performs encrypted communication while sequentially updating the second key information in the second method.
- the processing unit 1322 in the vehicle 10A transmits an IP packet encrypted using the common key, which is the second key information, to the other vehicle 10B, and then a packet reception response from the other vehicle 10B arrives within a predetermined time. If not, the common key, which is the second key information, the private key and public key pair, which is the first key derivation information, and the electronic certificate of the public key are destroyed, and encrypted communication with another vehicle 10B is performed. It ends (step S138).
- the vehicle 10A may transmit software log information in another vehicle 10B to the infrastructure side device 12. More specifically, in the other vehicle 10B, when the processing unit 1322 receives the encrypted IP packet from the vehicle 10A via the TCU 131 and the communication unit 1321, it is installed in each in-vehicle device in the other vehicle 10B.
- An IP packet containing a part of log information of various software may be encrypted by using the common key K1 or K2 and transmitted to the vehicle 10A together with a packet reception response via the communication unit 1321 and the TCU 131.
- the processing unit 1322 in the vehicle 10A decodes the IP packet received via the TCU 131 and the communication unit 1321 using the common key K1 or K2, and a part of the log information of the other vehicle 10B acquired by the decoding.
- the IP packet containing the above is transmitted to the infrastructure side device 12.
- the vehicle 10A and the other vehicle 10B use the common key K1 if the first predetermined condition is not satisfied within a predetermined time during encrypted communication using the common key K1 which is the first key information.
- the encrypted communication that was used is terminated. More specifically, if a predetermined time has elapsed since the vehicle 10A and the other vehicle 10B started using the common key K1 and the first predetermined condition is not satisfied, the vehicle 10A and the other vehicle 10B are common.
- the key K1 is destroyed and the encrypted communication is terminated.
- the vehicle 10A and the other vehicle 10B perform encrypted communication using the common key K1 regardless of the passage of time, for example, when one of the vehicles has finished running, or when the ignition or power is turned off. You may finish.
- the key information used for encrypting the IP packet is transmitted from the common key K1 to the common key K2. It is not limited to the configuration to switch to.
- the other vehicle 10B may switch the key information used for encrypting the IP packet from the common key K1 to the common key K2, for example, when an Ethernet frame containing a specific content such as a flag is received from the vehicle 10A. .. In this case, for example, when the vehicle 10A transmits an Ethernet frame containing the above specific content, the vehicle 10A switches the key information used for encrypting the IP packet from the common key K1 to the common key K2.
- data such as log information of various software of the vehicle is stored in, for example, an EDR (Event Data Recorder) mounted on the vehicle.
- EDR Event Data Recorder
- the log information that can be stored in the EDR is limited. Therefore, in order to collect more data, it is conceivable to upload vehicle log information to the server at any time. In this case, since data is exchanged between the vehicle and the server using wireless communication, it is necessary to encrypt the data.
- the common keys K1 and K2 are generated in the vehicle and used for encrypting the IP packet storing the data. ..
- the common keys K1 and K2 are destroyed when a predetermined time elapses and the wireless connection is disconnected. After that, when the IP packet is uploaded to the server 11 again, a new common key is generated and used for encryption of the IP packet. In this way, by generating the common keys K1 and K2 used for encrypting IP packets in the vehicle and using a timed expression that is used only for a specific period, the unique key stored in advance in each vehicle can be used for a long period of time.
- the subsequent encrypted communication is a common key different from the common keys K1 and K2. Is used. Therefore, it is possible to reduce the possibility that the subsequent encrypted communication will be decrypted again by the method of decrypting the previous encrypted communication. Therefore, better communication can be provided in the in-vehicle network.
- the vehicle 10A communicates with the infrastructure side device 12 using a standard such as LTE or 5G
- the communication becomes unstable depending on the position of the vehicle 10A or the communication environment, and it is difficult to upload data to the server 11. May become.
- the vehicle 10A uploads data to the server 11 via the other vehicle 10B and the infrastructure side device 12. .. Therefore, even if the communication between the vehicle 10A and the infrastructure side device 12 is unstable or impossible, if the other vehicle 10B can communicate with the infrastructure side device 12, the log information of the vehicle 10A should be uploaded to the server 11. Can be done. Therefore, better communication can be provided in the in-vehicle network.
- the vehicles 10A and 10B first use the first method, the pair of the private key and the public key.
- the common key K1 is generated by using it, and then the common key K2 using the cryptographic hash function, which is the second method, is generated and used for encryption.
- the common key K2 using the cryptographic hash function can be generated faster than the private key and public key pair. Therefore, the IP packet can be encrypted in a short time, and more encrypted IP packets can be exchanged in the vehicle-to-vehicle communication. Therefore, better communication can be provided in the in-vehicle network.
- Appendix 1 It is an in-vehicle device mounted on a vehicle.
- Department and A communication unit that transmits the packet encrypted by the processing unit to another vehicle is provided.
- the processing unit generates the second key derivation information according to the second method in which the key information generation time is shorter than that of the first method, and the second key information is used by using the second key derivation information. Is generated, and the second key information is used instead of the first key information to encrypt the packet newly transmitted by the communication unit.
- the processing unit When the second predetermined condition is satisfied, the processing unit generates a new second key derivation information according to the second method, and uses the new second key derivation information to create a new second key derivation information.
- An in-vehicle device that generates the key information of the above and uses the new second key information for encrypting a packet newly transmitted by the communication unit.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Health & Medical Sciences (AREA)
- Power Engineering (AREA)
- Small-Scale Networks (AREA)
- Traffic Control Systems (AREA)
Abstract
Description
この出願は、2020年10月22日に出願された日本出願特願2020-177070号を基礎とする優先権を主張し、その開示のすべてをここに取り込む。
非特許文献1の技術を超えて、車載ネットワークシステムの通信のセキュリティ、速度および安定性等を向上させることが可能な技術が望まれる。
本開示によれば、車載ネットワークにおいて、より良好な通信を提供することができる。
最初に、本開示の実施の形態の内容を列記して説明する。
図1は、本開示の実施の形態に係る車両管理システムの構成を示す図である。
車両管理システム1における各装置は、コンピュータを備え、当該コンピュータにおけるCPU等の演算処理部は、以下のシーケンス図またはフローチャートの各ステップの一部または全部を含むプログラムを図示しないメモリからそれぞれ読み出して実行する。これら複数の装置のプログラムは、それぞれ、外部からインストールすることができる。これら複数の装置のプログラムは、それぞれ、記録媒体に格納された状態で流通する。
車両に搭載される車載装置であって、
第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、
前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部とを備え、
前記処理部は、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化し、
前記処理部は、第2の所定条件を満たした場合、前記第2の方式に従い、新たな第2の鍵導出情報を生成し、前記新たな第2の鍵導出情報を用いて新たな第2の鍵情報を生成し、新たな第2の鍵情報を、前記通信部により新たに送信されるパケットの暗号化に用いる、車載装置。
10A 車両
10B 他の車両
11 サーバ
12 インフラ側装置
13 車載通信システム
131~134 車載装置
1321 通信部
1322 処理部
1323 記憶部
1324 タイマ
1325 暗号化部
1326 復号化部
1327 車両情報取得部
135 中継装置
14 車載通信システム(他の車両)
15 MEC
Claims (10)
- 車両に搭載される車載装置であって、
第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、
前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部とを備え、
前記処理部は、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化する、車載装置。 - 前記処理部は、前記第2の鍵導出情報を、前記第1の鍵情報を用いて暗号化し、
前記通信部は、前記処理部によって暗号化された前記第2の鍵導出情報を前記他の車両へ送信する、請求項1に記載の車載装置。 - 前記処理部は、前記第1の方式において、前記第1の鍵導出情報として秘密鍵および公開鍵のペアを生成し、前記ペアを用いて前記第1の鍵情報として共通鍵を生成し、
前記処理部は、前記第2の方式において、前記第2の鍵導出情報として第1の暗号学的ハッシュ関数を用いてハッシュ値を生成し、前記ハッシュ値から第2の暗号学的ハッシュ関数を用いて共通鍵を生成し、
前記通信部は、前記処理部によって生成された前記ハッシュ値を前記他の車両へ送信する、請求項1または請求項2に記載の車載装置。 - 前記処理部は、所定条件を満たした場合、前記第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を、前記通信部により新たに送信されるパケットの暗号化に用い、
前記所定条件は、経過時間または前記第1の鍵情報の使用を開始してからの前記他の車両との通信量に関する条件である、請求項1から請求項3のいずれか1項に記載の車載装置。 - 前記処理部は、所定条件を満たした場合、前記第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を、前記通信部により新たに送信されるパケットの暗号化に用い、
前記所定条件は、前記車両の走行状態に関する条件である、請求項1から請求項3のいずれか1項に記載の車載装置。 - 前記処理部は、前記第2の鍵情報を更新する、請求項1から請求項5のいずれか1項に記載の車載装置。
- 前記処理部は、前記第1の方式および前記第2の方式の少なくともいずれか一方において、時刻情報および乱数を鍵導出情報の生成に用いる、請求項1から請求項6のいずれか1項に記載の車載装置。
- 前記処理部は、前記第1の方式または前記第2の方式に従って、前記他の車両から受信した暗号化されたパケットを復号化し、
前記通信部は、復号化したパケットに格納されたデータをインフラ側装置へ送信する、請求項1から請求項7のいずれか1項に記載の車載装置。 - 車両に搭載される車載装置における暗号化通信方法であって、
第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化するステップと、
暗号化した前記パケットを他の車両へ送信するステップと、
前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、新たに送信するパケットを暗号化するステップとを含む、暗号化通信方法。 - 車両に搭載される車載装置に用いられる暗号化通信プログラムであって、
コンピュータを、
第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、
前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部として機能させるためのプログラムであり、
前記処理部は、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化する、暗号化通信プログラム。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2022556402A JP7574856B2 (ja) | 2020-10-22 | 2021-07-05 | 車載装置、暗号化通信方法および暗号化通信プログラム |
| US18/032,812 US20240007271A1 (en) | 2020-10-22 | 2021-07-05 | In-vehicle device, encrypted communication method, and encrypted communication program |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2020177070 | 2020-10-22 | ||
| JP2020-177070 | 2020-10-22 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022085243A1 true WO2022085243A1 (ja) | 2022-04-28 |
Family
ID=81290374
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2021/025351 Ceased WO2022085243A1 (ja) | 2020-10-22 | 2021-07-05 | 車載装置、暗号化通信方法および暗号化通信プログラム |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20240007271A1 (ja) |
| JP (1) | JP7574856B2 (ja) |
| WO (1) | WO2022085243A1 (ja) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12531840B2 (en) * | 2022-01-07 | 2026-01-20 | Samsung Electronics Co., Ltd. | Electronic apparatus for vehicle and method for storing vehicle information in electronic apparatus |
| US12452278B1 (en) * | 2024-04-03 | 2025-10-21 | Netscout Systems, Inc. | Systems and methods for selective decryption of encrypted data packets |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2003110540A (ja) * | 2001-10-01 | 2003-04-11 | Keio Gijuku | 暗号鍵更新方法 |
| JP2009064178A (ja) * | 2007-09-05 | 2009-03-26 | Hitachi Ltd | ストレージ装置及びデータの管理方法 |
| JP2011087249A (ja) * | 2009-10-19 | 2011-04-28 | Ricoh Co Ltd | 通信装置及び通信制御方法 |
| WO2012008158A1 (ja) * | 2010-07-13 | 2012-01-19 | 三洋電機株式会社 | 端末装置 |
| JP2020017805A (ja) * | 2018-07-23 | 2020-01-30 | Kddi株式会社 | 車両情報送信装置、車両情報受信装置、車両情報通信方法及びコンピュータプログラム |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US4200770A (en) * | 1977-09-06 | 1980-04-29 | Stanford University | Cryptographic apparatus and method |
| US10491404B1 (en) * | 2018-09-12 | 2019-11-26 | Hotpyp, Inc. | Systems and methods for cryptographic key generation and authentication |
| US11343084B2 (en) * | 2019-03-01 | 2022-05-24 | John A. Nix | Public key exchange with authenticated ECDHE and security against quantum computers |
-
2021
- 2021-07-05 US US18/032,812 patent/US20240007271A1/en active Pending
- 2021-07-05 WO PCT/JP2021/025351 patent/WO2022085243A1/ja not_active Ceased
- 2021-07-05 JP JP2022556402A patent/JP7574856B2/ja active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2003110540A (ja) * | 2001-10-01 | 2003-04-11 | Keio Gijuku | 暗号鍵更新方法 |
| JP2009064178A (ja) * | 2007-09-05 | 2009-03-26 | Hitachi Ltd | ストレージ装置及びデータの管理方法 |
| JP2011087249A (ja) * | 2009-10-19 | 2011-04-28 | Ricoh Co Ltd | 通信装置及び通信制御方法 |
| WO2012008158A1 (ja) * | 2010-07-13 | 2012-01-19 | 三洋電機株式会社 | 端末装置 |
| JP2020017805A (ja) * | 2018-07-23 | 2020-01-30 | Kddi株式会社 | 車両情報送信装置、車両情報受信装置、車両情報通信方法及びコンピュータプログラム |
Also Published As
| Publication number | Publication date |
|---|---|
| JPWO2022085243A1 (ja) | 2022-04-28 |
| US20240007271A1 (en) | 2024-01-04 |
| JP7574856B2 (ja) | 2024-10-29 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP4050474B1 (en) | Vehicle upgrade packet processing method and apparatus | |
| EP3337127B1 (en) | Legitimacy verification of a node in a distributed network using certificate white-listing | |
| US9135820B2 (en) | Communication system, vehicle-mounted terminal, roadside device | |
| JP6617173B2 (ja) | 複数のマネージャまたはアクセスポイントを有する無線ネットワークにおける独立したセキュリティ | |
| JP5435513B2 (ja) | 暗号通信システム、鍵配布装置、暗号通信方法 | |
| EP2981028B1 (en) | Transponder module and access module for activating and configuring such transponder module over a CAN bus | |
| JP5587239B2 (ja) | 車車/路車間通信システム | |
| AU2015295563B2 (en) | Transponder module and access module for activating and configuring such transponder module | |
| CN115885496B (zh) | 一种通信方法及相关装置 | |
| CN110858970B (zh) | 第一车辆侧的终端设备及其运行方法、第二车辆侧的终端设备及其运行方法 | |
| WO2021126554A1 (en) | Privacy-preserving delivery of activation codes for pseudonym certificates | |
| US11218309B2 (en) | Vehicle communication system and vehicle communication method | |
| JP7704192B2 (ja) | 車載中継装置、管理装置、車載システムおよび通信管理方法 | |
| JP7574856B2 (ja) | 車載装置、暗号化通信方法および暗号化通信プログラム | |
| JP7647974B2 (ja) | 中継装置、車両通信方法および車両通信プログラム | |
| JP2018121220A (ja) | 車載ネットワークシステム | |
| CN112400331A (zh) | 根据置信水平的车对外界通信装置和方法 | |
| JP2008060809A (ja) | 車車間通信方法、車車間通信システムおよび車載通信装置 | |
| KR102400940B1 (ko) | 자율 주행 차량의 통신 보안 장치 및 방법 | |
| CN112740726B (zh) | 一种数据传输方法及装置 | |
| WO2024154585A1 (ja) | 車載装置、情報処理方法及び、車載システム | |
| JP6681755B2 (ja) | 車両用通信網装置及び通信方法 | |
| CN119031341A (zh) | 纳入v2x通信伙伴的数据的方法和支持数据的纳入的方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21882386 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2022556402 Country of ref document: JP Kind code of ref document: A |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 18032812 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21882386 Country of ref document: EP Kind code of ref document: A1 |