WO2024201600A1 - 制御システムおよび車両 - Google Patents
制御システムおよび車両 Download PDFInfo
- Publication number
- WO2024201600A1 WO2024201600A1 PCT/JP2023/011933 JP2023011933W WO2024201600A1 WO 2024201600 A1 WO2024201600 A1 WO 2024201600A1 JP 2023011933 W JP2023011933 W JP 2023011933W WO 2024201600 A1 WO2024201600 A1 WO 2024201600A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication key
- control device
- authentication
- key
- electronic control
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0822—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0894—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0894—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
- H04L9/0897—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage involving additional devices, e.g. trusted platform module [TPM], smartcard or USB
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/84—Vehicles
Definitions
- This disclosure relates to a control system that performs authentication processing using an authentication key, and a vehicle equipped with such a control system.
- Patent Document 1 discloses technology for managing security access keys in a vehicle master device.
- a control system includes a first control device and a second control device.
- the first control device has a first security circuit in which a first encryption key is stored and in which external access is restricted, and a first storage circuit.
- the second control device has a second security circuit in which a second encryption key is stored and in which external access is restricted, and a second storage circuit.
- the first control device is capable of generating an authentication key used in authentication processing between the first control device and the second control device, and is capable of generating the first authentication key by encrypting the authentication key with the first encryption key, and is capable of storing the first authentication key in the first storage circuit.
- the first control device is capable of supplying the generated authentication key to the second control device.
- the second control device is capable of generating a second authentication key by encrypting the authentication key supplied from the first control device with the second encryption key, and is capable of storing the second authentication key in the second storage circuit.
- a vehicle according to one embodiment of the present disclosure is equipped with the above-described control system.
- the first control device includes an electronic control unit that controls the vehicle.
- FIG. 1 is an explanatory diagram illustrating an example configuration of a control system according to an embodiment of the present disclosure.
- FIG. 2 is a block diagram showing an example of the configuration of the central electronic control unit and the communication module shown in FIG.
- FIG. 3 is an explanatory diagram illustrating an example of an operation of the control system shown in FIG.
- FIG. 4 is a sequence diagram showing an example of an operation of the control system shown in FIG.
- FIG. 5 is an explanatory diagram showing another operation example of the control system shown in FIG.
- FIG. 6A is a sequence diagram illustrating an example of an operation of the control system illustrated in FIG.
- FIG. 6B is another sequence diagram illustrating an example of an operation of the control system illustrated in FIG.
- Control system 1 shows an example of a configuration of a control system (control system 1) according to an embodiment.
- the control system 1 is provided in a vehicle 9.
- the vehicle 9 is a vehicle such as an automobile.
- the control system 1 has a central electronic control unit (ECU: Electronic Control Unit) 10, a plurality of electronic control units 19, and a communication module 20.
- ECU Electronic Control Unit
- the central electronic control unit 10 is configured to control the operation of the vehicle 9 by controlling the operation of the multiple electronic control units 19.
- the central electronic control unit 10 is also connected to a diagnostic device 30 (described below) outside the vehicle, for example, via a communication cable, and is capable of communicating with this diagnostic device 30.
- the central electronic control unit 10 is also connected to a CAN (Controller Area Network) 9, and is configured to communicate with a communication module 20 via the CAN 9.
- CAN Controller Area Network
- the multiple electronic control units 19 are configured to control the operation of each device in the vehicle 9 based on instructions from the central electronic control unit 10.
- the multiple electronic control units 19 include, for example, an electronic control unit 19 that controls the powertrain such as the engine, an electronic control unit 19 that controls the steering device and the braking device, an electronic control unit 19 that controls the interior and exterior lighting, doors, windshield wipers, etc., an electronic control unit 19 that controls the driving assistance system, etc.
- the communication module 20 is configured to communicate with a base station by performing mobile communications such as 4G (4th Generation) or 5G (5th Generation). This allows the communication module 20 to communicate with a server 40 (described below) connected to the Internet via the base station.
- the communication module 20 is also connected to a CAN 9, and communicates with the central electronic control unit 10 via the CAN 9.
- authentication processing can be performed between the central electronic control unit 10 and the communication module 20.
- the central electronic control unit 10 for example, an encrypted authentication key KB1 is stored in a non-volatile memory 14 described below
- the communication module 20 for example, an encrypted authentication key KB2 is stored in a non-volatile memory 24 described below.
- the central electronic control unit 10 and the communication module 20 are capable of performing authentication processing using these authentication keys KB1 and KB2.
- FIG. 2 shows an example configuration of the central electronic control unit 10 and the communication module 20.
- the central electronic control unit 10 has a communication unit 11, a memory unit 12, a security module 15, an external communication unit 16, and a processing unit 17.
- the communication unit 11 is configured to communicate with the communication module 20 via the CAN 9.
- the memory unit 12 is configured to store data.
- the memory unit 12 has a RAM 13 and a non-volatile memory 14.
- the RAM 13 is configured, for example, using DRAM (Dynamic Random Access Memory) and is configured to temporarily store the processing contents of the central electronic control unit 10.
- the non-volatile memory 14 is configured, for example, using flash memory, and is configured to store software executed by the central electronic control unit 10 and an encrypted authentication key KB1.
- the memory areas of the RAM 13 and the non-volatile memory 14 can be accessed from outside the central electronic control unit 10 via the communication unit 11 and the processing unit 17.
- the security module 15 is a so-called HSM (Hardware Security Module), and is configured to store data in a secure memory area.
- the security module 15 stores an encryption key KA1.
- the security module 15 is configured to restrict access from outside the central electronic control unit 10. In this way, the security module 15 protects the stored data so that it cannot be easily rewritten and so that the stored data is not leaked.
- the external communication unit 16 is configured to communicate with a diagnostic device 30 (described below) using a communication cable, for example, when a malfunction occurs in the vehicle 9.
- the communication module 20 has a communication unit 21, a memory unit 22, a security module 25, a wireless communication unit 26, and a processing unit 27.
- the storage unit 22 is configured to store data.
- the storage unit 22 has a RAM 23 and a non-volatile memory 24.
- the RAM 23 is configured, for example, using a DRAM, and is configured to temporarily store the processing contents of the communication module 20.
- the non-volatile memory 24 is configured, for example, using a flash memory, and is configured to store the software executed by the communication module 20 and the encrypted authentication key KB2.
- the memory areas of the RAM 23 and the non-volatile memory 24 can be accessed from outside the communication module 20 via the communication unit 21 and the processing unit 27.
- the security module 25 is a so-called HSM, and is configured to store data in a secure memory area.
- the encryption key KA2 is stored in the security module 25.
- the security module 25 is configured to restrict access from outside the communication module 20. In this way, the security module 25 protects the stored data so that it cannot be easily rewritten and so that the stored data is not leaked.
- the wireless communication unit 26 is configured to communicate with a base station, for example, by performing mobile communications such as 4G or 5G. This allows the wireless communication unit 26 to communicate with a server 40 (described later) connected to the Internet via the base station.
- the wireless communication unit 26 is configured to be able to download, for example, update software from the server 40.
- the processing unit 27 is configured, for example, using one or more processors, and is configured to control the operation of the communication module 20 by executing software.
- the central electronic control unit 10 In this control system 1, the central electronic control unit 10 generates an authentication key KB based on instructions from the diagnostic device 30. The central electronic control unit 10 then transmits this authentication key KB to the communication module 20. The central electronic control unit 10 generates an authentication key KB1 by encrypting this authentication key KB using an encryption key KA1, and stores this authentication key KB1 in the non-volatile memory 14. Similarly, the communication module 20 generates an authentication key KB2 by encrypting this authentication key KB using an encryption key KA2, and stores this authentication key KB2 in the non-volatile memory 24. Thereafter, the central electronic control unit 10 and the communication module 20 are able to perform authentication processing using the authentication keys KB1 and KB2 stored in the non-volatile memories 14 and 24.
- the central electronic control unit 10 corresponds to a specific example of a "first control device” in one embodiment of the present disclosure.
- the encryption key KA1 corresponds to a specific example of a "first encryption key” in one embodiment of the present disclosure.
- the security module 15 corresponds to a specific example of a "first security circuit” in one embodiment of the present disclosure.
- the memory unit 12 corresponds to a specific example of a "first memory circuit” in one embodiment of the present disclosure.
- the communication module 20 corresponds to a specific example of a "second control device” in one embodiment of the present disclosure.
- the encryption key KA2 corresponds to a specific example of a "second encryption key” in one embodiment of the present disclosure.
- the security module 25 corresponds to a specific example of a "second security circuit” in one embodiment of the present disclosure.
- the memory unit 22 corresponds to a specific example of a "second memory circuit” in one embodiment of the present disclosure.
- the authentication key KB corresponds to a specific example of an "authentication key” in one embodiment of the present disclosure.
- the authentication key KB1 corresponds to a specific example of a "first authentication key” in one embodiment of the present disclosure.
- Authentication key KB2 corresponds to a specific example of a "second authentication key” in one embodiment of the present disclosure.
- the communication unit 11 communicates with the communication module 20 via the CAN 9.
- the memory unit 12 stores data.
- the security module 15 stores the data in a secure memory area.
- the security module 15 stores an encryption key KA1.
- the external communication unit 16 communicates with the diagnostic device 30 using a communication cable, for example, when a malfunction occurs in the vehicle 9.
- the processing unit 17 controls the operation of the central electronic control unit 10.
- the communication unit 21 communicates with the central electronic control unit 10 via the CAN 9.
- the memory unit 22 stores data.
- the security module 25 stores data in a secure memory area.
- the security module 25 stores an encryption key KA2.
- the wireless communication unit 26 performs mobile communication to communicate with a server 40 connected to the Internet via a base station.
- the wireless communication unit 26 can, for example, download update software from the server 40.
- the processing unit 27 controls the operation of the communication module 20.
- the control system 1 registers the authentication keys KB1 and KB2 used in the authentication process between the central electronic control unit 10 and the communication module 20. This operation is described in detail below.
- FIG. 3 shows an example of a vehicle 9 in which authentication keys KB1 and KB2 are stored.
- the owner of the vehicle 9 brings the vehicle 9 to a dealer.
- a dealer worker connects a diagnostic device 30 to the central electronic control unit 10 of the vehicle 9 via a communication cable 8, and the diagnostic device 30 diagnoses the vehicle 9.
- the diagnostic device 30 detects a malfunction of the central electronic control unit 10.
- the dealer worker replaces the central electronic control unit 10.
- the control system 1 registers the authentication keys KB1 and KB2 used in the authentication process between the central electronic control unit 10 and the communication module 20 based on instructions from the diagnostic device 30.
- FIG. 4 shows an example of the registration process for authentication keys KB1 and KB2 in the control system 1.
- the diagnostic device 30 requests the central electronic control unit 10 of the vehicle 9 to register an authentication key (step S101).
- the external communication unit 16 of the central electronic control unit 10 receives this registration request.
- the processing unit 17 of the central electronic control unit 10 generates an authentication key KB based on a request to register the authentication key from the diagnostic device 30, and stores this authentication key KB in the RAM 13 (step S102).
- the communication unit 11 of the central electronic control unit 10 supplies the authentication key KB generated in step S102 to the communication module 20 (step S103).
- the communication unit 21 of the communication module 20 receives this authentication key KB.
- the processing unit 27 of the communication module 20 stores the received authentication key KB in the RAM 23 (step S104).
- the processing unit 17 of the central electronic control unit 10 generates an authentication key KB1 by encrypting the authentication key KB stored in the RAM 13 using the encryption key KA1 stored in the security module 15, and stores this authentication key KB1 in the non-volatile memory 14 (step S105).
- the processing unit 17 of the central electronic control unit 10 deletes the authentication key KB stored in the RAM 13 (step S106).
- the processing unit 27 of the communication module 20 generates an authentication key KB2 by encrypting the authentication key KB stored in the RAM 23 using the encryption key KA2 stored in the security module 25, and stores this authentication key KB2 in the non-volatile memory 24 (step S107).
- the processing unit 27 of the communication module 20 deletes the authentication key KB stored in the RAM 23 (step S108).
- the authentication key KB1 encrypted using the encryption key KA1 is stored in the non-volatile memory 14 of the central electronic control unit 10
- the authentication key KB2 encrypted using the encryption key KA2 is stored in the non-volatile memory 24 of the communication module 20.
- the central electronic control unit 10 and the communication module 20 can then use these authentication keys KB1 and KB2 to perform authentication processing. This operation is described below.
- FIG. 5 shows an example of a vehicle 9 when performing authentication processing using authentication keys KB1 and KB2.
- the communication module 20 of the vehicle 9 downloads this update software from the server 40.
- the central electronic control unit 10 and communication module 20 of the vehicle 9 then perform authentication processing using authentication keys KB1 and KB2, and if this authentication processing is successful, the central electronic control unit 10 updates the software of the electronic control unit 19 using this update software.
- Figures 6A and 6B show an example of authentication processing using authentication keys KB1 and KB2 in control system 1.
- the server 40 transmits update software to the communication module 20 of the vehicle 9 (step S201).
- the wireless communication unit 26 of the communication module 20 receives the update software.
- the communication unit 21 of the communication module 20 makes an authentication request to the central electronic control unit 10 (step S202).
- the communication unit 11 of the central electronic control unit 10 receives this authentication request.
- the processing unit 27 of the communication module 20 restricts access to the RAM 23 (step S203). This temporarily restricts, for example, access to the memory area of the RAM 23 from outside the communication module 20.
- step S204 the processing unit 17 of the central electronic control unit 10 restricts access to the RAM 13 (step S204). This temporarily restricts, for example, access to the memory area of the RAM 13 from outside the central electronic control unit 10.
- the processing unit 17 of the central electronic control unit 10 generates random number data including a multi-digit random number, and stores the generated random number data in the RAM 13 (step S205).
- the communication section 11 of the central electronic control unit 10 supplies this random number data to the communication module 20 (step S206).
- the communication section 11 of the communication module 20 receives this random number data.
- the processing unit 27 of the communication module 20 stores the random number data received in step S206 in the RAM 23 (step S207).
- the processing unit 27 of the communication module 20 generates an authentication key KB21 by decrypting the authentication key KB2 stored in the non-volatile memory 24 using the encryption key KA2 stored in the security module 25, and stores this authentication key KB21 in the RAM 13 (step S208).
- This authentication key KB21 is the same as the authentication key KB generated in step S102.
- the processing unit 27 of the communication module 20 uses this decrypted authentication key KB21 to encrypt the random number data stored in RAM 23 in step S207 (step S209).
- the processing unit 17 of the central electronic control unit 10 generates an authentication key KB11 by decrypting the authentication key KB1 stored in the non-volatile memory 14 using the encryption key KA1 stored in the security module 15, and stores this authentication key KB11 in the RAM 13 (step S210).
- This authentication key KB11 is the same as the authentication key KB generated in step S102.
- the processing unit 17 of the central electronic control unit 10 uses this decrypted authentication key KB11 to encrypt the random number data stored in the RAM 13 in step S205 (step S211).
- the communication unit 11 of the communication module 20 supplies the random number data encrypted in step S209 to the central electronic control unit 10 (step S212).
- the communication unit 11 of the central electronic control unit 10 receives this encrypted random number data.
- the processing unit 17 of the central electronic control unit 10 performs authentication processing by comparing the random number data encrypted in step S211 with the encrypted random number data received from the communication module 20 in step S212 (step S213). In other words, if these random number data are the same, this means that the authentication key KB21 used in the communication module 20 and the authentication key KB11 used in the central electronic control unit 10 are the same, so the processing unit 17 can perform authentication processing by comparing these random number data.
- the communication unit 11 of the central electronic control unit 10 notifies the communication module 20 of permission to update the software (step S214).
- the communication unit 11 of the communication module 20 receives this permission to update.
- the processing unit 27 of the communication module 20 deletes the authentication key KB21 and the random number data stored in the RAM 23 (step S215). Then, the processing unit 27 of the communication module 20 releases the access restriction on the RAM 23 imposed in step S203 (step S216). This allows access to the memory area of the RAM 23 from outside the communication module 20, for example.
- the processing unit 17 of the central electronic control unit 10 deletes the authentication key KB11 and the random number data stored in the RAM 13 (step S217). Then, the processing unit 17 of the central electronic control unit 10 releases the access restriction on the RAM 13 imposed in step S204 (step S218). This allows access to the memory area of the RAM 13 from outside the central electronic control unit 10, for example.
- the communication unit 21 of the communication module 20 supplies the update software received in step S201 to the central electronic control unit 10 (step S219).
- the communication unit 11 of the central electronic control unit 10 receives this update software.
- the processing unit 17 of the central electronic control unit 10 uses the update software received in step S220 to update the software of the electronic control unit 19 that is the target of the update (step S220).
- authentication key KB11 corresponds to a specific example of a "third authentication key” in one embodiment of the present disclosure.
- Authentication key KB21 corresponds to a specific example of a "fourth authentication key” in one embodiment of the present disclosure.
- control system 1 includes a central electronic control unit 10 having a first security circuit (security module 15) in which a first encryption key (encryption key KA1) is stored and in which external access is restricted, and a first memory circuit (memory section 12), and a communication module 20 having a second security circuit (security module 25) in which a second encryption key (encryption key KA2) is stored and in which external access is restricted, and a second memory circuit (memory section 22).
- first security circuit security module 15
- KA1 a first encryption key
- memory section 12 a first memory circuit
- communication module 20 having a second security circuit (security module 25) in which a second encryption key (encryption key KA2) is stored and in which external access is restricted
- second memory circuit memory section 22
- the central electronic control unit 10 is capable of generating an authentication key KB used in authentication processing between the central electronic control unit 10 and the communication module 20, and is capable of generating a first authentication key (authentication key KB1) by encrypting the authentication key KB with the first encryption key (encryption key KA1), and is capable of storing the first authentication key (authentication key KB1) in the first memory circuit (memory section 12).
- the central electronic control unit 10 is capable of supplying the generated authentication key KB to the communication module 20.
- the communication module 20 is capable of generating a second authentication key (authentication key KB2) by encrypting the authentication key KB supplied from the central electronic control unit 10 with a second encryption key (encryption key KA2), and is capable of storing the second authentication key (authentication key KB2) in a second memory circuit (memory unit 22). This makes it possible to improve convenience while also enhancing security.
- a method may be used in which the generated authentication key is stored in the security modules 15, 25.
- the diagnostic device 30 in order for the diagnostic device 30 to store the authentication key in the security module 15, it is necessary to use the encryption key KA1 stored in the security module 15. Therefore, the diagnostic device 30 needs to store this encryption key KA1.
- the diagnostic device 30 needs to manage the encryption keys KA1 of each of the multiple vehicles 9, which increases management costs and reduces convenience.
- an authentication key KB1 is generated by encrypting the authentication key KB using the encryption key KA1 stored in the security module 15, and this authentication key KB1 is stored in the storage unit 12.
- an authentication key KB2 is generated by encrypting the authentication key KB using the encryption key KA2 stored in the security module 25, and this authentication key KB2 is stored in the storage unit 22.
- the diagnostic device 30 does not need to store the encryption keys KA1 and KA2, which makes it possible to reduce management costs and improve convenience.
- the central electronic control unit 10 can temporarily store the generated authentication key (authentication key KB) in the first memory circuit (memory section 12), and after storing the first authentication key (authentication key KB1) in the first memory circuit (memory section 12), the authentication key (authentication key KB) stored in the first memory circuit (memory section 12) can be deleted.
- the communication module 20 can temporarily store the authentication key (authentication key KB) supplied from the central electronic control unit 10 in the second memory circuit (memory section 22), and after storing the second authentication key (authentication key KB2) in the second memory circuit (memory section 22), the authentication key (authentication key KB) stored in the second memory circuit (memory section 22) can be deleted.
- the memory unit 12 stores the encrypted authentication key KB1 and deletes the unencrypted authentication key KB
- the memory unit 22 stores the encrypted authentication key KB2 and deletes the unencrypted authentication key KB, thereby improving security.
- the present invention includes a central electronic control unit having a first security circuit in which a first encryption key is stored and external access is restricted, and a first storage circuit, and a communication module having a second security circuit in which a second encryption key is stored and external access is restricted, and a second storage circuit.
- the central electronic control unit is capable of generating an authentication key used in authentication processing between the central electronic control unit and the communication module, and is capable of generating the first authentication key by encrypting the authentication key with the first encryption key, and is capable of storing the first authentication key in the first storage circuit.
- the central electronic control unit is capable of supplying the generated authentication key to the communication module.
- the communication module is capable of generating a second authentication key by encrypting the authentication key supplied from the central electronic control unit with the second encryption key, and is capable of storing the second authentication key in the second storage circuit. This makes it possible to improve convenience while enhancing security.
- the central electronic control unit is capable of temporarily storing the generated authentication key in the first storage circuit, and after storing the first authentication key in the first storage circuit, the authentication key stored in the first storage circuit can be deleted.
- the communication module is capable of temporarily storing the authentication key supplied from the central electronic control unit in the second storage circuit, and after storing the second authentication key in the second storage circuit, the authentication key stored in the second storage circuit can be deleted. This can improve security.
- the central electronic control unit is capable of generating an authentication key based on instructions from the diagnostic device, thereby improving security.
- the central electronic control unit is capable of generating a third authentication key by decrypting the first authentication key with the first encryption key, and is capable of performing the first processing based on the third authentication key.
- the communication module is capable of generating a fourth authentication key by decrypting the second authentication key with the second encryption key, and is capable of performing the second processing based on the fourth authentication key. The central electronic control unit and the communication module then perform the authentication processing by performing the first processing and the second processing. This can enhance security.
- the authentication process is performed using the method shown in Figures 6A and 6B, but this is not limited to this, and any authentication method may be used as long as it uses the authentication key KB1 stored in the memory unit 22 of the central electronic control unit 10 and the authentication key KB2 stored in the memory unit 22 of the communication module 20.
- the central electronic control unit 10 and the communication module 20 perform the authentication process, but this is not limited to this, and various other circuits in the vehicle 9 may perform the authentication process.
- the technology is applied to a vehicle 9, but the technology is not limited to this and may be applied to vehicles other than a vehicle 9.
- the first control device is capable of generating an authentication key used in an authentication process between the first control device and the second control device, is capable of generating a first authentication key by encrypting the authentication key with the first encryption key, and is capable of storing the first authentication key in the first storage circuit;
- the first control device is capable of supplying the generated authentication key to the second control device,
- the second control device is capable of generating a second authentication key by encrypting the authentication key supplied from the first control device with the second encryption key, and is capable of storing the second authentication key in the second memory circuit.
- the first control device is capable of temporarily storing the generated authentication key in the first storage circuit, and after storing the first authentication key in the first storage circuit, is capable of deleting the authentication key stored in the first storage circuit;
- the second control device is capable of temporarily storing the authentication key supplied from the first control device in the second memory circuit, and is capable of deleting the authentication key stored in the second memory circuit after storing the second authentication key in the second memory circuit.
- the first control device is capable of generating a third authentication key by decrypting the first authentication key by using the first encryption key, and is capable of performing a first process based on the third authentication key;
- the second control device is capable of generating a fourth authentication key by decrypting the second authentication key by using the second encryption key, and is capable of performing a second process based on the fourth authentication key;
- the control system according to any one of (1) to (3), wherein the first control device and the second control device perform the authentication process by performing the first process and the second process.
- the first control device includes an electronic control unit for controlling a vehicle.
- the at least one processor may be configured to execute all or a portion of the various functions of the processing unit 17 shown in FIG. 2 by reading instructions from at least one non-transitory and tangible computer-readable medium.
- Such media may take a variety of forms, including, but not limited to, various magnetic media such as hard disks, various optical media such as CDs or DVDs, and various semiconductor memories (i.e., semiconductor circuits) such as volatile or non-volatile memories. Volatile memories may include DRAM and SRAM.
- Non-volatile memories may include ROM and NVRAM.
- An ASIC is an integrated circuit (IC) specialized to execute all or a portion of the various functions of the processing unit 17 shown in FIG. 2.
- An FPGA is an integrated circuit designed to be configurable after manufacture to execute all or a portion of the various functions of the processing unit 17 shown in FIG. 2. Note that, although the above description has been given using the processing unit 17 as an example, this is not limited to this, and the same applies to the processing unit 27.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Lock And Its Accessories (AREA)
Abstract
Description
[構成例]
図1は、一実施の形態に係る制御システム(制御システム1)の一構成例を表すものである。この制御システム1は、車両9に設けられる。車両9は、自動車などの車両である。制御システム1は、セントラル電子制御ユニット(ECU:Electronic Control Unit)10と、複数の電子制御ユニット19と、通信モジュール20とを有している。
続いて、本実施の形態の制御システム1の動作および作用について説明する。
まず、図1,2を参照して、制御システム1の動作を説明する。セントラル電子制御ユニット10では、通信部11は、CAN9を介して、通信モジュール20と通信を行う。記憶部12は、データを記憶する。セキュリティモジュール15は、データをセキュアなメモリ領域に記憶する。セキュリティモジュール15は、暗号鍵KA1を記憶している。外部通信部16は、例えば、車両9に不具合がある場合に、通信ケーブルを用いて、診断装置30と通信を行う。処理部17は、セントラル電子制御ユニット10の動作を制御する。
以下に、制御システム1の動作について、詳細に説明する。
以上のように本実施の形態では、第1の暗号鍵が記憶され、外部からのアクセスが制限された第1のセキュリティ回路と、第1の記憶回路とを有するセントラル電子制御ユニットと、第2の暗号鍵が記憶され、外部からのアクセスが制限された第2のセキュリティ回路と、第2の記憶回路とを有する通信モジュールとを備えるようにした。セントラル電子制御ユニットは、セントラル電子制御ユニットおよび通信モジュールの間の認証処理に使用される認証鍵を生成可能であり、認証鍵を第1の暗号鍵を用いて暗号化することにより第1の認証鍵を生成可能であり、第1の認証鍵を第1の記憶回路に記憶させることが可能であるようにした。セントラル電子制御ユニットは、生成した認証鍵を通信モジュールに供給可能なようにした。通信モジュールは、セントラル電子制御ユニットから供給された認証鍵を第2の暗号鍵を用いて暗号化することにより第2の認証鍵を生成可能であり、第2の認証鍵を第2の記憶回路に記憶させることが可能なようにした。これにより、セキュリティを高めつつ、利便性を高めることができる。
第1の暗号鍵が記憶され、外部からのアクセスが制限された第1のセキュリティ回路と、第1の記憶回路とを有する第1の制御装置と、
第2の暗号鍵が記憶され、外部からのアクセスが制限された第2のセキュリティ回路と、第2の記憶回路とを有する第2の制御装置と
を備え、
前記第1の制御装置は、前記第1の制御装置および前記第2の制御装置の間の認証処理に使用される認証鍵を生成可能であり、前記認証鍵を前記第1の暗号鍵を用いて暗号化することにより第1の認証鍵を生成可能であり、前記第1の認証鍵を前記第1の記憶回路に記憶させることが可能であり、
前記第1の制御装置は、生成した前記認証鍵を前記第2の制御装置に供給可能であり、
前記第2の制御装置は、前記第1の制御装置から供給された前記認証鍵を前記第2の暗号鍵を用いて暗号化することにより第2の認証鍵を生成可能であり、前記第2の認証鍵を前記第2の記憶回路に記憶させることが可能である
制御システム。
(2)
前記第1の制御装置は、生成した前記認証鍵を前記第1の記憶回路に一旦記憶させることが可能であり、前記第1の認証鍵を前記第1の記憶回路に記憶させた後に、前記第1の記憶回路に記憶された前記認証鍵を削除可能であり、
前記第2の制御装置は、前記第1の制御装置から供給された前記認証鍵を前記第2の記憶回路に一旦記憶させることが可能であり、前記第2の認証鍵を前記第2の記憶回路に記憶させた後に、前記第2の記憶回路に記憶された前記認証鍵を削除可能である
前記(1)に記載の制御システム。
(3)
前記第1の制御装置は、外部装置からの指示に基づいて前記認証鍵を生成可能である
前記(1)または(2)に記載の制御システム。
(4)
前記第1の制御装置は、前記第1の認証鍵を前記第1の暗号鍵を用いて復号することにより第3の認証鍵を生成可能であり、前記第3の認証鍵に基づいて第1の処理を行うことが可能であり、
前記第2の制御装置は、前記第2の認証鍵を前記第2の暗号鍵を用いて復号することにより第4の認証鍵を生成可能であり、前記第4の認証鍵に基づいて第2の処理を行うことが可能であり、
前記第1の制御装置および前記第2の制御装置は、前記第1の処理および前記第2の処理を行うことにより、前記認証処理を行う
前記(1)から(3)のいずれかに記載の制御システム。
(5)
請求項1から請求項4のいずれか一項に記載の制御システムを備え、
前記第1の制御装置は、車両を制御する電子制御ユニットを含む
車両。
Claims (5)
- 第1の暗号鍵が記憶され、外部からのアクセスが制限された第1のセキュリティ回路と、第1の記憶回路とを有する第1の制御装置と、
第2の暗号鍵が記憶され、外部からのアクセスが制限された第2のセキュリティ回路と、第2の記憶回路とを有する第2の制御装置と
を備え、
前記第1の制御装置は、前記第1の制御装置および前記第2の制御装置の間の認証処理に使用される認証鍵を生成可能であり、前記認証鍵を前記第1の暗号鍵を用いて暗号化することにより第1の認証鍵を生成可能であり、前記第1の認証鍵を前記第1の記憶回路に記憶させることが可能であり、
前記第1の制御装置は、生成した前記認証鍵を前記第2の制御装置に供給可能であり、
前記第2の制御装置は、前記第1の制御装置から供給された前記認証鍵を前記第2の暗号鍵を用いて暗号化することにより第2の認証鍵を生成可能であり、前記第2の認証鍵を前記第2の記憶回路に記憶させることが可能である
制御システム。 - 前記第1の制御装置は、生成した前記認証鍵を前記第1の記憶回路に一旦記憶させることが可能であり、前記第1の認証鍵を前記第1の記憶回路に記憶させた後に、前記第1の記憶回路に記憶された前記認証鍵を削除可能であり、
前記第2の制御装置は、前記第1の制御装置から供給された前記認証鍵を前記第2の記憶回路に一旦記憶させることが可能であり、前記第2の認証鍵を前記第2の記憶回路に記憶させた後に、前記第2の記憶回路に記憶された前記認証鍵を削除可能である
請求項1に記載の制御システム。 - 前記第1の制御装置は、外部装置からの指示に基づいて前記認証鍵を生成可能である
請求項1に記載の制御システム。 - 前記第1の制御装置は、前記第1の認証鍵を前記第1の暗号鍵を用いて復号することにより第3の認証鍵を生成可能であり、前記第3の認証鍵に基づいて第1の処理を行うことが可能であり、
前記第2の制御装置は、前記第2の認証鍵を前記第2の暗号鍵を用いて復号することにより第4の認証鍵を生成可能であり、前記第4の認証鍵に基づいて第2の処理を行うことが可能であり、
前記第1の制御装置および前記第2の制御装置は、前記第1の処理および前記第2の処理を行うことにより、前記認証処理を行う
請求項1に記載の制御システム。 - 請求項1から請求項4のいずれか一項に記載の制御システムを備え、
前記第1の制御装置は、車両を制御する電子制御ユニットを含む
車両。
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2023/011933 WO2024201600A1 (ja) | 2023-03-24 | 2023-03-24 | 制御システムおよび車両 |
| CN202380045863.8A CN119343890A (zh) | 2023-03-24 | 2023-03-24 | 控制系统以及车辆 |
| JP2025509237A JPWO2024201600A1 (ja) | 2023-03-24 | 2023-03-24 | |
| US18/979,893 US20250112775A1 (en) | 2023-03-24 | 2024-12-13 | Control system and vehicle |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2023/011933 WO2024201600A1 (ja) | 2023-03-24 | 2023-03-24 | 制御システムおよび車両 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US18/979,893 Continuation US20250112775A1 (en) | 2023-03-24 | 2024-12-13 | Control system and vehicle |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024201600A1 true WO2024201600A1 (ja) | 2024-10-03 |
Family
ID=92904164
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2023/011933 Ceased WO2024201600A1 (ja) | 2023-03-24 | 2023-03-24 | 制御システムおよび車両 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20250112775A1 (ja) |
| JP (1) | JPWO2024201600A1 (ja) |
| CN (1) | CN119343890A (ja) |
| WO (1) | WO2024201600A1 (ja) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2016075865A1 (ja) * | 2014-11-12 | 2016-05-19 | パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ | 更新管理方法、更新管理装置及び制御プログラム |
| JP2017130908A (ja) * | 2016-01-18 | 2017-07-27 | Kddi株式会社 | 車載コンピュータシステム、車両、鍵生成装置、管理方法、鍵生成方法、及びコンピュータプログラム |
| JP2018196080A (ja) * | 2017-05-22 | 2018-12-06 | 株式会社デンソー | 電子制御装置および電子制御装置における鍵登録方法 |
| JP2021135817A (ja) * | 2020-02-27 | 2021-09-13 | 日立Astemo株式会社 | 車載機器の電子制御装置 |
-
2023
- 2023-03-24 CN CN202380045863.8A patent/CN119343890A/zh active Pending
- 2023-03-24 WO PCT/JP2023/011933 patent/WO2024201600A1/ja not_active Ceased
- 2023-03-24 JP JP2025509237A patent/JPWO2024201600A1/ja active Pending
-
2024
- 2024-12-13 US US18/979,893 patent/US20250112775A1/en active Pending
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2016075865A1 (ja) * | 2014-11-12 | 2016-05-19 | パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ | 更新管理方法、更新管理装置及び制御プログラム |
| JP2017130908A (ja) * | 2016-01-18 | 2017-07-27 | Kddi株式会社 | 車載コンピュータシステム、車両、鍵生成装置、管理方法、鍵生成方法、及びコンピュータプログラム |
| JP2018196080A (ja) * | 2017-05-22 | 2018-12-06 | 株式会社デンソー | 電子制御装置および電子制御装置における鍵登録方法 |
| JP2021135817A (ja) * | 2020-02-27 | 2021-09-13 | 日立Astemo株式会社 | 車載機器の電子制御装置 |
Non-Patent Citations (1)
| Title |
|---|
| KENJI SUGASHIMA, KENGO OKA, CAMILLE VIOMME: "4F2-4 Approaches for Secure and Efficient In-Vehicle Key Management", PROCEEDINGS OF THE 2016 SYMPOSIUM ON CRYPTOGRAPHY AND INFORMATION SECURITY; JANUARY 19–22, 2016, IEICE TECHNICAL COMMITTEE ON INFORMATION SECURITY (ISEC), JP, 19 January 2016 (2016-01-19) - 22 January 2016 (2016-01-22), JP, pages 1 - 6, XP009557876 * |
Also Published As
| Publication number | Publication date |
|---|---|
| US20250112775A1 (en) | 2025-04-03 |
| JPWO2024201600A1 (ja) | 2024-10-03 |
| CN119343890A (zh) | 2025-01-21 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11182485B2 (en) | In-vehicle apparatus for efficient reprogramming and controlling method thereof | |
| JP6173411B2 (ja) | 管理装置、車両、管理システム、管理方法、及びコンピュータプログラム | |
| CN103685214B (zh) | 用于汽车电子控制单元的安全访问方法 | |
| JP6228093B2 (ja) | システム | |
| CN115066868B (zh) | 车辆安全系统 | |
| US20190028267A1 (en) | In-vehicle computer system, vehicle, key generation device, management method, key generation method, and computer program | |
| US12347243B2 (en) | Method and system for replacing vehicle parts using in-vehicle network based on vehicle ethernet | |
| CN107925568A (zh) | 管理装置、管理系统、密钥生成装置、密钥生成系统、密钥管理系统、车辆、管理方法、密钥生成方法以及计算机程序 | |
| WO2016152556A1 (ja) | 管理装置、車両、管理方法、及びコンピュータプログラム | |
| US11748275B2 (en) | Method for securely updating control units | |
| WO2016093368A1 (ja) | 管理装置、鍵生成装置、車両、メンテナンスツール、管理システム、管理方法、及びコンピュータプログラム | |
| JP2018093370A (ja) | 車載電子制御装置、車載電子制御システム、中継装置 | |
| EP4305835B1 (en) | Method and system for performing identity checks in a distributed system | |
| JP6860464B2 (ja) | システム及び管理方法 | |
| WO2020090418A1 (ja) | 電子制御装置、電子制御装置のリプログラミング方法 | |
| US20250112775A1 (en) | Control system and vehicle | |
| CN119892342A (zh) | 一种硬件安全模块的刷写方法、装置、设备、介质及产品 | |
| JP6926671B2 (ja) | 電子制御装置および電子制御装置における鍵登録方法 | |
| JPWO2024201600A5 (ja) | ||
| JP7511492B2 (ja) | 自動車用電子制御装置 | |
| JP2022150140A (ja) | 車両プログラム更新管理システム、リプログラミング端末、車両プログラム更新管理方法 | |
| US12634262B2 (en) | Method for controlling access of external devices to in-vehicle network and gateway therefor | |
| US11804981B2 (en) | Method and apparatus for providing an individually secure system to multiple distrusting parties | |
| CN111142902A (zh) | 处理器的升级固件保护方法、装置及车辆 | |
| CN114329506B (zh) | 具有增强的安全性的系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23930241 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202380045863.8 Country of ref document: CN |
|
| WWP | Wipo information: published in national office |
Ref document number: 202380045863.8 Country of ref document: CN |
|
| ENP | Entry into the national phase |
Ref document number: 2025509237 Country of ref document: JP Kind code of ref document: A |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2025509237 Country of ref document: JP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 23930241 Country of ref document: EP Kind code of ref document: A1 |