WO2022085243A1 - 車載装置、暗号化通信方法および暗号化通信プログラム - Google Patents

車載装置、暗号化通信方法および暗号化通信プログラム Download PDF

Info

Publication number
WO2022085243A1
WO2022085243A1 PCT/JP2021/025351 JP2021025351W WO2022085243A1 WO 2022085243 A1 WO2022085243 A1 WO 2022085243A1 JP 2021025351 W JP2021025351 W JP 2021025351W WO 2022085243 A1 WO2022085243 A1 WO 2022085243A1
Authority
WO
WIPO (PCT)
Prior art keywords
key
vehicle
information
packet
processing unit
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2021/025351
Other languages
English (en)
French (fr)
Inventor
稲葉多津茂
畑洋一
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Sumitomo Electric Industries Ltd
Original Assignee
Sumitomo Electric Industries Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Sumitomo Electric Industries Ltd filed Critical Sumitomo Electric Industries Ltd
Priority to JP2022556402A priority Critical patent/JP7574856B2/ja
Priority to US18/032,812 priority patent/US20240007271A1/en
Publication of WO2022085243A1 publication Critical patent/WO2022085243A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/088Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0825Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
    • H04L9/3242Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving keyed hash functions, e.g. message authentication codes [MACs], CBC-MAC or HMAC
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/84Vehicles

Definitions

  • the present disclosure relates to in-vehicle devices, encrypted communication methods and encrypted communication programs.
  • This application claims priority on the basis of Japanese Application Japanese Patent Application No. 2020-177070 filed on October 22, 2020 and incorporates all of its disclosures herein.
  • Non-Patent Document 1 Korean Organic Chemical Networks, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan, Inc., Japan Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc., Inc
  • the in-vehicle device of the present disclosure is an in-vehicle device mounted on a vehicle, generates a first key derivation information according to the first method, and uses the first key derivation information to generate a first key information.
  • the processing unit includes a processing unit that is generated and encrypts a packet using the first key information, and a communication unit that transmits the packet encrypted by the processing unit to another vehicle.
  • the second key derivation information is generated according to the second method in which the key information generation time is shorter than that of the first method, and the second key information is generated.
  • the second key information is generated using the key derivation information, and the second key information is used instead of the first key information to encrypt a packet newly transmitted by the communication unit.
  • the encrypted communication method of the present disclosure is an encrypted communication method in an in-vehicle device mounted on a vehicle, in which the first key derivation information is generated according to the first method, and the first key derivation information is used.
  • a step of generating a first key information and encrypting a packet using the first key information a step of transmitting the encrypted packet to another vehicle, and a step of using the first key information.
  • the second key derivation information is generated according to the second method in which the key information generation time is shorter than that of the first method, and the second key derivation information is used. 2.
  • the key information is generated, and the second key information is used instead of the first key information to encrypt a newly transmitted packet.
  • the encrypted communication program of the present disclosure is an encrypted communication program used for an in-vehicle device mounted on a vehicle, and a computer generates a first key derivation information according to a first method, and the first key derivation information is generated.
  • a processing unit that generates the first key information using the key derivation information and encrypts the packet using the first key information, and transmits the packet encrypted by the processing unit to another vehicle. It is a program for functioning as a communication unit, and the processing unit uses the first key information to encrypt the packet, and then the second method has a shorter key information generation time than the first method. According to the method, the second key derivation information is generated, the second key information is generated by using the second key derivation information, and the second key information is used instead of the first key information. , The packet newly transmitted by the communication unit is encrypted.
  • One aspect of the present disclosure can be realized not only as an in-vehicle device provided with such a characteristic processing unit, but also as an in-vehicle communication system including the in-vehicle device. Further, one aspect of the present disclosure can be realized as a semiconductor integrated circuit that realizes a part or all of an in-vehicle device.
  • FIG. 1 is a diagram showing a configuration of a vehicle management system according to an embodiment of the present disclosure.
  • FIG. 2 is a diagram showing a configuration of an in-vehicle communication system according to an embodiment of the present disclosure.
  • FIG. 3 is a diagram showing a configuration of an in-vehicle device in the in-vehicle communication system according to the embodiment of the present disclosure.
  • FIG. 4 is a diagram showing a configuration of a processing unit in the in-vehicle device according to the embodiment of the present disclosure.
  • FIG. 5 is a diagram showing the first half of a sequence showing the processing of encrypted communication in the vehicle management system according to the embodiment of the present disclosure.
  • FIG. 6 is a diagram showing the latter half of the sequence showing the processing of encrypted communication in the vehicle management system according to the embodiment of the present disclosure.
  • the present disclosure has been made to solve the above-mentioned problems, and an object thereof is to provide an in-vehicle device, an encryption method and a program capable of providing better communication in an in-vehicle network. ..
  • the in-vehicle device is an in-vehicle device mounted on a vehicle, generates a first key derivation information according to the first method, and uses the first key derivation information.
  • a processing unit that uses the first key information to generate the first key information and encrypts the packet using the first key information, and a communication unit that transmits the packet encrypted by the processing unit to another vehicle.
  • the processing unit encrypts the packet using the first key information, and then follows the second method in which the key information generation time is shorter than that of the first method, and the second key derivation information is provided. Is generated, the second key information is generated using the second key derivation information, and the second key information is used instead of the first key information, and is newly transmitted by the communication unit. Encrypt the packet.
  • the key information is generated in the vehicle and used for packet encryption, so that it is not necessary to use and manage the unique key stored in advance in each vehicle for a long period of time. Further, for example, by first using an encryption method having a certain degree of security and then switching to an encryption method having a short generation time, encrypted communication can be effectively performed according to the characteristics of each method. Therefore, better communication can be provided in the in-vehicle network.
  • the processing unit encrypts the second key derivation information using the first key information
  • the communication unit encrypts the second key derivation information encrypted by the processing unit. It may be transmitted to the other vehicle.
  • the second key derivation information can be transmitted to another vehicle by using the first method having high security, and the generation time is short while ensuring security by simple processing. Encrypted communication using the second method can be started.
  • the processing unit In the first method, the processing unit generates a pair of a private key and a public key as the first key derivation information, and generates a common key as the first key information using the pair. Then, in the second method, the processing unit generates a hash value by using the first cryptographic hash function as the second key derivation information, and the second cryptographic hash is generated from the hash value.
  • a common key may be generated using a function, and the communication unit may transmit the hash value generated by the processing unit to the other vehicle.
  • a common key using a cryptographic hash function can be generated faster than a pair of private key and public key. Therefore, the data can be encrypted in a short time, and more encrypted packets can be exchanged in the vehicle-to-vehicle communication.
  • the processing unit When the predetermined condition is satisfied, the processing unit generates the second key information, and the second key information is newly transmitted by the communication unit in place of the first key information.
  • the predetermined condition may be used for encryption of the packet, and is a condition relating to the elapsed time or the amount of communication with the other vehicle after the use of the first key information is started.
  • the processing unit When the predetermined condition is satisfied, the processing unit generates the second key information, and the second key information is newly transmitted by the communication unit in place of the first key information.
  • the predetermined condition used for encrypting the packet may be a condition relating to the traveling state of the vehicle.
  • the encrypted communication using the first key information is encrypted using the second key information. Switching to communication can be performed at an appropriate timing.
  • the processing unit may update the second key information.
  • the subsequent encrypted communication can use the updated second key information, so that the encryption is performed.
  • the possibility that the communication will be decrypted can be reduced.
  • the security of the encrypted communication can be further enhanced.
  • the second key information when the second key information is generated when the predetermined condition is satisfied, the second key information can be updated at an appropriate timing according to the predetermined condition.
  • the processing unit may use the time information and the random number to generate the key derivation information in at least one of the first method and the second method.
  • the key derivation information can be changed with the passage of time. Further, if the key derivation information is generated using only the time information, the time information may be estimated and the key derivation information may be deciphered. However, by using a random number in addition to the time information, it is possible to prevent the key derivation information from being deciphered even if the time information is estimated. Therefore, the security of encrypted communication can be further enhanced.
  • the processing unit decodes the encrypted packet received from the other vehicle according to the first method or the second method, and the communication unit is stored in the decrypted packet. Data may be transmitted to the infrastructure side device.
  • the vehicle data is uploaded to the infrastructure side device. be able to. Then, on the infrastructure side, the vehicle data can be analyzed in detail, and even if a problem occurs in the vehicle, it can be appropriately dealt with.
  • the encrypted communication method is an encrypted communication method in an in-vehicle device mounted on a vehicle, in which the first key derivation information is generated according to the first method and described above.
  • the second key derivation information is generated according to the second method in which the key information generation time is shorter than that of the first method.
  • the second key information is generated by using the key derivation information of the above, and the second key information is used instead of the first key information to encrypt a newly transmitted packet.
  • the key information is generated in the vehicle and used for packet encryption, so that it is not necessary to use and manage the unique key stored in advance in each vehicle for a long period of time. Further, for example, by first using an encryption method having a certain degree of security and then switching to an encryption method having a short generation time, encrypted communication can be effectively performed according to the characteristics of each method. Therefore, better communication can be provided in the in-vehicle network.
  • the encrypted communication program according to the embodiment of the present disclosure is an encrypted communication program used for an in-vehicle device mounted on a vehicle, and a computer is subjected to a first key derivation information according to a first method.
  • the second key derivation information is generated according to the second method having a short generation time, and the second key information is generated by using the second key derivation information.
  • the second key information is used to encrypt a packet newly transmitted by the communication unit.
  • the key information is generated in the vehicle and used for packet encryption, so that it is not necessary to use and manage the unique key stored in advance in each vehicle for a long period of time. Further, for example, by first using an encryption method having a certain degree of security and then switching to an encryption method having a short generation time, encrypted communication can be effectively performed according to the characteristics of each method. Therefore, better communication can be provided in the in-vehicle network.
  • FIG. 1 is a diagram showing a configuration of a vehicle management system according to an embodiment of the present disclosure.
  • the vehicle management system 1 includes a server 11, an infrastructure side device 12, an in-vehicle communication system 13 mounted on the vehicle 10A, and an in-vehicle communication system 14 mounted on another vehicle 10B. It is equipped with MEC (Mobile Edge Computing) 15 of the above.
  • MEC Mobile Edge Computing
  • the vehicle management system 1 makes it possible to exchange various data between the vehicles 10A and 10B and the server 11.
  • the vehicle management system 1 makes it possible to upload camera images, moving images, and the like taken in the vehicles 10A and 10B to the server 11.
  • the vehicle management system 1 makes it possible to transmit update programs of various software mounted on the vehicles 10A and 10B from the server 11 to the vehicles 10A and 10B.
  • the vehicle 10A uploads log information including logs of various software in the vehicle 10A to the server 11 via the vehicle 10B.
  • Vehicle 10A transmits log information to vehicle 10B.
  • the vehicle 10B transmits the log information received from the vehicle 10A to the infrastructure side device 12 which is close to the vehicle 10B or has a good communication environment with the vehicle 10B.
  • the infrastructure side device 12 is, for example, a radio base station device.
  • the infrastructure side device 12 transmits the log information received from the vehicle 10B to the MEC 15.
  • the infrastructure side device 12 may be a beacon. Further, the infrastructure side device 12 may include the MEC 15.
  • the MEC15 analyzes the log information received from the infrastructure side device 12, shares the log information with other MEC15s, and complements the log information with each other.
  • the MEC15 acquires emergency information such as accident information from log information, for example, the MEC15 issues an alarm to the vehicles 10A and 10B.
  • the MEC 15 may issue an alarm directly to the vehicles 10A and 10B, may issue an alarm to the vehicle 10A via the vehicle 10B, or may issue an alarm to the vehicle 10B via the vehicle 10A. Further, the MEC 15 transmits the log information to the server 11.
  • the server 11 analyzes the log information received from the MEC 15 in more detail and takes necessary measures.
  • FIG. 2 is a diagram showing a configuration of an in-vehicle communication system according to an embodiment of the present disclosure.
  • FIG. 2 shows the configuration of the vehicle-mounted communication system 13 in the vehicle 10A as an example, but the configuration of the vehicle-mounted communication system 14 in the other vehicle 10B is also the same.
  • the vehicle-mounted communication system 13 includes vehicle-mounted devices 131 to 134 and a relay device 135.
  • the in-vehicle communication system 13 is not limited to the configuration including four in-vehicle devices 131 to 134, but may be configured to include three or less or five or more in-vehicle devices. Further, the in-vehicle communication system 13 is not limited to the configuration including one relay device 135, and may be configured to include two or more relay devices.
  • the in-vehicle device 131 is, for example, a TCU (Telematics Communication Unit).
  • TCU Transmission Control Unit
  • the in-vehicle device 131 is also referred to as a TCU 131.
  • the in-vehicle devices 133 and 134 are, for example, an automatic operation ECU (Electronic Control Unit), a sensor, a navigation device, a human-machine interface, a camera, and the like.
  • ECU Electronic Control Unit
  • the in-vehicle device 132 will be described later.
  • the in-vehicle devices 131 to 134 are connected to the relay device 135 via an Ethernet (registered trademark) cable.
  • the relay device 135 is, for example, a switch device.
  • the relay device 135 may be a gateway device.
  • the relay device 135 relays the Ethernet frame according to the Ethernet communication standard.
  • the relay device 135 relays, for example, an Ethernet frame exchanged between the in-vehicle devices 131 to 134. IP packets are stored in the Ethernet frame.
  • the in-vehicle communication system 13 is not limited to a configuration in which an Ethernet frame is relayed according to an Ethernet communication standard, for example, CAN (Control Area Protocol) (registered trademark), FlexRay (registered trademark), MOST (Media Oriented Systems Transport). ) (Registered trademark) and LIN (Local Ethernet Protocol) and other communication standards may be used to relay data.
  • CAN Control Area Protocol
  • FlexRay registered trademark
  • MOST Media Oriented Systems Transport
  • LIN Local Ethernet Protocol
  • the TCU 131 can communicate with the infrastructure side device 12. Specifically, the TCU 131 can communicate with the server 11 via the infrastructure side device 12, for example, according to the IP protocol.
  • the TCU 131 can perform wireless communication with the infrastructure side device 12 according to a communication standard such as LTE (Long Term Evolution) or 5G.
  • LTE Long Term Evolution
  • 5G 5th Generation
  • the TCU 131 when the TCU 131 receives a wireless frame containing an IP packet from an IP server from the infrastructure side device 12, it acquires an IP packet from the received wireless frame and converts the acquired IP packet into an Ethernet frame. It is stored and transmitted to the relay device 135.
  • the TCU 131 when the TCU 131 receives an Ethernet frame from the relay device 135, it acquires an IP packet from the received Ethernet frame, stores the acquired IP packet in a wireless frame, and transmits the acquired IP packet to the infrastructure side device 12.
  • the TCU 131 can wirelessly communicate with the TCU in another vehicle 10B by short-range wireless communication or the like.
  • FIG. 3 is a diagram showing a configuration of an in-vehicle device in the in-vehicle communication system according to the embodiment of the present disclosure.
  • FIG. 3 shows, as an example, the configuration of the in-vehicle device 132 in the vehicle 10A.
  • the in-vehicle device 132 includes a communication unit 1321, a processing unit 1322, and a storage unit 1323.
  • the communication unit 1321 is realized by, for example, a communication circuit such as a communication IC (Integrated Circuit).
  • the processing unit 1322 is realized by, for example, a processor such as a CPU or a DSP (Digital Signal Processing).
  • the storage unit 1323 is, for example, a non-volatile memory.
  • the communication unit 1321 exchanges data with the vehicle 10B and the infrastructure side device 12 via the TCU 131. Further, the communication unit 1321 exchanges data with other in-vehicle devices 131, 133, 134 via the relay device 135.
  • the processing unit 1322 divides the data into a plurality of IP packets and stores them, and performs processing such as encryption and decryption of the data portion of each IP packet.
  • FIG. 4 is a diagram showing a configuration of a processing unit in the in-vehicle device according to the embodiment of the present disclosure.
  • FIG. 4 shows, as an example, the configuration of the processing unit 1322 in the vehicle 10A.
  • the processing unit 1322 includes a timer 1324, an encryption unit 1325, a decryption unit 1326, and a vehicle information acquisition unit 1327.
  • the timer 1324 periodically stores the time information indicating the current time in the storage unit 1323.
  • the vehicle information acquisition unit 1327 acquires information indicating a traveling state such as the speed of the vehicle 10A from another in-vehicle device via the relay device 135 and the communication unit 1321 and outputs the information to the encryption unit 1325.
  • the encryption unit 1325 receives information indicating a traveling state from the vehicle information acquisition unit 1327, and when the information satisfies a predetermined condition as described later, the encryption unit 1325 acquires time information from the storage unit 1323, and obtains the time information and a random number. Encrypt IP packets using.
  • the decryption unit 1326 when the decryption unit 1326 receives an encrypted IP packet from another vehicle 10B via the TCU 131, the relay device 135, and the communication unit 1321, the decryption unit 1326 decodes the IP packet.
  • Each device in the vehicle management system 1 includes a computer, and an arithmetic processing unit such as a CPU in the computer reads a program including a part or all of each step of the following sequence diagram or flowchart from a memory (not shown) and executes the program. do.
  • the programs of these plurality of devices can be installed from the outside.
  • the programs of these plurality of devices are distributed in a state of being stored in a recording medium.
  • FIG. 5 is a diagram showing the first half of a sequence showing the processing of encrypted communication in the vehicle management system according to the embodiment of the present disclosure.
  • the infrastructure side device 12 periodically transmits time information to the vehicle 10A and another vehicle 10B (step S101).
  • the vehicle 10A and the other vehicle 10B receive the time information from the infrastructure side device 12 and synchronize the time.
  • time synchronization for example, NTP (Network Time Protocol) is used (step S102).
  • NTP Network Time Protocol
  • the vehicle 10A and the other vehicle 10B periodically broadcast a communicable notification indicating that the vehicle has entered the communicable range of its own vehicle. Then, when the other vehicle 10B enters the communicable range, the processing unit 1322 in the vehicle 10A receives a communicable notification from the other vehicle 10B via the TCU 131, the relay device 135, and the communication unit 1321 (step S103). ..
  • the processing unit 1322 When the processing unit 1322 receives the communicable notification from the other vehicle 10B for the first time, the processing unit 1322 generates the first key derivation information according to the first method, and generates the first key information using the first key derivation information. do.
  • the first method is, for example, an encryption method that combines an encryption method using a private key and a public key and an encryption method using a common key.
  • the processing unit 1322 generates a pair of a private key and a public key as the first key derivation information by using the time information and the random number stored in the storage unit 1323. ..
  • the processing unit 1322 stores the generated private key and public key pair in the storage unit 1323 (steps S104 and S105).
  • the processing unit 1322 generates an electronic certificate for the generated public key and stores it in the storage unit 1323 (step S106).
  • the processing unit 1322 in the other vehicle 10B also generates a pair of a private key and a public key as the first key derivation information by using the time information and the random number in the first method. do.
  • the processing unit 1322 generates an electronic certificate for the generated public key and stores it in the storage unit 1323 (steps S107 to S109).
  • the processing unit 1322 in the vehicle 10A transmits the public key and the digital certificate stored in the storage unit 1323 to the other vehicle 10B via the communication unit 1321 and the TCU 131 together with the key exchange request (step S110). ..
  • the processing unit 1322 verifies the electronic certificate (step S111). ..
  • step S112 when the processing unit 1322 confirms that the received public key is generated in the vehicle 10A, the generated public key and the electronic certificate are sent to the communication unit 1321 together with the key exchange response. And transmission to the vehicle 10A via the TCU 131 (step S112).
  • step S113 when the processing unit 1322 in the vehicle 10A receives the public key, the electronic certificate, and the key exchange response from the other vehicle 10B via the TCU 131 and the communication unit 1321, the electronic certificate is verified (step S113).
  • Step S114 when the processing unit 1322 in the vehicle 10A confirms that the received public key is generated in the other vehicle 10B, the key exchange result notification to that effect is notified via the communication unit 1321 and the TCU 131.
  • the processing unit 1322 generates a common key K1 as the first key information using the generated private key and the public key received from the other vehicle 10B (step S115).
  • the processing unit 1322 receives the key exchange result notification from the vehicle 10A via the TCU 131 and the communication unit 1321, the secret key and the vehicle generated in the other vehicle 10B are received.
  • a common key K1 is generated using the public key received from 10A (step S116).
  • the processing unit 1322 in the other vehicle 10B when the processing unit 1322 in the other vehicle 10B generates the common key K1, the processing unit 1322 transmits a common key confirmation request encrypted using the common key K1 to the vehicle 10A via the communication unit 1321 and the TCU 131 (step S117). ).
  • the processing unit 1322 when the processing unit 1322 receives the common key confirmation request via the TCU 131 and the communication unit 1321, the received common key confirmation request is decoded using the common key K1 and the common key confirmation response is communicated. It is transmitted to another vehicle 10B via the unit 1321 and the TCU 131 (step S118).
  • the processing unit 1322 encrypts the IP packet storing the data by using the common key K1 which is the first key information. More specifically, the processing unit 1322 divides and stores the log information of various software installed in the in-vehicle devices 131, 133, and 134 into a plurality of IP packets, for example. Then, the processing unit 1322 encrypts the data portion of the IP packet using the common key K1 and outputs the IP packet to the communication unit 1321 (step S119).
  • the communication unit 1321 in the vehicle 10A receives the encrypted IP packet from the processing unit 1322 and transmits the IP packet to the other vehicle 10B via the TCU 131 (step S120).
  • the processing unit 1322 when the processing unit 1322 receives the encrypted IP packet from the vehicle 10A via the TCU 131 and the communication unit 1321, the data portion of the IP packet is decoded using the common key K1. do.
  • the processing unit 1322 transmits an IP packet containing a part of the log information acquired by decryption to the infrastructure side device 12 via the communication unit 1321 and the TCU 131.
  • the processing unit 1322 encrypts a part of the log information and transmits it to the infrastructure side device 12.
  • the encryption method at this time is not particularly limited, and a well-known encryption method may be used (step S121).
  • FIG. 6 is a diagram showing the latter half of the sequence showing the processing of encrypted communication in the vehicle management system according to the embodiment of the present disclosure.
  • the processing unit 1322 in the vehicle 10A encrypts the IP packet using the first key information and then satisfies the first predetermined condition
  • the key information of the key information is higher than that of the first method.
  • the second key derivation information is generated according to the second method having a short generation time, and the second key information is generated by using the second key derivation information.
  • the processing unit 1322 uses the second key information instead of the first key information to encrypt the IP packet newly transmitted by the communication unit 1321 containing a part of the log information.
  • the first predetermined condition is, for example, a condition relating to the elapsed time or the amount of communication with another vehicle 10B since the start of using the first key information. More specifically, the condition regarding the elapsed time is, for example, the case where the duration of the encrypted communication using the common key K1 is a predetermined time or longer. The condition regarding the communication amount is, for example, the case where the communication amount of the encrypted communication using the common key K1 becomes a predetermined amount or more.
  • the first predetermined condition is not limited to the above condition, and may be, for example, a condition relating to the traveling state of the vehicle 10A. More specifically, it is a case where the difference in speed or acceleration between the vehicle 10A and the other vehicle 10B is equal to or larger than a predetermined value.
  • the second method is, for example, an encryption method using a cryptographic hash function.
  • the processing unit 1322 uses the time information and the random number stored in the storage unit 1323 to obtain the hash value by using the first cryptographic hash function. It is generated as key derivation information, and the common key K2, which is the second key information, is generated from the generated hash value by using the second cryptographic hash function (steps S122 to S124).
  • the processing unit 1322 encrypts the hash value, which is the second key derivation information, using the common key K1 which is the first key information (step S125).
  • the processing unit 1322 transmits the encrypted second key derivation information together with the key update request to the other vehicle 10B via the communication unit 1321, the relay device 135, and the TCU 131 (step S126).
  • the processing unit 1322 in the other vehicle 10B receives the key update request and the encrypted second key derivation information hash value from the vehicle 10A via the TCU 131, the relay device 135, and the communication unit 1321, the processing unit 1322 receives the hash value.
  • the hash value is decrypted using the common key K1 which is the first key information (step S127).
  • the processing unit 1322 in the other vehicle 10B generates a common key K2 from the hash value which is the decrypted second key derivation information by using the second cryptographic hash function (step S128).
  • the processing unit 1322 in the vehicle 10A sends a common key confirmation request to the communication unit 1321, the relay device 135, and the TCU 131 after a predetermined time has elapsed after transmitting the encrypted second key derivation information to the other vehicle 10B. It is transmitted to another vehicle 10B via (step S129).
  • the processing unit 1322 in the other vehicle 10B receives the common key confirmation request from the vehicle 10A via, for example, the TCU 131, the relay device 135, and the communication unit 1321, and the generation of the common key K2 is completed.
  • the key information used for encrypting the IP packet is switched from the common key K1 to the common key K2.
  • the processing unit 1322 transmits the common key confirmation response to the vehicle 10A via the communication unit 1321, the relay device 135, and the TCU 131, and discards the common key K1 which is the first key information (steps S130 and S131).
  • the processing unit 1322 in the vehicle 10A receives the common key confirmation response from the other vehicle 10B via the TCU 131 and the communication unit 1321, the key information used for encrypting the IP packet is transferred from the common key K1 to the common key K2. Switch. Then, the processing unit 1322 discards the common key K1 which is the first key information (step S132).
  • the processing unit 1322 in the vehicle 10A is, for example, an IP packet that stores a part of the log information divided in step S119 of FIG. 5, and is data of an IP packet that has not yet been transmitted to another vehicle 10B.
  • the portion is encrypted using the common key K2, and the IP packet is output to the communication unit 1321 (step S133).
  • the communication unit 1321 in the vehicle 10A receives the encrypted IP packet from the processing unit 1322 and transmits the IP packet to the other vehicle 10B via the TCU 131 (step S134).
  • the processing unit 1322 when the processing unit 1322 receives the encrypted IP packet from the vehicle 10A via the TCU 131 and the communication unit 1321, the packet reception response is sent to the vehicle 10A via the communication unit 1321 and the TCU 131.
  • the data portion of the IP packet is decoded using the common key K2 (steps S135 and S136).
  • the processing unit 1322 in the other vehicle 10B transmits a part of the log information acquired by decoding to the infrastructure side device 12 via the communication unit 1321 and the TCU 131.
  • the processing unit 1322 encrypts the IP packet storing a part of the log information and transmits it to the infrastructure side device 12.
  • the encryption method at this time is not particularly limited, and a well-known encryption method may be used (step S137).
  • the processing unit 1322 in the vehicle 10A when the second predetermined condition is satisfied, the processing unit 1322 in the vehicle 10A generates new second key derivation information according to the second method, and uses the new second key derivation information. Generate new second key information. Then, the processing unit 1322 uses the new second key information to encrypt the IP packet newly transmitted by the communication unit 1321 that stores a part of the log information. More specifically, the processing unit 1322 uses, for example, a new cryptographic hash function as the second key derivation information using the time information and the random number when a predetermined time elapses from the start of the encrypted communication using the common key K2. Is generated, a new common key K2 is generated using the generated cryptographic hash function, and encrypted communication with another vehicle 10B using the common key K2 is started.
  • the processing unit 1322 discards the old common key K2 after starting the encrypted communication using the new common key K2. In this way, when the second predetermined condition is satisfied, by updating the common key K2, security can be ensured even when the log information increases due to a change in the state of the vehicle 10A, for example. ..
  • the second predetermined condition is not limited to the predetermined elapsed time from the start of the encrypted communication using the common key K2, and may be a condition related to the traveling state of the vehicle 10A.
  • the processing unit 1322 performs encrypted communication while sequentially updating the second key information in the second method.
  • the processing unit 1322 in the vehicle 10A transmits an IP packet encrypted using the common key, which is the second key information, to the other vehicle 10B, and then a packet reception response from the other vehicle 10B arrives within a predetermined time. If not, the common key, which is the second key information, the private key and public key pair, which is the first key derivation information, and the electronic certificate of the public key are destroyed, and encrypted communication with another vehicle 10B is performed. It ends (step S138).
  • the vehicle 10A may transmit software log information in another vehicle 10B to the infrastructure side device 12. More specifically, in the other vehicle 10B, when the processing unit 1322 receives the encrypted IP packet from the vehicle 10A via the TCU 131 and the communication unit 1321, it is installed in each in-vehicle device in the other vehicle 10B.
  • An IP packet containing a part of log information of various software may be encrypted by using the common key K1 or K2 and transmitted to the vehicle 10A together with a packet reception response via the communication unit 1321 and the TCU 131.
  • the processing unit 1322 in the vehicle 10A decodes the IP packet received via the TCU 131 and the communication unit 1321 using the common key K1 or K2, and a part of the log information of the other vehicle 10B acquired by the decoding.
  • the IP packet containing the above is transmitted to the infrastructure side device 12.
  • the vehicle 10A and the other vehicle 10B use the common key K1 if the first predetermined condition is not satisfied within a predetermined time during encrypted communication using the common key K1 which is the first key information.
  • the encrypted communication that was used is terminated. More specifically, if a predetermined time has elapsed since the vehicle 10A and the other vehicle 10B started using the common key K1 and the first predetermined condition is not satisfied, the vehicle 10A and the other vehicle 10B are common.
  • the key K1 is destroyed and the encrypted communication is terminated.
  • the vehicle 10A and the other vehicle 10B perform encrypted communication using the common key K1 regardless of the passage of time, for example, when one of the vehicles has finished running, or when the ignition or power is turned off. You may finish.
  • the key information used for encrypting the IP packet is transmitted from the common key K1 to the common key K2. It is not limited to the configuration to switch to.
  • the other vehicle 10B may switch the key information used for encrypting the IP packet from the common key K1 to the common key K2, for example, when an Ethernet frame containing a specific content such as a flag is received from the vehicle 10A. .. In this case, for example, when the vehicle 10A transmits an Ethernet frame containing the above specific content, the vehicle 10A switches the key information used for encrypting the IP packet from the common key K1 to the common key K2.
  • data such as log information of various software of the vehicle is stored in, for example, an EDR (Event Data Recorder) mounted on the vehicle.
  • EDR Event Data Recorder
  • the log information that can be stored in the EDR is limited. Therefore, in order to collect more data, it is conceivable to upload vehicle log information to the server at any time. In this case, since data is exchanged between the vehicle and the server using wireless communication, it is necessary to encrypt the data.
  • the common keys K1 and K2 are generated in the vehicle and used for encrypting the IP packet storing the data. ..
  • the common keys K1 and K2 are destroyed when a predetermined time elapses and the wireless connection is disconnected. After that, when the IP packet is uploaded to the server 11 again, a new common key is generated and used for encryption of the IP packet. In this way, by generating the common keys K1 and K2 used for encrypting IP packets in the vehicle and using a timed expression that is used only for a specific period, the unique key stored in advance in each vehicle can be used for a long period of time.
  • the subsequent encrypted communication is a common key different from the common keys K1 and K2. Is used. Therefore, it is possible to reduce the possibility that the subsequent encrypted communication will be decrypted again by the method of decrypting the previous encrypted communication. Therefore, better communication can be provided in the in-vehicle network.
  • the vehicle 10A communicates with the infrastructure side device 12 using a standard such as LTE or 5G
  • the communication becomes unstable depending on the position of the vehicle 10A or the communication environment, and it is difficult to upload data to the server 11. May become.
  • the vehicle 10A uploads data to the server 11 via the other vehicle 10B and the infrastructure side device 12. .. Therefore, even if the communication between the vehicle 10A and the infrastructure side device 12 is unstable or impossible, if the other vehicle 10B can communicate with the infrastructure side device 12, the log information of the vehicle 10A should be uploaded to the server 11. Can be done. Therefore, better communication can be provided in the in-vehicle network.
  • the vehicles 10A and 10B first use the first method, the pair of the private key and the public key.
  • the common key K1 is generated by using it, and then the common key K2 using the cryptographic hash function, which is the second method, is generated and used for encryption.
  • the common key K2 using the cryptographic hash function can be generated faster than the private key and public key pair. Therefore, the IP packet can be encrypted in a short time, and more encrypted IP packets can be exchanged in the vehicle-to-vehicle communication. Therefore, better communication can be provided in the in-vehicle network.
  • Appendix 1 It is an in-vehicle device mounted on a vehicle.
  • Department and A communication unit that transmits the packet encrypted by the processing unit to another vehicle is provided.
  • the processing unit generates the second key derivation information according to the second method in which the key information generation time is shorter than that of the first method, and the second key information is used by using the second key derivation information. Is generated, and the second key information is used instead of the first key information to encrypt the packet newly transmitted by the communication unit.
  • the processing unit When the second predetermined condition is satisfied, the processing unit generates a new second key derivation information according to the second method, and uses the new second key derivation information to create a new second key derivation information.
  • An in-vehicle device that generates the key information of the above and uses the new second key information for encrypting a packet newly transmitted by the communication unit.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • Power Engineering (AREA)
  • Small-Scale Networks (AREA)
  • Traffic Control Systems (AREA)

Abstract

車載装置は、車両に搭載される車載装置であって、第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部とを備え、前記処理部は、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化する。

Description

車載装置、暗号化通信方法および暗号化通信プログラム
 本開示は、車載装置、暗号化通信方法および暗号化通信プログラムに関する。
 この出願は、2020年10月22日に出願された日本出願特願2020-177070号を基礎とする優先権を主張し、その開示のすべてをここに取り込む。
 非特許文献1(竹森敬祐著 「コネクティッドカーのセキュリティ」国際交通安全学会誌 Vol.42 No.2 2017年)には、以下のような車載ネットワークシステムが開示されている。すなわち、車両の走行ログをサーバへアップロードする際等に、鍵を用いて通信データを暗号化する車載ネットワークシステムが開示されている。
竹森敬祐著 「コネクティッドカーのセキュリティ」国際交通安全学会誌 Vol.42 No.2 2017年
 本開示の車載装置は、車両に搭載される車載装置であって、第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部とを備え、前記処理部は、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化する。
 本開示の暗号化通信方法は、車両に搭載される車載装置における暗号化通信方法であって、第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化するステップと、暗号化した前記パケットを他の車両へ送信するステップと、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、新たに送信するパケットを暗号化するステップとを含む。
 本開示の暗号化通信プログラムは、車両に搭載される車載装置に用いられる暗号化通信プログラムであって、コンピュータを、第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部として機能させるためのプログラムであり、前記処理部は、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化する。
 本開示の一態様は、このような特徴的な処理部を備える車載装置として実現することができるだけでなく、車載装置を備える車載通信システムとして実現され得る。また、本開示の一態様は、車載装置の一部または全部を実現する半導体集積回路として実現され得る。
図1は、本開示の実施の形態に係る車両管理システムの構成を示す図である。 図2は、本開示の実施の形態に係る車載通信システムの構成を示す図である。 図3は、本開示の実施の形態に係る車載通信システムにおける車載装置の構成を示す図である。 図4は、本開示の実施の形態に係る車載装置における処理部の構成を示す図である。 図5は、本開示の実施の形態に係る車両管理システムにおける暗号化通信の処理を示すシーケンスの前半を示す図である。 図6は、本開示の実施の形態に係る車両管理システムにおける暗号化通信の処理を示すシーケンスの後半を示す図である。
 従来、インターネットに接続可能なコネクティッドカーにおける車載ネットワークシステムのセキュリティについて開発がされている。
 [本開示が解決しようとする課題]
 非特許文献1の技術を超えて、車載ネットワークシステムの通信のセキュリティ、速度および安定性等を向上させることが可能な技術が望まれる。
 本開示は、上述の課題を解決するためになされたもので、その目的は、車載ネットワークにおいて、より良好な通信を提供することが可能な車載装置、暗号化方法およびプログラムを提供することである。
 [本開示の効果]
 本開示によれば、車載ネットワークにおいて、より良好な通信を提供することができる。
 [本開示の実施形態の説明]
 最初に、本開示の実施の形態の内容を列記して説明する。
 (1)本開示の実施の形態に係る車載装置は、車両に搭載される車載装置であって、第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部とを備え、前記処理部は、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化する。
 このように、車両において鍵情報を生成し、パケットの暗号化に用いる構成により、個々の車両において事前に格納した固有の鍵を長期間使用および管理する必要がない。また、たとえば最初にある程度セキュリティの高い暗号化方式を用いた上で、生成時間の短い暗号化方式へ切り替えることにより、各方式の特徴に応じて暗号化通信を効果的に行うことができる。したがって、車載ネットワークにおいて、より良好な通信を提供することができる。
 (2)前記処理部は、前記第2の鍵導出情報を、前記第1の鍵情報を用いて暗号化し、前記通信部は、前記処理部によって暗号化された前記第2の鍵導出情報を前記他の車両へ送信してもよい。
 このような構成により、たとえば、セキュリティの高い第1の方式を用いて第2の鍵導出情報を他の車両へ送信することができ、簡易な処理で、セキュリティを確保した上で生成時間の短い第2の方式を用いた暗号化通信を開始することができる。
 (3)前記処理部は、前記第1の方式において、前記第1の鍵導出情報として秘密鍵および公開鍵のペアを生成し、前記ペアを用いて前記第1の鍵情報として共通鍵を生成し、前記処理部は、前記第2の方式において、前記第2の鍵導出情報として第1の暗号学的ハッシュ関数を用いてハッシュ値を生成し、前記ハッシュ値から第2の暗号学的ハッシュ関数を用いて共通鍵を生成し、前記通信部は、前記処理部によって生成された前記ハッシュ値を前記他の車両へ送信してもよい。
 暗号学的ハッシュ関数を用いた共通鍵は、秘密鍵および公開鍵のペアよりも速く生成することができる。そのため、短時間でデータを暗号化することができ、車車間通信において、より多くの暗号化されたパケットをやり取りすることができる。
 (4)前記処理部は、所定条件を満たした場合、前記第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を、前記通信部により新たに送信されるパケットの暗号化に用いてもよく、前記所定条件は、経過時間または前記第1の鍵情報の使用を開始してからの前記他の車両との通信量に関する条件である。
 このような構成により、第1の鍵情報を用いた暗号化通信から第2の鍵情報を用いた暗号化通信への切り替えを適切なタイミングで行うことができる。
 (5)前記処理部は、所定条件を満たした場合、前記第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を、前記通信部により新たに送信されるパケットの暗号化に用い、前記所定条件は、前記車両の走行状態に関する条件であってもよい。
 このような構成により、たとえば、車両と他の車両との速度差、すなわち車間距離の変化等に応じて、第1の鍵情報を用いた暗号化通信から第2の鍵情報を用いた暗号化通信への切り替えを適切なタイミングで行うことができる。
 (6)前記処理部は、前記第2の鍵情報を更新してもよい。
 このような構成により、第2の鍵情報を用いた暗号化通信が傍受され、解読されたとしても、その後の暗号化通信は更新された第2の鍵情報を用いることができるため、暗号化通信が解読される可能性を低減することができる。また、生成時間の短い第2の鍵情報の更新を繰り返し行うことで、暗号化通信のセキュリティをより高めることができる。さらに、所定条件を満たした場合に第2の鍵情報を生成する場合、所定条件に従う適切なタイミングで第2の鍵情報を更新することができる。
 (7)前記処理部は、前記第1の方式および前記第2の方式の少なくともいずれか一方において、時刻情報および乱数を鍵導出情報の生成に用いてもよい。
 このように、時刻情報を用いることで、時間の経過とともに鍵導出情報を変えることができる。また、単に時刻情報のみを用いて鍵導出情報を生成すると、時刻情報を推定され、鍵導出情報が解読される可能性がある。しかしながら、時刻情報に加えて乱数を用いることで、時刻情報を推定されたとしても鍵導出情報が解読されることを抑制できる。したがって、暗号化通信のセキュリティをより高めることができる。
 (8)前記処理部は、前記第1の方式または前記第2の方式に従って、前記他の車両から受信した暗号化されたパケットを復号化し、前記通信部は、復号化したパケットに格納されたデータをインフラ側装置へ送信してもよい。
 このような構成により、たとえば、車両とインフラ側装置との通信が不安定または不能であっても、他の車両がインフラ側装置と通信可能であれば、車両のデータをインフラ側装置へアップロードすることができる。そして、インフラ側において、車両のデータを詳細に解析することができ、車両において不具合等が発生したとしても適切に対応することができる。
 (9)本開示の実施の形態に係る暗号化通信方法は、車両に搭載される車載装置における暗号化通信方法であって、第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化するステップと、暗号化した前記パケットを他の車両へ送信するステップと、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、新たに送信するパケットを暗号化するステップとを含む。
 このように、車両において鍵情報を生成し、パケットの暗号化に用いる構成により、個々の車両において事前に格納した固有の鍵を長期間使用および管理する必要がない。また、たとえば最初にある程度セキュリティの高い暗号化方式を用いた上で、生成時間の短い暗号化方式へ切り替えることにより、各方式の特徴に応じて暗号化通信を効果的に行うことができる。したがって、車載ネットワークにおいて、より良好な通信を提供することができる。
 (10)本開示の実施の形態に係る暗号化通信プログラムは、車両に搭載される車載装置に用いられる暗号化通信プログラムであって、コンピュータを、第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部として機能させるためのプログラムであり、前記処理部は、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化する。
 このように、車両において鍵情報を生成し、パケットの暗号化に用いる構成により、個々の車両において事前に格納した固有の鍵を長期間使用および管理する必要がない。また、たとえば最初にある程度セキュリティの高い暗号化方式を用いた上で、生成時間の短い暗号化方式へ切り替えることにより、各方式の特徴に応じて暗号化通信を効果的に行うことができる。したがって、車載ネットワークにおいて、より良好な通信を提供することができる。
 以下、本開示の実施の形態について図面を用いて説明する。なお、図中同一または相当部分には同一符号を付してその説明は繰り返さない。また、以下に記載する実施の形態の少なくとも一部を任意に組み合わせてもよい。
 [構成および基本動作]
 図1は、本開示の実施の形態に係る車両管理システムの構成を示す図である。
 図1を参照して、車両管理システム1は、サーバ11と、インフラ側装置12と、車両10Aに搭載される車載通信システム13と、他の車両10Bに搭載される車載通信システム14と、複数のMEC(Mobile Edge Computing)15とを備える。
 車両管理システム1は、車両10A,10Bとサーバ11との間で種々のデータのやり取りをすることを可能にする。たとえば、車両管理システム1は、車両10A,10Bにおいて撮影されたカメラ画像および動画等をサーバ11へアップロードすることを可能にする。また、車両管理システム1は、車両10A,10Bに搭載された各種ソフトウェアの更新プログラムをサーバ11から車両10A,10Bへ送信することを可能にする。本実施の形態では、一例として、車両10Aが、車両10Aにおける各種ソフトウェアのログを含むログ情報を車両10B経由でサーバ11へアップロードする場合を想定する。
 車両10Aは、ログ情報を車両10Bへ送信する。車両10Bは、車両10Aから受信したログ情報を車両10Bに近いかまたは車両10Bとの通信環境が良いインフラ側装置12へ送信する。インフラ側装置12は、たとえば無線基地局装置である。インフラ側装置12は、車両10Bから受信したログ情報をMEC15へ送信する。なお、インフラ側装置12は、ビーコンであってもよい。また、インフラ側装置12は、MEC15を含んでいてもよい。
 MEC15は、インフラ側装置12から受信したログ情報を分析し、他のMEC15とログ情報を共有したり、各MEC15同士でログ情報を補完し合ったりする。MEC15は、たとえばログ情報から事故情報等の緊急の情報を取得すると、車両10A,10Bへ警報を発報する。MEC15は、警報を車両10A,10Bに直接発報してもよいし、車両10Bを経由して車両10Aへ発報または車両10Aを経由して車両10Bへ発報してもよい。また、MEC15は、ログ情報をサーバ11へ送信する。
 サーバ11は、MEC15から受信したログ情報をさらに詳細に分析し、必要な処置を行う。
 図2は、本開示の実施の形態に係る車載通信システムの構成を示す図である。図2は、一例として、車両10Aにおける車載通信システム13の構成を示すが、他の車両10Bにおける車載通信システム14の構成も同様である。
 図2を参照して、車載通信システム13は、車載装置131~134と、中継装置135とを備える。
 なお、車載通信システム13は、4つの車載装置131~134を備える構成に限らず、3つ以下、または5つ以上の車載装置を備える構成であってもよい。また、車載通信システム13は、1つの中継装置135を備える構成に限らず、2つ以上の中継装置を備える構成であってもよい。
 車載装置131は、たとえばTCU(Telematics Communication Unit)である。以下、車載装置131を、TCU131とも称する。
 車載装置133,134は、たとえば、自動運転ECU(Electronic Control Unit)、センサ、ナビゲーション装置、ヒューマンマシンインタフェース、およびカメラ等である。なお、車載装置132については、後述する。
 車載通信システム13では、車載装置131~134は、イーサネット(登録商標)ケーブルを介して中継装置135に接続される。
 中継装置135は、たとえば、スイッチ装置である。なお、中継装置135は、ゲートウェイ装置であってもよい。中継装置135は、イーサネットの通信規格に従って、イーサネットフレームの中継処理を行う。
 具体的には、中継装置135は、たとえば、車載装置131~134間でやり取りされるイーサネットフレームを中継する。イーサネットフレームには、IPパケットが格納される。
 なお、車載通信システム13では、イーサネットの通信規格に従ってイーサネットフレームの中継が行われる構成に限らず、たとえば、CAN(Controller Area Network)(登録商標)、FlexRay(登録商標)、MOST(Media Oriented Systems Transport)(登録商標)およびLIN(Local Interconnect Network)等の通信規格に従ってデータの中継が行われる構成であってもよい。
 図1および図2を参照して、TCU131は、インフラ側装置12と通信を行うことが可能である。詳細には、TCU131は、たとえば、IPプロトコルに従い、インフラ側装置12を介してサーバ11と通信することが可能である。
 より詳細には、TCU131は、たとえば、LTE(Long Term Evolution)または5G等の通信規格に従って、インフラ側装置12と無線通信を行うことが可能である。
 具体的には、TCU131は、たとえば、IPサーバからのIPパケットが格納された無線フレームをインフラ側装置12から受信すると、受信した無線フレームからIPパケットを取得し、取得したIPパケットをイーサネットフレームに格納して中継装置135へ送信する。
 また、TCU131は、中継装置135からイーサネットフレームを受信すると、受信したイーサネットフレームからIPパケットを取得し、取得したIPパケットを無線フレームに格納してインフラ側装置12へ送信する。
 また、TCU131は、たとえば、他の車両10BにおけるTCUと近距離無線通信等によって無線通信することが可能である。
 図3は、本開示の実施の形態に係る車載通信システムにおける車載装置の構成を示す図である。図3では、一例として、車両10Aにおける車載装置132の構成を示す。
 図3を参照して、車載装置132は、通信部1321と、処理部1322と、記憶部1323とを備える。通信部1321は、たとえば通信用IC(Integrated Circuit)等の通信回路によって実現される。処理部1322は、たとえば、CPUまたはDSP(Digital Signal Processing)等のプロセッサによって実現される。記憶部1323は、たとえば不揮発性メモリである。
 通信部1321は、TCU131を介して車両10Bおよびインフラ側装置12とデータのやり取りを行う。また、通信部1321は、中継装置135を介して他の車載装置131,133,134とデータのやり取りを行う。
 処理部1322は、たとえば、データを複数のIPパケットに分割して格納し、各IPパケットのデータ部分の暗号化および復号化等の処理を行う。
 図4は、本開示の実施の形態に係る車載装置における処理部の構成を示す図である。図4では、一例として、車両10Aにおける処理部1322の構成を示す。
 図4を参照して、処理部1322は、タイマ1324と、暗号化部1325と、復号化部1326と、車両情報取得部1327とを含む。
 タイマ1324は、現在時刻を示す時刻情報を定期的に記憶部1323に保存する。
 車両情報取得部1327は、車両10Aの速度等の走行状態を示す情報を中継装置135および通信部1321経由で他の車載装置から取得し、暗号化部1325へ出力する。
 暗号化部1325は、車両情報取得部1327から走行状態を示す情報を受けて、後述するように当該情報が所定の条件を満たす場合、記憶部1323から時刻情報を取得し、当該時刻情報および乱数を用いてIPパケットを暗号化する。
 復号化部1326は、後述するように、他の車両10Bから暗号化されたIPパケットをTCU131、中継装置135および通信部1321を介して受信すると、当該IPパケットを復号化する。
 [動作の流れ]
 車両管理システム1における各装置は、コンピュータを備え、当該コンピュータにおけるCPU等の演算処理部は、以下のシーケンス図またはフローチャートの各ステップの一部または全部を含むプログラムを図示しないメモリからそれぞれ読み出して実行する。これら複数の装置のプログラムは、それぞれ、外部からインストールすることができる。これら複数の装置のプログラムは、それぞれ、記録媒体に格納された状態で流通する。
 図5は、本開示の実施の形態に係る車両管理システムにおける暗号化通信の処理を示すシーケンスの前半を示す図である。
 図3から図5を参照して、まず、インフラ側装置12は、車両10Aおよび他の車両10Bへ時刻情報を定期的に送信する(ステップS101)。
 次に、車両10Aおよび他の車両10Bは、インフラ側装置12から時刻情報を受信し、時刻同期を行う。時刻同期は、たとえばNTP(Neetwork Time Protocol)を用いる(ステップS102)。
 次に、車両10Aおよび他の車両10Bは、自己の車両における通信可能範囲に入ったことを示す通信可能通知を定期的にブロードキャストする。そして、車両10Aにおける処理部1322は、他の車両10Bが通信可能範囲内に入ると、TCU131、中継装置135および通信部1321を介して他の車両10Bから通信可能通知を受信する(ステップS103)。
 処理部1322は、他の車両10Bから初めて通信可能通知を受信すると、第1の方式に従い、第1の鍵導出情報を生成し、第1の鍵導出情報を用いて第1の鍵情報を生成する。
 第1の方式は、たとえば、秘密鍵および公開鍵による暗号化方式と、共通鍵による暗号化方式とを組み合わせた暗号化方式である。
 より詳細には、処理部1322は、第1の方式において、記憶部1323に保存されている時刻情報と乱数とを用いて、第1の鍵導出情報として秘密鍵および公開鍵のペアを生成する。処理部1322は、生成した秘密鍵および公開鍵のペアを記憶部1323に保存する(ステップS104,S105)。
 次に、処理部1322は、生成した公開鍵について電子証明書を生成し、記憶部1323に保存する(ステップS106)。
 次に、車両10Aと同様に、他の車両10Bにおける処理部1322も、第1の方式において、時刻情報と乱数とを用いて、第1の鍵導出情報として秘密鍵および公開鍵のペアを生成する。他の車両10Bにおいて、処理部1322は、生成した公開鍵について電子証明書を生成し、記憶部1323に保存する(ステップS107~S109)。
 次に、車両10Aにおける処理部1322は、記憶部1323に保存されている公開鍵および電子証明書を、鍵交換要求とともに通信部1321およびTCU131を介して他の車両10Bへ送信する(ステップS110)。
 次に、他の車両10Bにおいて、処理部1322は、TCU131および通信部1321を介して車両10Aから公開鍵、電子証明書および鍵交換要求を受信すると、当該電子証明書を検証する(ステップS111)。
 次に、他の車両10Bにおいて、処理部1322は、受信した公開鍵が車両10Aにおいて生成されたものであることを確認すると、生成した公開鍵および電子証明書を、鍵交換応答とともに通信部1321およびTCU131を介して車両10Aへ送信する(ステップS112)。
 次に、車両10Aにおける処理部1322は、TCU131および通信部1321を介して他の車両10Bから公開鍵、電子証明書および鍵交換応答を受信すると、電子証明書を検証する(ステップS113)。
 次に、車両10Aにおける処理部1322は、受信した公開鍵が他の車両10Bにおいて生成されたものであることを確認すると、その旨を示す鍵交換結果通知を通信部1321およびTCU131を介して他の車両10Bへ送信する(ステップS114)。
 次に、車両10Aにおいて、処理部1322は、生成した秘密鍵と他の車両10Bから受信した公開鍵とを用いて第1の鍵情報として共通鍵K1を生成する(ステップS115)。
 次に、車両10Aと同様に、他の車両10Bにおいて、処理部1322は、車両10AからTCU131および通信部1321を介して鍵交換結果通知を受信すると、他の車両10Bにおいて生成した秘密鍵と車両10Aから受信した公開鍵とを用いて共通鍵K1を生成する(ステップS116)。
 次に、他の車両10Bにおける処理部1322は、共通鍵K1を生成すると、共通鍵K1を用いて暗号化した共通鍵確認要求を通信部1321およびTCU131を介して車両10Aへ送信する(ステップS117)。
 次に、車両10Aにおいて、処理部1322は、TCU131および通信部1321を介して共通鍵確認要求を受信すると、受信した共通鍵確認要求を共通鍵K1を用いて復号化し、共通鍵確認応答を通信部1321およびTCU131を介して他の車両10Bへ送信する(ステップS118)。
 次に、車両10Aにおいて、処理部1322は、第1の鍵情報である共通鍵K1を用いて、データを格納したIPパケットを暗号化する。より詳細には、処理部1322は、たとえば、車載装置131,133,134にインストールされている各種ソフトウェアのログ情報を複数のIPパケットに分割して格納する。そして、処理部1322は、IPパケットのデータ部分を共通鍵K1を用いて暗号化し、当該IPパケットを通信部1321へ出力する(ステップS119)。
 次に、車両10Aにおける通信部1321は、処理部1322から暗号化されたIPパケットを受けて、当該IPパケットをTCU131経由で他の車両10Bへ送信する(ステップS120)。
 次に、他の車両10Bにおいて、処理部1322は、TCU131および通信部1321を介して車両10Aから暗号化されたIPパケットを受信すると、共通鍵K1を用いて当該IPパケットのデータ部分を復号化する。処理部1322は、復号化により取得したログ情報の一部を格納したIPパケットを通信部1321およびTCU131を介してインフラ側装置12へ送信する。この際、処理部1322は、当該ログ情報の一部を暗号化してインフラ側装置12へ送信する。このときの暗号化方式は、特に限定されず、周知の暗号化方式でよい(ステップS121)。
 図6は、本開示の実施の形態に係る車両管理システムにおける暗号化通信の処理を示すシーケンスの後半を示す図である。
 図6を参照して、車両10Aにおける処理部1322は、第1の鍵情報を用いてIPパケットを暗号化した後、第1の所定条件を満たした場合、第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、第2の鍵導出情報を用いて、第2の鍵情報を生成する。そして、処理部1322は、第1の鍵情報の代わりに第2の鍵情報を用いて、通信部1321により新たに送信される、ログ情報の一部を格納したIPパケットを暗号化する。
 第1の所定条件は、たとえば、経過時間または第1の鍵情報の使用を開始してからの他の車両10Bとの通信量に関する条件である。より詳細には、経過時間に関する条件は、たとえば、共通鍵K1を用いた暗号化通信の継続時間が所定時間以上となった場合である。通信量に関する条件は、たとえば、共通鍵K1を用いた暗号化通信の通信量が所定量以上となった場合である。
 ただし、第1の所定条件は、上記条件に限定されず、たとえば車両10Aの走行状態に関する条件であってもよい。より詳細には、車両10Aと他の車両10Bとの速度または加速度の差が、所定値以上である場合である。
 第2の方式は、たとえば、暗号学的ハッシュ関数を用いた暗号化方式である。
 より詳細には、処理部1322は、第2の方式において、記憶部1323に保存されている時刻情報と乱数とを用いて、第1の暗号学的ハッシュ関数を用いてハッシュ値を第2の鍵導出情報として生成し、生成したハッシュ値から第2の暗号学的ハッシュ関数を用いて第2の鍵情報である共通鍵K2を生成する(ステップS122~S124)。
 次に、処理部1322は、第2の鍵導出情報であるハッシュ値を、第1の鍵情報である共通鍵K1を用いて暗号化する(ステップS125)。
 次に、処理部1322は、暗号化した第2の鍵導出情報を鍵更新要求とともに通信部1321、中継装置135およびTCU131を介して他の車両10Bへ送信する(ステップS126)。
 次に、他の車両10Bにおける処理部1322は、TCU131、中継装置135および通信部1321を介して車両10Aから鍵更新要求および暗号化された第2の鍵導出情報であるハッシュ値を受信すると、当該ハッシュ値を第1の鍵情報である共通鍵K1を用いて復号化する(ステップS127)。
 次に、他の車両10Bにおける処理部1322は、復号化した第2の鍵導出情報であるハッシュ値から第2の暗号学的ハッシュ関数を用いて共通鍵K2を生成する(ステップS128)。
 次に、車両10Aにおける処理部1322は、暗号化した第2の鍵導出情報を他の車両10Bへ送信してから所定時間経過後に、共通鍵確認要求を通信部1321、中継装置135およびTCU131を介して他の車両10Bへ送信する(ステップS129)。
 次に、他の車両10Bにおける処理部1322は、たとえば、TCU131、中継装置135および通信部1321を介して車両10Aから共通鍵確認要求を受信し、かつ、共通鍵K2の生成が完了した場合、IPパケットの暗号化に用いる鍵情報を共通鍵K1から共通鍵K2に切り替える。そして、処理部1322は、共通鍵確認応答を通信部1321、中継装置135およびTCU131を介して車両10Aへ送信し、第1の鍵情報である共通鍵K1を破棄する(ステップS130およびS131)。
 次に、車両10Aにおける処理部1322は、他の車両10BからTCU131および通信部1321を介して共通鍵確認応答を受信すると、IPパケットの暗号化に用いる鍵情報を共通鍵K1から共通鍵K2に切り替える。そして、処理部1322は、第1の鍵情報である共通鍵K1を破棄する(ステップS132)。
 次に、車両10Aにおける処理部1322は、たとえば、図5のステップS119において分割されたログ情報の一部を格納したIPパケットであって、他の車両10Bへ未だ送信されていないIPパケットのデータ部分を共通鍵K2を用いて暗号化し、当該IPパケットを通信部1321へ出力する(ステップS133)。
 次に、車両10Aにおける通信部1321は、処理部1322から暗号化されたIPパケットを受けて、当該IPパケットをTCU131経由で他の車両10Bへ送信する(ステップS134)。
 次に、他の車両10Bにおいて、処理部1322は、TCU131および通信部1321を介して車両10Aから暗号化されたIPパケットを受信すると、パケット受信応答を通信部1321およびTCU131を介して車両10Aへ送信するとともに、共通鍵K2を用いて当該IPパケットのデータ部分を復号化する(ステップS135およびS136)。
 次に、他の車両10Bにおける処理部1322は、復号化により取得したログ情報の一部を通信部1321およびTCU131を介してインフラ側装置12へ送信する。この際、処理部1322は、当該ログ情報の一部を格納したIPパケットを暗号化してインフラ側装置12へ送信する。このときの暗号化方式は、特に限定されず、周知の暗号化方式でよい(ステップS137)。
 次に、車両10Aにおける処理部1322は、第2の所定条件を満たした場合、第2の方式に従い、新たな第2の鍵導出情報を生成し、新たな第2の鍵導出情報を用いて新たな第2の鍵情報を生成する。そして、処理部1322は、新たな第2の鍵情報を用いて、通信部1321により新たに送信される、ログ情報の一部を格納したIPパケットを暗号化する。より詳細には、処理部1322は、たとえば、共通鍵K2を用いた暗号化通信の開始から所定時間経過すると、時刻情報および乱数を用いて第2の鍵導出情報として新たな暗号学的ハッシュ関数を生成し、生成した暗号学的ハッシュ関数を用いて新たな共通鍵K2を生成し、当該共通鍵K2を用いた他の車両10Bとの暗号化通信を開始する。処理部1322は、新たな共通鍵K2を用いた暗号化通信の開始後、古い共通鍵K2を破棄する。このように、第2の所定条件を満たした場合、共通鍵K2を更新することで、たとえば車両10Aの状態が変わることでログ情報が増加した場合であっても、セキュリティを確保することができる。なお、第2の所定条件は、共通鍵K2を用いた暗号化通信の開始からの所定の経過時間に限られず、車両10Aの走行状態に関する条件等であってもよい。
 このように、処理部1322は、第2の方式において、第2の鍵情報を順次更新しながら暗号化通信を行う。
 車両10Aにおける処理部1322は、第2の鍵情報である共通鍵を用いて暗号化したIPパケットを他の車両10Bへ送信した後、所定時間内に他の車両10Bからのパケット受信応答が到着しない場合、第2の鍵情報である共通鍵、第1の鍵導出情報である秘密鍵および公開鍵のペア、ならびに公開鍵の電子証明書を破棄し、他の車両10Bとの暗号化通信を終了する(ステップS138)。
 なお、車両10Aは、他の車両10Bにおけるソフトウェアのログ情報をインフラ側装置12へ送信してもよい。より詳細には、他の車両10Bにおいて、処理部1322は、TCU131および通信部1321を介して車両10Aから暗号化されたIPパケットを受信すると、他の車両10Bにおける各車載装置にインストールされている各種ソフトウェアのログ情報の一部が格納されたIPパケットを、共通鍵K1またはK2を用いて暗号化し、通信部1321およびTCU131を介してパケット受信応答とともに車両10Aへ送信してもよい。この場合、車両10Aにおける処理部1322は、TCU131および通信部1321を介して受信したIPパケットを共通鍵K1またはK2を用いて復号化し、復号化により取得した他の車両10Bのログ情報の一部を格納したIPパケットをインフラ側装置12へ送信する。
 なお、車両10Aおよび他の車両10Bは、第1の鍵情報である共通鍵K1を用いた暗号化通信中において、所定時間内に上記第1の所定条件を満たさない場合、共通鍵K1を用いた暗号化通信を終了する。より詳細には、車両10Aおよび他の車両10Bが共通鍵K1の使用を開始してから所定時間が経過し、かつ、第1の所定条件を満たさない場合、車両10Aおよび他の車両10Bは共通鍵K1を破棄し、暗号化通信を終了する。ただし、車両10Aおよび他の車両10Bは、共通鍵K1を用いた暗号化通信を、時間の経過によらず、たとえば一方の車両の走行が終了するか、またはイグニッションもしくは電源がオフされたときに終了してもよい。
 また、他の車両10Bは、車両10Aからの共通鍵確認要求を受信し、かつ、共通鍵K2の生成が完了した場合に、IPパケットの暗号化に用いる鍵情報を共通鍵K1から共通鍵K2に切り替える構成に限らない。他の車両10Bは、たとえば、フラグ等の特定の内容を含むイーサネットフレームを車両10Aから受信した場合等に、IPパケットの暗号化に用いる鍵情報を共通鍵K1から共通鍵K2に切り替えてもよい。この場合、車両10Aは、たとえば、上記の特定の内容を含むイーサネットフレームを送信した場合、IPパケットの暗号化に用いる鍵情報を共通鍵K1から共通鍵K2に切り替える。
 ところで、車両の各種ソフトウェアのログ情報等のデータは、たとえば車両に搭載されたEDR(Event Data Recorder)に保存される。しかしながら、EDRの記憶容量の制限により、EDRに保存できるログ情報には限りがある。そこで、より多くのデータを収集するために、車両のログ情報をサーバに随時アップロードすることが考えられる。この場合、車両とサーバとは無線通信を用いてデータをやり取りするため、データを暗号化する必要がある。
 しかしながら、車両がサーバ等の他の設備と暗号化通信を行うには、認証局および鍵生成局等の外部システムから暗号化に必要な電子証明書および暗号鍵等の情報を、事前に車両に格納および管理する必要がある。暗号化に必要な情報の管理は、個々の車両ごとで行うため、車両の台数が増えるにつれて煩雑になり、困難である。
 これに対し、本実施の形態に係る車両管理システム、車載装置、暗号化通信方法および暗号化通信プログラムでは、車両において共通鍵K1,K2を生成し、データを格納したIPパケットの暗号化に用いる。共通鍵K1,K2は、所定時間が経過および無線接続が切断される等により破棄される。その後、再びIPパケットをサーバ11へアップロードする際には、新たな共通鍵を生成し、IPパケットの暗号化に用いる。このように、IPパケットの暗号化に用いる共通鍵K1,K2を車両において生成し、ある特定の期間のみ用いる時限式とすることで、個々の車両において事前に格納した固有の鍵を長期間使用および管理する必要がない。また、時限式の共通鍵を用いることで、仮に共通鍵K1,K2を用いた暗号化通信が傍受され、解読されたとしても、その後の暗号化通信は共通鍵K1,K2とは異なる共通鍵を用いる。そのため、その後の暗号化通信が先の暗号化通信の解読方法で再び解読される可能性を低減できる。したがって、車載ネットワークにおいて、より良好な通信を提供することができる。
 また、車両10Aがインフラ側装置12とLTEまたは5G等の規格を用いて通信する場合、車両10Aの位置または通信環境等によっては、通信が不安定となり、サーバ11へのデータのアップロードが困難となることがある。
 これに対し、本実施の形態に係る車両管理システム、車載装置、暗号化通信方法および暗号化通信プログラムでは、車両10Aは、データを他の車両10Bおよびインフラ側装置12経由でサーバ11へアップロードする。そのため、車両10Aおよびインフラ側装置12間の通信が不安定または不能であっても、他の車両10Bがインフラ側装置12と通信可能であれば、車両10Aのログ情報をサーバ11へアップロードすることができる。したがって、車載ネットワークにおいて、より良好な通信を提供することができる。
 また、一般に、共通鍵を用いた暗号化通信は、共通鍵を通信相手に渡す際に共通鍵が第3者に知られると、暗号が解読される可能性がある。一方、秘密鍵および公開鍵のペアを用いた暗号化通信は、公開鍵のみを通信相手に渡し、この公開鍵は第3者に知られたとしても暗号が解読される可能性は低い。そのため、車車間通信は、秘密鍵および公開鍵のペアを用いた暗号化通信を採用することが望ましい。
 しかしながら、秘密鍵および公開鍵のペアの生成は、処理が多く、長時間を要する。車両は移動体であるため、車両間の距離および障害物等により、車車間通信は意図せず切断されることがある。そのため、車車間通信においては、鍵の生成は速い方が望ましい。
 これに対し、本実施の形態に係る車両管理システム、車載装置、暗号化通信方法および暗号化通信プログラムでは、車両10A,10Bは、最初に第1の方式である秘密鍵および公開鍵のペアを用いて共通鍵K1を生成するが、その後は第2の方式である暗号学的ハッシュ関数を用いた共通鍵K2を生成し、暗号化に用いる。暗号学的ハッシュ関数を用いた共通鍵K2は、秘密鍵および公開鍵のペアよりも速く生成することができる。そのため、短時間でIPパケットを暗号化することができ、車車間通信において、より多くの暗号化されたIPパケットをやり取りすることができる。したがって、車載ネットワークにおいて、より良好な通信を提供することができる。
 上記実施の形態は、すべての点で例示であって制限的なものではないと考えられるべきである。本発明の範囲は、上記説明ではなく請求の範囲によって示され、請求の範囲と均等の意味および範囲内でのすべての変更が含まれることが意図される。
 以上の説明は、以下に付記する特徴を含む。
 [付記1]
 車両に搭載される車載装置であって、
 第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、
 前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部とを備え、
 前記処理部は、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化し、
 前記処理部は、第2の所定条件を満たした場合、前記第2の方式に従い、新たな第2の鍵導出情報を生成し、前記新たな第2の鍵導出情報を用いて新たな第2の鍵情報を生成し、新たな第2の鍵情報を、前記通信部により新たに送信されるパケットの暗号化に用いる、車載装置。
   1 車両管理システム
 10A 車両
 10B 他の車両
  11 サーバ
  12 インフラ側装置
  13 車載通信システム
 131~134 車載装置
1321 通信部
1322 処理部
1323 記憶部
1324 タイマ
1325 暗号化部
1326 復号化部
1327 車両情報取得部
 135 中継装置
  14 車載通信システム(他の車両)
  15 MEC

Claims (10)

  1.  車両に搭載される車載装置であって、
     第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、
     前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部とを備え、
     前記処理部は、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化する、車載装置。
  2.  前記処理部は、前記第2の鍵導出情報を、前記第1の鍵情報を用いて暗号化し、
     前記通信部は、前記処理部によって暗号化された前記第2の鍵導出情報を前記他の車両へ送信する、請求項1に記載の車載装置。
  3.  前記処理部は、前記第1の方式において、前記第1の鍵導出情報として秘密鍵および公開鍵のペアを生成し、前記ペアを用いて前記第1の鍵情報として共通鍵を生成し、
     前記処理部は、前記第2の方式において、前記第2の鍵導出情報として第1の暗号学的ハッシュ関数を用いてハッシュ値を生成し、前記ハッシュ値から第2の暗号学的ハッシュ関数を用いて共通鍵を生成し、
     前記通信部は、前記処理部によって生成された前記ハッシュ値を前記他の車両へ送信する、請求項1または請求項2に記載の車載装置。
  4.  前記処理部は、所定条件を満たした場合、前記第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を、前記通信部により新たに送信されるパケットの暗号化に用い、
     前記所定条件は、経過時間または前記第1の鍵情報の使用を開始してからの前記他の車両との通信量に関する条件である、請求項1から請求項3のいずれか1項に記載の車載装置。
  5.  前記処理部は、所定条件を満たした場合、前記第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を、前記通信部により新たに送信されるパケットの暗号化に用い、
     前記所定条件は、前記車両の走行状態に関する条件である、請求項1から請求項3のいずれか1項に記載の車載装置。
  6.  前記処理部は、前記第2の鍵情報を更新する、請求項1から請求項5のいずれか1項に記載の車載装置。
  7.  前記処理部は、前記第1の方式および前記第2の方式の少なくともいずれか一方において、時刻情報および乱数を鍵導出情報の生成に用いる、請求項1から請求項6のいずれか1項に記載の車載装置。
  8.  前記処理部は、前記第1の方式または前記第2の方式に従って、前記他の車両から受信した暗号化されたパケットを復号化し、
     前記通信部は、復号化したパケットに格納されたデータをインフラ側装置へ送信する、請求項1から請求項7のいずれか1項に記載の車載装置。
  9.  車両に搭載される車載装置における暗号化通信方法であって、
     第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化するステップと、
     暗号化した前記パケットを他の車両へ送信するステップと、
     前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、新たに送信するパケットを暗号化するステップとを含む、暗号化通信方法。
  10.  車両に搭載される車載装置に用いられる暗号化通信プログラムであって、
     コンピュータを、
     第1の方式に従い、第1の鍵導出情報を生成し、前記第1の鍵導出情報を用いて第1の鍵情報を生成し、前記第1の鍵情報を用いてパケットを暗号化する処理部と、
     前記処理部によって暗号化された前記パケットを他の車両へ送信する通信部として機能させるためのプログラムであり、
     前記処理部は、前記第1の鍵情報を用いて前記パケットを暗号化した後、前記第1の方式よりも鍵情報の生成時間が短い第2の方式に従い、第2の鍵導出情報を生成し、前記第2の鍵導出情報を用いて第2の鍵情報を生成し、前記第1の鍵情報の代わりに前記第2の鍵情報を用いて、前記通信部により新たに送信されるパケットを暗号化する、暗号化通信プログラム。
     
PCT/JP2021/025351 2020-10-22 2021-07-05 車載装置、暗号化通信方法および暗号化通信プログラム Ceased WO2022085243A1 (ja)

Priority Applications (2)

Application Number Priority Date Filing Date Title
JP2022556402A JP7574856B2 (ja) 2020-10-22 2021-07-05 車載装置、暗号化通信方法および暗号化通信プログラム
US18/032,812 US20240007271A1 (en) 2020-10-22 2021-07-05 In-vehicle device, encrypted communication method, and encrypted communication program

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2020177070 2020-10-22
JP2020-177070 2020-10-22

Publications (1)

Publication Number Publication Date
WO2022085243A1 true WO2022085243A1 (ja) 2022-04-28

Family

ID=81290374

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2021/025351 Ceased WO2022085243A1 (ja) 2020-10-22 2021-07-05 車載装置、暗号化通信方法および暗号化通信プログラム

Country Status (3)

Country Link
US (1) US20240007271A1 (ja)
JP (1) JP7574856B2 (ja)
WO (1) WO2022085243A1 (ja)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US12531840B2 (en) * 2022-01-07 2026-01-20 Samsung Electronics Co., Ltd. Electronic apparatus for vehicle and method for storing vehicle information in electronic apparatus
US12452278B1 (en) * 2024-04-03 2025-10-21 Netscout Systems, Inc. Systems and methods for selective decryption of encrypted data packets

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003110540A (ja) * 2001-10-01 2003-04-11 Keio Gijuku 暗号鍵更新方法
JP2009064178A (ja) * 2007-09-05 2009-03-26 Hitachi Ltd ストレージ装置及びデータの管理方法
JP2011087249A (ja) * 2009-10-19 2011-04-28 Ricoh Co Ltd 通信装置及び通信制御方法
WO2012008158A1 (ja) * 2010-07-13 2012-01-19 三洋電機株式会社 端末装置
JP2020017805A (ja) * 2018-07-23 2020-01-30 Kddi株式会社 車両情報送信装置、車両情報受信装置、車両情報通信方法及びコンピュータプログラム

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US4200770A (en) * 1977-09-06 1980-04-29 Stanford University Cryptographic apparatus and method
US10491404B1 (en) * 2018-09-12 2019-11-26 Hotpyp, Inc. Systems and methods for cryptographic key generation and authentication
US11343084B2 (en) * 2019-03-01 2022-05-24 John A. Nix Public key exchange with authenticated ECDHE and security against quantum computers

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003110540A (ja) * 2001-10-01 2003-04-11 Keio Gijuku 暗号鍵更新方法
JP2009064178A (ja) * 2007-09-05 2009-03-26 Hitachi Ltd ストレージ装置及びデータの管理方法
JP2011087249A (ja) * 2009-10-19 2011-04-28 Ricoh Co Ltd 通信装置及び通信制御方法
WO2012008158A1 (ja) * 2010-07-13 2012-01-19 三洋電機株式会社 端末装置
JP2020017805A (ja) * 2018-07-23 2020-01-30 Kddi株式会社 車両情報送信装置、車両情報受信装置、車両情報通信方法及びコンピュータプログラム

Also Published As

Publication number Publication date
JPWO2022085243A1 (ja) 2022-04-28
US20240007271A1 (en) 2024-01-04
JP7574856B2 (ja) 2024-10-29

Similar Documents

Publication Publication Date Title
EP4050474B1 (en) Vehicle upgrade packet processing method and apparatus
EP3337127B1 (en) Legitimacy verification of a node in a distributed network using certificate white-listing
US9135820B2 (en) Communication system, vehicle-mounted terminal, roadside device
JP6617173B2 (ja) 複数のマネージャまたはアクセスポイントを有する無線ネットワークにおける独立したセキュリティ
JP5435513B2 (ja) 暗号通信システム、鍵配布装置、暗号通信方法
EP2981028B1 (en) Transponder module and access module for activating and configuring such transponder module over a CAN bus
JP5587239B2 (ja) 車車/路車間通信システム
AU2015295563B2 (en) Transponder module and access module for activating and configuring such transponder module
CN115885496B (zh) 一种通信方法及相关装置
CN110858970B (zh) 第一车辆侧的终端设备及其运行方法、第二车辆侧的终端设备及其运行方法
WO2021126554A1 (en) Privacy-preserving delivery of activation codes for pseudonym certificates
US11218309B2 (en) Vehicle communication system and vehicle communication method
JP7704192B2 (ja) 車載中継装置、管理装置、車載システムおよび通信管理方法
JP7574856B2 (ja) 車載装置、暗号化通信方法および暗号化通信プログラム
JP7647974B2 (ja) 中継装置、車両通信方法および車両通信プログラム
JP2018121220A (ja) 車載ネットワークシステム
CN112400331A (zh) 根据置信水平的车对外界通信装置和方法
JP2008060809A (ja) 車車間通信方法、車車間通信システムおよび車載通信装置
KR102400940B1 (ko) 자율 주행 차량의 통신 보안 장치 및 방법
CN112740726B (zh) 一种数据传输方法及装置
WO2024154585A1 (ja) 車載装置、情報処理方法及び、車載システム
JP6681755B2 (ja) 車両用通信網装置及び通信方法
CN119031341A (zh) 纳入v2x通信伙伴的数据的方法和支持数据的纳入的方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21882386

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2022556402

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 18032812

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21882386

Country of ref document: EP

Kind code of ref document: A1