WO2024201600A1 - 制御システムおよび車両 - Google Patents

制御システムおよび車両 Download PDF

Info

Publication number
WO2024201600A1
WO2024201600A1 PCT/JP2023/011933 JP2023011933W WO2024201600A1 WO 2024201600 A1 WO2024201600 A1 WO 2024201600A1 JP 2023011933 W JP2023011933 W JP 2023011933W WO 2024201600 A1 WO2024201600 A1 WO 2024201600A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication key
control device
authentication
key
electronic control
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2023/011933
Other languages
English (en)
French (fr)
Inventor
久太郎 飯波
優祐 小松
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Subaru Corp
Original Assignee
Subaru Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Subaru Corp filed Critical Subaru Corp
Priority to PCT/JP2023/011933 priority Critical patent/WO2024201600A1/ja
Priority to CN202380045863.8A priority patent/CN119343890A/zh
Priority to JP2025509237A priority patent/JPWO2024201600A1/ja
Publication of WO2024201600A1 publication Critical patent/WO2024201600A1/ja
Priority to US18/979,893 priority patent/US20250112775A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0822Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0894Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0894Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
    • H04L9/0897Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage involving additional devices, e.g. trusted platform module [TPM], smartcard or USB
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/84Vehicles

Definitions

  • This disclosure relates to a control system that performs authentication processing using an authentication key, and a vehicle equipped with such a control system.
  • Patent Document 1 discloses technology for managing security access keys in a vehicle master device.
  • a control system includes a first control device and a second control device.
  • the first control device has a first security circuit in which a first encryption key is stored and in which external access is restricted, and a first storage circuit.
  • the second control device has a second security circuit in which a second encryption key is stored and in which external access is restricted, and a second storage circuit.
  • the first control device is capable of generating an authentication key used in authentication processing between the first control device and the second control device, and is capable of generating the first authentication key by encrypting the authentication key with the first encryption key, and is capable of storing the first authentication key in the first storage circuit.
  • the first control device is capable of supplying the generated authentication key to the second control device.
  • the second control device is capable of generating a second authentication key by encrypting the authentication key supplied from the first control device with the second encryption key, and is capable of storing the second authentication key in the second storage circuit.
  • a vehicle according to one embodiment of the present disclosure is equipped with the above-described control system.
  • the first control device includes an electronic control unit that controls the vehicle.
  • FIG. 1 is an explanatory diagram illustrating an example configuration of a control system according to an embodiment of the present disclosure.
  • FIG. 2 is a block diagram showing an example of the configuration of the central electronic control unit and the communication module shown in FIG.
  • FIG. 3 is an explanatory diagram illustrating an example of an operation of the control system shown in FIG.
  • FIG. 4 is a sequence diagram showing an example of an operation of the control system shown in FIG.
  • FIG. 5 is an explanatory diagram showing another operation example of the control system shown in FIG.
  • FIG. 6A is a sequence diagram illustrating an example of an operation of the control system illustrated in FIG.
  • FIG. 6B is another sequence diagram illustrating an example of an operation of the control system illustrated in FIG.
  • Control system 1 shows an example of a configuration of a control system (control system 1) according to an embodiment.
  • the control system 1 is provided in a vehicle 9.
  • the vehicle 9 is a vehicle such as an automobile.
  • the control system 1 has a central electronic control unit (ECU: Electronic Control Unit) 10, a plurality of electronic control units 19, and a communication module 20.
  • ECU Electronic Control Unit
  • the central electronic control unit 10 is configured to control the operation of the vehicle 9 by controlling the operation of the multiple electronic control units 19.
  • the central electronic control unit 10 is also connected to a diagnostic device 30 (described below) outside the vehicle, for example, via a communication cable, and is capable of communicating with this diagnostic device 30.
  • the central electronic control unit 10 is also connected to a CAN (Controller Area Network) 9, and is configured to communicate with a communication module 20 via the CAN 9.
  • CAN Controller Area Network
  • the multiple electronic control units 19 are configured to control the operation of each device in the vehicle 9 based on instructions from the central electronic control unit 10.
  • the multiple electronic control units 19 include, for example, an electronic control unit 19 that controls the powertrain such as the engine, an electronic control unit 19 that controls the steering device and the braking device, an electronic control unit 19 that controls the interior and exterior lighting, doors, windshield wipers, etc., an electronic control unit 19 that controls the driving assistance system, etc.
  • the communication module 20 is configured to communicate with a base station by performing mobile communications such as 4G (4th Generation) or 5G (5th Generation). This allows the communication module 20 to communicate with a server 40 (described below) connected to the Internet via the base station.
  • the communication module 20 is also connected to a CAN 9, and communicates with the central electronic control unit 10 via the CAN 9.
  • authentication processing can be performed between the central electronic control unit 10 and the communication module 20.
  • the central electronic control unit 10 for example, an encrypted authentication key KB1 is stored in a non-volatile memory 14 described below
  • the communication module 20 for example, an encrypted authentication key KB2 is stored in a non-volatile memory 24 described below.
  • the central electronic control unit 10 and the communication module 20 are capable of performing authentication processing using these authentication keys KB1 and KB2.
  • FIG. 2 shows an example configuration of the central electronic control unit 10 and the communication module 20.
  • the central electronic control unit 10 has a communication unit 11, a memory unit 12, a security module 15, an external communication unit 16, and a processing unit 17.
  • the communication unit 11 is configured to communicate with the communication module 20 via the CAN 9.
  • the memory unit 12 is configured to store data.
  • the memory unit 12 has a RAM 13 and a non-volatile memory 14.
  • the RAM 13 is configured, for example, using DRAM (Dynamic Random Access Memory) and is configured to temporarily store the processing contents of the central electronic control unit 10.
  • the non-volatile memory 14 is configured, for example, using flash memory, and is configured to store software executed by the central electronic control unit 10 and an encrypted authentication key KB1.
  • the memory areas of the RAM 13 and the non-volatile memory 14 can be accessed from outside the central electronic control unit 10 via the communication unit 11 and the processing unit 17.
  • the security module 15 is a so-called HSM (Hardware Security Module), and is configured to store data in a secure memory area.
  • the security module 15 stores an encryption key KA1.
  • the security module 15 is configured to restrict access from outside the central electronic control unit 10. In this way, the security module 15 protects the stored data so that it cannot be easily rewritten and so that the stored data is not leaked.
  • the external communication unit 16 is configured to communicate with a diagnostic device 30 (described below) using a communication cable, for example, when a malfunction occurs in the vehicle 9.
  • the communication module 20 has a communication unit 21, a memory unit 22, a security module 25, a wireless communication unit 26, and a processing unit 27.
  • the storage unit 22 is configured to store data.
  • the storage unit 22 has a RAM 23 and a non-volatile memory 24.
  • the RAM 23 is configured, for example, using a DRAM, and is configured to temporarily store the processing contents of the communication module 20.
  • the non-volatile memory 24 is configured, for example, using a flash memory, and is configured to store the software executed by the communication module 20 and the encrypted authentication key KB2.
  • the memory areas of the RAM 23 and the non-volatile memory 24 can be accessed from outside the communication module 20 via the communication unit 21 and the processing unit 27.
  • the security module 25 is a so-called HSM, and is configured to store data in a secure memory area.
  • the encryption key KA2 is stored in the security module 25.
  • the security module 25 is configured to restrict access from outside the communication module 20. In this way, the security module 25 protects the stored data so that it cannot be easily rewritten and so that the stored data is not leaked.
  • the wireless communication unit 26 is configured to communicate with a base station, for example, by performing mobile communications such as 4G or 5G. This allows the wireless communication unit 26 to communicate with a server 40 (described later) connected to the Internet via the base station.
  • the wireless communication unit 26 is configured to be able to download, for example, update software from the server 40.
  • the processing unit 27 is configured, for example, using one or more processors, and is configured to control the operation of the communication module 20 by executing software.
  • the central electronic control unit 10 In this control system 1, the central electronic control unit 10 generates an authentication key KB based on instructions from the diagnostic device 30. The central electronic control unit 10 then transmits this authentication key KB to the communication module 20. The central electronic control unit 10 generates an authentication key KB1 by encrypting this authentication key KB using an encryption key KA1, and stores this authentication key KB1 in the non-volatile memory 14. Similarly, the communication module 20 generates an authentication key KB2 by encrypting this authentication key KB using an encryption key KA2, and stores this authentication key KB2 in the non-volatile memory 24. Thereafter, the central electronic control unit 10 and the communication module 20 are able to perform authentication processing using the authentication keys KB1 and KB2 stored in the non-volatile memories 14 and 24.
  • the central electronic control unit 10 corresponds to a specific example of a "first control device” in one embodiment of the present disclosure.
  • the encryption key KA1 corresponds to a specific example of a "first encryption key” in one embodiment of the present disclosure.
  • the security module 15 corresponds to a specific example of a "first security circuit” in one embodiment of the present disclosure.
  • the memory unit 12 corresponds to a specific example of a "first memory circuit” in one embodiment of the present disclosure.
  • the communication module 20 corresponds to a specific example of a "second control device” in one embodiment of the present disclosure.
  • the encryption key KA2 corresponds to a specific example of a "second encryption key” in one embodiment of the present disclosure.
  • the security module 25 corresponds to a specific example of a "second security circuit” in one embodiment of the present disclosure.
  • the memory unit 22 corresponds to a specific example of a "second memory circuit” in one embodiment of the present disclosure.
  • the authentication key KB corresponds to a specific example of an "authentication key” in one embodiment of the present disclosure.
  • the authentication key KB1 corresponds to a specific example of a "first authentication key” in one embodiment of the present disclosure.
  • Authentication key KB2 corresponds to a specific example of a "second authentication key” in one embodiment of the present disclosure.
  • the communication unit 11 communicates with the communication module 20 via the CAN 9.
  • the memory unit 12 stores data.
  • the security module 15 stores the data in a secure memory area.
  • the security module 15 stores an encryption key KA1.
  • the external communication unit 16 communicates with the diagnostic device 30 using a communication cable, for example, when a malfunction occurs in the vehicle 9.
  • the processing unit 17 controls the operation of the central electronic control unit 10.
  • the communication unit 21 communicates with the central electronic control unit 10 via the CAN 9.
  • the memory unit 22 stores data.
  • the security module 25 stores data in a secure memory area.
  • the security module 25 stores an encryption key KA2.
  • the wireless communication unit 26 performs mobile communication to communicate with a server 40 connected to the Internet via a base station.
  • the wireless communication unit 26 can, for example, download update software from the server 40.
  • the processing unit 27 controls the operation of the communication module 20.
  • the control system 1 registers the authentication keys KB1 and KB2 used in the authentication process between the central electronic control unit 10 and the communication module 20. This operation is described in detail below.
  • FIG. 3 shows an example of a vehicle 9 in which authentication keys KB1 and KB2 are stored.
  • the owner of the vehicle 9 brings the vehicle 9 to a dealer.
  • a dealer worker connects a diagnostic device 30 to the central electronic control unit 10 of the vehicle 9 via a communication cable 8, and the diagnostic device 30 diagnoses the vehicle 9.
  • the diagnostic device 30 detects a malfunction of the central electronic control unit 10.
  • the dealer worker replaces the central electronic control unit 10.
  • the control system 1 registers the authentication keys KB1 and KB2 used in the authentication process between the central electronic control unit 10 and the communication module 20 based on instructions from the diagnostic device 30.
  • FIG. 4 shows an example of the registration process for authentication keys KB1 and KB2 in the control system 1.
  • the diagnostic device 30 requests the central electronic control unit 10 of the vehicle 9 to register an authentication key (step S101).
  • the external communication unit 16 of the central electronic control unit 10 receives this registration request.
  • the processing unit 17 of the central electronic control unit 10 generates an authentication key KB based on a request to register the authentication key from the diagnostic device 30, and stores this authentication key KB in the RAM 13 (step S102).
  • the communication unit 11 of the central electronic control unit 10 supplies the authentication key KB generated in step S102 to the communication module 20 (step S103).
  • the communication unit 21 of the communication module 20 receives this authentication key KB.
  • the processing unit 27 of the communication module 20 stores the received authentication key KB in the RAM 23 (step S104).
  • the processing unit 17 of the central electronic control unit 10 generates an authentication key KB1 by encrypting the authentication key KB stored in the RAM 13 using the encryption key KA1 stored in the security module 15, and stores this authentication key KB1 in the non-volatile memory 14 (step S105).
  • the processing unit 17 of the central electronic control unit 10 deletes the authentication key KB stored in the RAM 13 (step S106).
  • the processing unit 27 of the communication module 20 generates an authentication key KB2 by encrypting the authentication key KB stored in the RAM 23 using the encryption key KA2 stored in the security module 25, and stores this authentication key KB2 in the non-volatile memory 24 (step S107).
  • the processing unit 27 of the communication module 20 deletes the authentication key KB stored in the RAM 23 (step S108).
  • the authentication key KB1 encrypted using the encryption key KA1 is stored in the non-volatile memory 14 of the central electronic control unit 10
  • the authentication key KB2 encrypted using the encryption key KA2 is stored in the non-volatile memory 24 of the communication module 20.
  • the central electronic control unit 10 and the communication module 20 can then use these authentication keys KB1 and KB2 to perform authentication processing. This operation is described below.
  • FIG. 5 shows an example of a vehicle 9 when performing authentication processing using authentication keys KB1 and KB2.
  • the communication module 20 of the vehicle 9 downloads this update software from the server 40.
  • the central electronic control unit 10 and communication module 20 of the vehicle 9 then perform authentication processing using authentication keys KB1 and KB2, and if this authentication processing is successful, the central electronic control unit 10 updates the software of the electronic control unit 19 using this update software.
  • Figures 6A and 6B show an example of authentication processing using authentication keys KB1 and KB2 in control system 1.
  • the server 40 transmits update software to the communication module 20 of the vehicle 9 (step S201).
  • the wireless communication unit 26 of the communication module 20 receives the update software.
  • the communication unit 21 of the communication module 20 makes an authentication request to the central electronic control unit 10 (step S202).
  • the communication unit 11 of the central electronic control unit 10 receives this authentication request.
  • the processing unit 27 of the communication module 20 restricts access to the RAM 23 (step S203). This temporarily restricts, for example, access to the memory area of the RAM 23 from outside the communication module 20.
  • step S204 the processing unit 17 of the central electronic control unit 10 restricts access to the RAM 13 (step S204). This temporarily restricts, for example, access to the memory area of the RAM 13 from outside the central electronic control unit 10.
  • the processing unit 17 of the central electronic control unit 10 generates random number data including a multi-digit random number, and stores the generated random number data in the RAM 13 (step S205).
  • the communication section 11 of the central electronic control unit 10 supplies this random number data to the communication module 20 (step S206).
  • the communication section 11 of the communication module 20 receives this random number data.
  • the processing unit 27 of the communication module 20 stores the random number data received in step S206 in the RAM 23 (step S207).
  • the processing unit 27 of the communication module 20 generates an authentication key KB21 by decrypting the authentication key KB2 stored in the non-volatile memory 24 using the encryption key KA2 stored in the security module 25, and stores this authentication key KB21 in the RAM 13 (step S208).
  • This authentication key KB21 is the same as the authentication key KB generated in step S102.
  • the processing unit 27 of the communication module 20 uses this decrypted authentication key KB21 to encrypt the random number data stored in RAM 23 in step S207 (step S209).
  • the processing unit 17 of the central electronic control unit 10 generates an authentication key KB11 by decrypting the authentication key KB1 stored in the non-volatile memory 14 using the encryption key KA1 stored in the security module 15, and stores this authentication key KB11 in the RAM 13 (step S210).
  • This authentication key KB11 is the same as the authentication key KB generated in step S102.
  • the processing unit 17 of the central electronic control unit 10 uses this decrypted authentication key KB11 to encrypt the random number data stored in the RAM 13 in step S205 (step S211).
  • the communication unit 11 of the communication module 20 supplies the random number data encrypted in step S209 to the central electronic control unit 10 (step S212).
  • the communication unit 11 of the central electronic control unit 10 receives this encrypted random number data.
  • the processing unit 17 of the central electronic control unit 10 performs authentication processing by comparing the random number data encrypted in step S211 with the encrypted random number data received from the communication module 20 in step S212 (step S213). In other words, if these random number data are the same, this means that the authentication key KB21 used in the communication module 20 and the authentication key KB11 used in the central electronic control unit 10 are the same, so the processing unit 17 can perform authentication processing by comparing these random number data.
  • the communication unit 11 of the central electronic control unit 10 notifies the communication module 20 of permission to update the software (step S214).
  • the communication unit 11 of the communication module 20 receives this permission to update.
  • the processing unit 27 of the communication module 20 deletes the authentication key KB21 and the random number data stored in the RAM 23 (step S215). Then, the processing unit 27 of the communication module 20 releases the access restriction on the RAM 23 imposed in step S203 (step S216). This allows access to the memory area of the RAM 23 from outside the communication module 20, for example.
  • the processing unit 17 of the central electronic control unit 10 deletes the authentication key KB11 and the random number data stored in the RAM 13 (step S217). Then, the processing unit 17 of the central electronic control unit 10 releases the access restriction on the RAM 13 imposed in step S204 (step S218). This allows access to the memory area of the RAM 13 from outside the central electronic control unit 10, for example.
  • the communication unit 21 of the communication module 20 supplies the update software received in step S201 to the central electronic control unit 10 (step S219).
  • the communication unit 11 of the central electronic control unit 10 receives this update software.
  • the processing unit 17 of the central electronic control unit 10 uses the update software received in step S220 to update the software of the electronic control unit 19 that is the target of the update (step S220).
  • authentication key KB11 corresponds to a specific example of a "third authentication key” in one embodiment of the present disclosure.
  • Authentication key KB21 corresponds to a specific example of a "fourth authentication key” in one embodiment of the present disclosure.
  • control system 1 includes a central electronic control unit 10 having a first security circuit (security module 15) in which a first encryption key (encryption key KA1) is stored and in which external access is restricted, and a first memory circuit (memory section 12), and a communication module 20 having a second security circuit (security module 25) in which a second encryption key (encryption key KA2) is stored and in which external access is restricted, and a second memory circuit (memory section 22).
  • first security circuit security module 15
  • KA1 a first encryption key
  • memory section 12 a first memory circuit
  • communication module 20 having a second security circuit (security module 25) in which a second encryption key (encryption key KA2) is stored and in which external access is restricted
  • second memory circuit memory section 22
  • the central electronic control unit 10 is capable of generating an authentication key KB used in authentication processing between the central electronic control unit 10 and the communication module 20, and is capable of generating a first authentication key (authentication key KB1) by encrypting the authentication key KB with the first encryption key (encryption key KA1), and is capable of storing the first authentication key (authentication key KB1) in the first memory circuit (memory section 12).
  • the central electronic control unit 10 is capable of supplying the generated authentication key KB to the communication module 20.
  • the communication module 20 is capable of generating a second authentication key (authentication key KB2) by encrypting the authentication key KB supplied from the central electronic control unit 10 with a second encryption key (encryption key KA2), and is capable of storing the second authentication key (authentication key KB2) in a second memory circuit (memory unit 22). This makes it possible to improve convenience while also enhancing security.
  • a method may be used in which the generated authentication key is stored in the security modules 15, 25.
  • the diagnostic device 30 in order for the diagnostic device 30 to store the authentication key in the security module 15, it is necessary to use the encryption key KA1 stored in the security module 15. Therefore, the diagnostic device 30 needs to store this encryption key KA1.
  • the diagnostic device 30 needs to manage the encryption keys KA1 of each of the multiple vehicles 9, which increases management costs and reduces convenience.
  • an authentication key KB1 is generated by encrypting the authentication key KB using the encryption key KA1 stored in the security module 15, and this authentication key KB1 is stored in the storage unit 12.
  • an authentication key KB2 is generated by encrypting the authentication key KB using the encryption key KA2 stored in the security module 25, and this authentication key KB2 is stored in the storage unit 22.
  • the diagnostic device 30 does not need to store the encryption keys KA1 and KA2, which makes it possible to reduce management costs and improve convenience.
  • the central electronic control unit 10 can temporarily store the generated authentication key (authentication key KB) in the first memory circuit (memory section 12), and after storing the first authentication key (authentication key KB1) in the first memory circuit (memory section 12), the authentication key (authentication key KB) stored in the first memory circuit (memory section 12) can be deleted.
  • the communication module 20 can temporarily store the authentication key (authentication key KB) supplied from the central electronic control unit 10 in the second memory circuit (memory section 22), and after storing the second authentication key (authentication key KB2) in the second memory circuit (memory section 22), the authentication key (authentication key KB) stored in the second memory circuit (memory section 22) can be deleted.
  • the memory unit 12 stores the encrypted authentication key KB1 and deletes the unencrypted authentication key KB
  • the memory unit 22 stores the encrypted authentication key KB2 and deletes the unencrypted authentication key KB, thereby improving security.
  • the present invention includes a central electronic control unit having a first security circuit in which a first encryption key is stored and external access is restricted, and a first storage circuit, and a communication module having a second security circuit in which a second encryption key is stored and external access is restricted, and a second storage circuit.
  • the central electronic control unit is capable of generating an authentication key used in authentication processing between the central electronic control unit and the communication module, and is capable of generating the first authentication key by encrypting the authentication key with the first encryption key, and is capable of storing the first authentication key in the first storage circuit.
  • the central electronic control unit is capable of supplying the generated authentication key to the communication module.
  • the communication module is capable of generating a second authentication key by encrypting the authentication key supplied from the central electronic control unit with the second encryption key, and is capable of storing the second authentication key in the second storage circuit. This makes it possible to improve convenience while enhancing security.
  • the central electronic control unit is capable of temporarily storing the generated authentication key in the first storage circuit, and after storing the first authentication key in the first storage circuit, the authentication key stored in the first storage circuit can be deleted.
  • the communication module is capable of temporarily storing the authentication key supplied from the central electronic control unit in the second storage circuit, and after storing the second authentication key in the second storage circuit, the authentication key stored in the second storage circuit can be deleted. This can improve security.
  • the central electronic control unit is capable of generating an authentication key based on instructions from the diagnostic device, thereby improving security.
  • the central electronic control unit is capable of generating a third authentication key by decrypting the first authentication key with the first encryption key, and is capable of performing the first processing based on the third authentication key.
  • the communication module is capable of generating a fourth authentication key by decrypting the second authentication key with the second encryption key, and is capable of performing the second processing based on the fourth authentication key. The central electronic control unit and the communication module then perform the authentication processing by performing the first processing and the second processing. This can enhance security.
  • the authentication process is performed using the method shown in Figures 6A and 6B, but this is not limited to this, and any authentication method may be used as long as it uses the authentication key KB1 stored in the memory unit 22 of the central electronic control unit 10 and the authentication key KB2 stored in the memory unit 22 of the communication module 20.
  • the central electronic control unit 10 and the communication module 20 perform the authentication process, but this is not limited to this, and various other circuits in the vehicle 9 may perform the authentication process.
  • the technology is applied to a vehicle 9, but the technology is not limited to this and may be applied to vehicles other than a vehicle 9.
  • the first control device is capable of generating an authentication key used in an authentication process between the first control device and the second control device, is capable of generating a first authentication key by encrypting the authentication key with the first encryption key, and is capable of storing the first authentication key in the first storage circuit;
  • the first control device is capable of supplying the generated authentication key to the second control device,
  • the second control device is capable of generating a second authentication key by encrypting the authentication key supplied from the first control device with the second encryption key, and is capable of storing the second authentication key in the second memory circuit.
  • the first control device is capable of temporarily storing the generated authentication key in the first storage circuit, and after storing the first authentication key in the first storage circuit, is capable of deleting the authentication key stored in the first storage circuit;
  • the second control device is capable of temporarily storing the authentication key supplied from the first control device in the second memory circuit, and is capable of deleting the authentication key stored in the second memory circuit after storing the second authentication key in the second memory circuit.
  • the first control device is capable of generating a third authentication key by decrypting the first authentication key by using the first encryption key, and is capable of performing a first process based on the third authentication key;
  • the second control device is capable of generating a fourth authentication key by decrypting the second authentication key by using the second encryption key, and is capable of performing a second process based on the fourth authentication key;
  • the control system according to any one of (1) to (3), wherein the first control device and the second control device perform the authentication process by performing the first process and the second process.
  • the first control device includes an electronic control unit for controlling a vehicle.
  • the at least one processor may be configured to execute all or a portion of the various functions of the processing unit 17 shown in FIG. 2 by reading instructions from at least one non-transitory and tangible computer-readable medium.
  • Such media may take a variety of forms, including, but not limited to, various magnetic media such as hard disks, various optical media such as CDs or DVDs, and various semiconductor memories (i.e., semiconductor circuits) such as volatile or non-volatile memories. Volatile memories may include DRAM and SRAM.
  • Non-volatile memories may include ROM and NVRAM.
  • An ASIC is an integrated circuit (IC) specialized to execute all or a portion of the various functions of the processing unit 17 shown in FIG. 2.
  • An FPGA is an integrated circuit designed to be configurable after manufacture to execute all or a portion of the various functions of the processing unit 17 shown in FIG. 2. Note that, although the above description has been given using the processing unit 17 as an example, this is not limited to this, and the same applies to the processing unit 27.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Lock And Its Accessories (AREA)

Abstract

本開示の一実施の形態に係る制御システムは、第1の暗号鍵が記憶され、外部からのアクセスが制限された第1のセキュリティ回路と、第1の記憶回路とを有する第1の制御装置と、第2の暗号鍵が記憶され、外部からのアクセスが制限された第2のセキュリティ回路と、第2の記憶回路とを有する第2の制御装置とを備える。第1の制御装置は、第1の制御装置および第2の制御装置の間の認証処理に使用される認証鍵を生成可能であり、認証鍵を第1の暗号鍵を用いて暗号化することにより第1の認証鍵を生成可能であり、第1の認証鍵を第1の記憶回路に記憶させることが可能である。第1の制御装置は、生成した認証鍵を第2の制御装置に供給可能である。第2の制御装置は、第1の制御装置から供給された認証鍵を第2の暗号鍵を用いて暗号化することにより第2の認証鍵を生成可能であり、第2の認証鍵を第2の記憶回路に記憶させることが可能である。

Description

制御システムおよび車両
 本開示は、認証鍵を用いて認証処理を行う制御システム、およびそのような制御システムを備えた車両に関する。
 電子機器では、しばしば、鍵を用いてセキュリティを高める技術が用いられる。例えば特許文献1には、車両用マスタ装置における、セキュリティアクセス鍵の管理方法についての技術が開示されている。
特開2020-028120号公報
 本開示の一実施の形態に係る制御システムは、第1の制御装置と、第2の制御装置とを備えている。第1の制御装置は、第1の暗号鍵が記憶され、外部からのアクセスが制限された第1のセキュリティ回路と、第1の記憶回路とを有している。第2の制御装置は、第2の暗号鍵が記憶され、外部からのアクセスが制限された第2のセキュリティ回路と、第2の記憶回路とを有している。第1の制御装置は、第1の制御装置および第2の制御装置の間の認証処理に使用される認証鍵を生成可能であり、認証鍵を第1の暗号鍵を用いて暗号化することにより第1の認証鍵を生成可能であり、第1の認証鍵を第1の記憶回路に記憶させることが可能である。第1の制御装置は、生成した認証鍵を前記第2の制御装置に供給可能である。第2の制御装置は、第1の制御装置から供給された認証鍵を第2の暗号鍵を用いて暗号化することにより第2の認証鍵を生成可能であり、第2の認証鍵を第2の記憶回路に記憶させることが可能である。
 本開示の一実施の形態に係る車両は、上記制御システムを備えている。第1の制御装置は、車両を制御する電子制御ユニットを含む。
 添付図面は、本開示をさらに理解するために設けられており、本明細書に組み込まれるとともに、本明細書の一部を構成するものである。図面は、一実施の形態を示し、明細書とともに、本開示の原理を説明する役割を果たす。
図1は、本開示の一実施の形態に係る制御システムの一構成例を表す説明図である。 図2は、図1に示したセントラル電子制御ユニットおよび通信モジュールの一構成例を表すブロック図である。 図3は、図1に示した制御システムの一動作例を表す説明図である。 図4は、図3に示した制御システムの一動作例を表すシーケンス図である。 図5は、図1に示した制御システムの他の一動作例を表す説明図である。 図6Aは、図5に示した制御システムの一動作例を表すシーケンス図である。 図6Bは、図5に示した制御システムの一動作例を表す他のシーケンス図である。
 制御システムでは、セキュリティを高めつつ、利便性を高めることが望まれており、さらなる利便性の向上が期待されている。
 セキュリティを高めつつ、利便性を高めることができる制御システムおよび車両を提供することが望ましい。
 以下、本開示のいくつかの例示的な実施の形態を、添付図面を参照して詳細に説明する。なお、以下の説明は、本開示の一具体例を示すものであり、本開示を限定するものと解釈されてはならない。例えば、数値、形状、材料、部品、各部品の位置および各部品の接続方法等を含む各要素は、一例にすぎず、本開示を限定するものと解釈されてはならない。また、以下の例示的な実施の形態において、本開示の最上位概念に基づく独立項に記載されていない構成要素は、任意的なものであり、必要に応じて設けられ得る。図面は模式的なものであり、原寸通りの図示を意図してはいない。本明細書および図面の全般において、略同じ機能および略同じ構成を有する構成要素については、同一の参照符号を付し、重複する説明を省略する。また、本開示の一実施の形態に直接関係の無い構成要素は、図面に図示してはいない。
<実施の形態>
[構成例]
 図1は、一実施の形態に係る制御システム(制御システム1)の一構成例を表すものである。この制御システム1は、車両9に設けられる。車両9は、自動車などの車両である。制御システム1は、セントラル電子制御ユニット(ECU:Electronic Control Unit)10と、複数の電子制御ユニット19と、通信モジュール20とを有している。
 セントラル電子制御ユニット10は、複数の電子制御ユニット19の動作を制御することにより、車両9の動作を制御するように構成される。また、セントラル電子制御ユニット10は、例えば、通信ケーブルを介して車外の診断装置30(後述)に接続され、この診断装置30と通信を行うことができるようになっている。また、このセントラル電子制御ユニット10は、CAN(Controller Area Network)9に接続され、CAN9を介して通信モジュール20と通信を行うようになっている。
 複数の電子制御ユニット19は、セントラル電子制御ユニット10からの指示に基づいて、車両9における各装置の動作を制御するように構成される。複数の電子制御ユニット19は、例えば、エンジンなどのパワートレインを制御する電子制御ユニット19、操舵装置や制動装置を制御する電子制御ユニット19、車内外の照明、ドア、ワイパーなどを制御する電子制御ユニット19、運転支援システムを制御する電子制御ユニット19などを含んでいる。
 通信モジュール20は、例えば、4G(4th Generation)や5G(5th Generation)などの移動通信を行うことにより、基地局と通信を行うように構成される。これにより、通信モジュール20は、基地局を介して、インターネットに接続されたサーバ40(後述)と通信を行うことができるようになっている。また、この通信モジュール20は、CAN9に接続され、CAN9を介してセントラル電子制御ユニット10と通信を行うようになっている。
 この制御システム1では、セントラル電子制御ユニット10および通信モジュール20の間で認証処理を行うことができる。セントラル電子制御ユニット10では、例えば、後述する不揮発性メモリ14に、暗号化された認証鍵KB1が記憶され、通信モジュール20では、例えば、後述する不揮発性メモリ24に、暗号化された認証鍵KB2が記憶される。セントラル電子制御ユニット10および通信モジュール20は、これらの認証鍵KB1,KB2を用いて認証処理を行うことができるようになっている。
 図2は、セントラル電子制御ユニット10および通信モジュール20の一構成例を表すものである。
 セントラル電子制御ユニット10は、通信部11と、記憶部12と、セキュリティモジュール15と、外部通信部16と、処理部17とを有している。
 通信部11は、CAN9を介して、通信モジュール20と通信を行うように構成される。
 記憶部12は、データを記憶するように構成される。記憶部12は、RAM13と、不揮発性メモリ14とを有している。RAM13は、例えばDRAM(Dynamic Random Access Memory)を用いて構成され、セントラル電子制御ユニット10の処理内容を一時的に記憶するように構成される。不揮発性メモリ14は、例えばフラッシュメモリなどを用いて構成され、セントラル電子制御ユニット10で実行されるソフトウェアや、暗号化された認証鍵KB1を記憶するように構成される。RAM13および不揮発性メモリ14のメモリ領域は、セントラル電子制御ユニット10の外部から、通信部11および処理部17を介してアクセスされることができるようになっている。
 セキュリティモジュール15は、いわゆるHSM(Hardware Security Module)であり、データをセキュアなメモリ領域に記憶するように構成される。この例では、セキュリティモジュール15には、暗号鍵KA1が記憶される。セキュリティモジュール15は、セントラル電子制御ユニット10の外部からのアクセスが制限されるように構成される。これにより、セキュリティモジュール15は、記憶しているデータを容易に書き換えできないように、そして記憶しているデータが漏洩しないように、データを保護するようになっている。
 外部通信部16は、例えば、車両9に不具合がある場合に、通信ケーブルを用いて、診断装置30(後述)と通信を行うように構成される。
 処理部17は、例えば、1または複数のプロセッサを用いて構成され、ソフトウェアを実行することによりセントラル電子制御ユニット10の動作を制御するように構成される。
 通信モジュール20は、通信部21と、記憶部22と、セキュリティモジュール25と、無線通信部26と、処理部27とを有している。
 通信部21は、CAN9を介して、セントラル電子制御ユニット10と通信を行うように構成される。
 記憶部22は、データを記憶するように構成される。記憶部22は、RAM23と、不揮発性メモリ24とを有している。RAM23は、例えばDRAMを用いて構成され、通信モジュール20の処理内容を一時的に記憶するように構成される。不揮発性メモリ24は、例えばフラッシュメモリなどを用いて構成され、通信モジュール20で実行されるソフトウェアや、暗号化された認証鍵KB2を記憶するように構成される。RAM23および不揮発性メモリ24のメモリ領域は、通信モジュール20の外部から、通信部21および処理部27を介してアクセスされることができるようになっている。
 セキュリティモジュール25は、いわゆるHSMであり、データをセキュアなメモリ領域に記憶するように構成される。この例では、セキュリティモジュール25には、暗号鍵KA2が記憶される。セキュリティモジュール25は、通信モジュール20の外部からのアクセスが制限されるように構成される。これにより、セキュリティモジュール25は、記憶しているデータを容易に書き換えできないように、そして記憶しているデータが漏洩しないように、データを保護するようになっている。
 無線通信部26は、例えば、4Gや5Gなどの移動通信を行うことにより、基地局と通信を行うように構成される。これにより、無線通信部26は、基地局を介して、インターネットに接続されたサーバ40(後述)と通信を行うことができる。無線通信部26は、例えば、更新用のソフトウェアを、サーバ40からダウンロードすることができるようになっている。
 処理部27は、例えば、1または複数のプロセッサを用いて構成され、ソフトウェアを実行することにより通信モジュール20の動作を制御するように構成される。
 この制御システム1では、セントラル電子制御ユニット10は、診断装置30からの指示に基づいて認証鍵KBを生成する。そして、セントラル電子制御ユニット10は、この認証鍵KBを通信モジュール20に送信する。セントラル電子制御ユニット10は、暗号鍵KA1を用いてこの認証鍵KBを暗号化することにより認証鍵KB1を生成し、この認証鍵KB1を不揮発性メモリ14に記憶させる。同様に、通信モジュール20は、暗号鍵KA2を用いてこの認証鍵KBを暗号化することにより認証鍵KB2を生成し、この認証鍵KB2を不揮発性メモリ24に記憶させる。これ以降、セントラル電子制御ユニット10および通信モジュール20は、不揮発性メモリ14,24に記憶されたこの認証鍵KB1,KB2を用いて認証処理を行うことができるようになっている。
 ここで、セントラル電子制御ユニット10は、本開示の一実施の形態における「第1の制御装置」の一具体例に対応する。暗号鍵KA1は、本開示の一実施の形態における「第1の暗号鍵」の一具体例に対応する。セキュリティモジュール15は、本開示の一実施の形態における「第1のセキュリティ回路」の一具体例に対応する。記憶部12は、本開示の一実施の形態における「第1の記憶回路」の一具体例に対応する。通信モジュール20は、本開示の一実施の形態における「第2の制御装置」の一具体例に対応する。暗号鍵KA2は、本開示の一実施の形態における「第2の暗号鍵」の一具体例に対応する。セキュリティモジュール25は、本開示の一実施の形態における「第2のセキュリティ回路」の一具体例に対応する。記憶部22は、本開示の一実施の形態における「第2の記憶回路」の一具体例に対応する。認証鍵KBは、本開示の一実施の形態における「認証鍵」の一具体例に対応する。認証鍵KB1は、本開示の一実施の形態における「第1の認証鍵」の一具体例に対応する。認証鍵KB2は、本開示の一実施の形態における「第2の認証鍵」の一具体例に対応する。
[動作および作用]
 続いて、本実施の形態の制御システム1の動作および作用について説明する。
(全体動作概要)
 まず、図1,2を参照して、制御システム1の動作を説明する。セントラル電子制御ユニット10では、通信部11は、CAN9を介して、通信モジュール20と通信を行う。記憶部12は、データを記憶する。セキュリティモジュール15は、データをセキュアなメモリ領域に記憶する。セキュリティモジュール15は、暗号鍵KA1を記憶している。外部通信部16は、例えば、車両9に不具合がある場合に、通信ケーブルを用いて、診断装置30と通信を行う。処理部17は、セントラル電子制御ユニット10の動作を制御する。
 通信モジュール20では、通信部21は、CAN9を介して、セントラル電子制御ユニット10と通信を行う。記憶部22は、データを記憶する。セキュリティモジュール25は、データをセキュアなメモリ領域に記憶する。セキュリティモジュール25は、暗号鍵KA2を記憶している。無線通信部26は、移動通信を行うことにより、基地局を介して、インターネットに接続されたサーバ40と通信を行う。無線通信部26は、例えば、更新用のソフトウェアを、サーバ40からダウンロードすることができる。処理部27は、通信モジュール20の動作を制御する。
(詳細動作)
 以下に、制御システム1の動作について、詳細に説明する。
 制御システム1は、セントラル電子制御ユニット10および通信モジュール20の間の認証処理で使用される認証鍵KB1,KB2を登録する。以下に、この動作について詳細に説明する。
 図3は、認証鍵KB1,KB2が記憶される場合における車両9の一例を表すものである。例えば、車両9に不具合がある場合には、車両9の所有者は、この車両9をディーラに持ち込む。ディーラの作業員は、この例では、通信ケーブル8を介して、診断装置30を、車両9のセントラル電子制御ユニット10に接続し、診断装置30は、車両9を診断する。この例では、診断装置30は、セントラル電子制御ユニット10の故障を検出する。ディーラの作業員は、セントラル電子制御ユニット10を交換する。この場合には、制御システム1は、診断装置30からの指示に基づいて、セントラル電子制御ユニット10および通信モジュール20の間の認証処理で使用される認証鍵KB1,KB2を登録する。
 図4は、制御システム1における認証鍵KB1,KB2の登録処理の一例を表すものである。
 まず、診断装置30は、車両9のセントラル電子制御ユニット10に対して認証鍵の登録要求を行う(ステップS101)。セントラル電子制御ユニット10の外部通信部16は、この登録要求を受け取る。
 次に、セントラル電子制御ユニット10の処理部17は、診断装置30からの認証鍵の登録要求に基づいて、認証鍵KBを生成し、この認証鍵KBをRAM13に記憶させる(ステップS102)。
 次に、セントラル電子制御ユニット10の通信部11は、ステップS102において生成した認証鍵KBを通信モジュール20に供給する(ステップS103)。通信モジュール20の通信部21は、この認証鍵KBを受け取る。
 そして、通信モジュール20の処理部27は、受け取った認証鍵KBをRAM23に記憶させる(ステップS104)。
 セントラル電子制御ユニット10の処理部17は、セキュリティモジュール15に記憶された暗号鍵KA1を用いて、RAM13に記憶された認証鍵KBを暗号化することにより認証鍵KB1を生成し、この認証鍵KB1を不揮発性メモリ14に記憶させる(ステップS105)。
 そして、セントラル電子制御ユニット10の処理部17は、RAM13に記憶された認証鍵KBを削除する(ステップS106)。
 同様に、通信モジュール20の処理部27は、セキュリティモジュール25に記憶された暗号鍵KA2を用いて、RAM23に記憶された認証鍵KBを暗号化することにより認証鍵KB2を生成し、この認証鍵KB2を不揮発性メモリ24に記憶させる(ステップS107)。
 そして、通信モジュール20の処理部27は、RAM23に記憶された認証鍵KBを削除する(ステップS108)。
 以上で、この処理は終了する。
 このようにして、セントラル電子制御ユニット10の不揮発性メモリ14には、暗号鍵KA1を用いて暗号化された認証鍵KB1が記憶され、通信モジュール20の不揮発性メモリ24には、暗号鍵KA2を用いて暗号化された認証鍵KB2が記憶される。
 制御システム1では、セントラル電子制御ユニット10および通信モジュール20は、これ以降、この認証鍵KB1,KB2を用いて認証処理を行うことができる。以下に、この動作について説明する。
 図5は、認証鍵KB1,KB2を用いた認証処理を行う場合における車両9の一例を表すものである。例えば、複数の電子制御ユニット19のうちのある電子制御ユニット19において実行されるソフトウェアの更新用のソフトウェアが準備された場合には、車両9の通信モジュール20は、サーバ40から、この更新用のソフトウェアをダウンロードする。そして、車両9のセントラル電子制御ユニット10および通信モジュール20は、認証鍵KB1,KB2を用いて認証処理を行い、この認証処理が成功した場合には、セントラル電子制御ユニット10は、この更新用のソフトウェアを用いて、電子制御ユニット19のソフトウェアを更新する。
 図6A,6Bは、制御システム1における認証鍵KB1,KB2を用いた認証処理の一例を表すものである。
 まず、サーバ40は、車両9の通信モジュール20に対して、更新用のソフトウェアを送信する(ステップS201)。通信モジュール20の無線通信部26は、この更新用のソフトウェアを受信する。
 次に、通信モジュール20の通信部21は、セントラル電子制御ユニット10に対して、認証要求を行う(ステップS202)。セントラル電子制御ユニット10の通信部11は、この認証要求を受け取る。
 通信モジュール20の処理部27は、RAM23のアクセス制限を行う(ステップS203)。これにより、例えば、通信モジュール20の外部からのRAM23のメモリ領域へのアクセスが一時的に制限される。
 同様に、セントラル電子制御ユニット10の処理部17は、RAM13のアクセス制限を行う(ステップS204)。これにより、例えば、セントラル電子制御ユニット10の外部からのRAM13のメモリ領域へのアクセスが一時的に制限される。
 次に、セントラル電子制御ユニット10の処理部17は、複数桁の乱数を含む乱数データを生成し、生成した乱数データをRAM13に記憶させる(ステップS205)。
 次に、セントラル電子制御ユニット10の通信部11は、この乱数データを通信モジュール20に対して供給する(ステップS206)。通信モジュール20の通信部11は、この乱数データを受け取る。
 次に、通信モジュール20の処理部27は、ステップS206において受け取った乱数データをRAM23に記憶させる(ステップS207)。
 次に、通信モジュール20の処理部27は、セキュリティモジュール25に記憶された暗号鍵KA2を用いて、不揮発性メモリ24に記憶された認証鍵KB2を復号することにより認証鍵KB21を生成し、この認証鍵KB21をRAM13に記憶させる(ステップS208)。この認証鍵KB21は、ステップS102において生成された認証鍵KBと同じである。
 そして、通信モジュール20の処理部27は、この復号された認証鍵KB21を用いて、ステップS207においてRAM23に記憶された乱数データを暗号化する(ステップS209)。
 同様に、セントラル電子制御ユニット10の処理部17は、セキュリティモジュール15に記憶された暗号鍵KA1を用いて、不揮発性メモリ14に記憶された認証鍵KB1を復号することにより認証鍵KB11を生成し、この認証鍵KB11をRAM13に記憶させる(ステップS210)。この認証鍵KB11は、ステップS102において生成された認証鍵KBと同じである。
 そして、セントラル電子制御ユニット10の処理部17は、この復号された認証鍵KB11を用いて、ステップS205においてRAM13に記憶された乱数データを暗号化する(ステップS211)。
 次に、通信モジュール20の通信部11は、ステップS209において暗号化された乱数データを、セントラル電子制御ユニット10に対して供給する(ステップS212)。セントラル電子制御ユニット10の通信部11は、この暗号化された乱数データを受け取る。
 次に、セントラル電子制御ユニット10の処理部17は、ステップS211において暗号化された乱数データと、ステップS212において通信モジュール20から受け取った暗号化された乱数データとを比較することにより、認証処理を行う(ステップS213)。すなわち、これらの乱数データが同じである場合には、通信モジュール20において用いられた認証鍵KB21と、セントラル電子制御ユニット10において用いられた認証鍵KB11が同じであることを意味するので、処理部17は、これらの乱数データを比較することにより、認証処理を行うことができる。
 認証処理が成功した場合には、セントラル電子制御ユニット10の通信部11は、通信モジュール20に対して、ソフトウェアの更新許可通知を行う(ステップS214)。通信モジュール20の通信部11は、この更新許可通知を受け取る。
 次に、通信モジュール20の処理部27は、RAM23に記憶された認証鍵KB21および乱数データを削除する(ステップS215)。そして、通信モジュール20の処理部27は、ステップS203において行ったRAM23のアクセス制限を解除する(ステップS216)。これにより、例えば、通信モジュール20の外部からのRAM23のメモリ領域へのアクセスは許可される。
 同様に、セントラル電子制御ユニット10の処理部17は、RAM13に記憶された認証鍵KB11および乱数データを削除する(ステップS217)。そして、セントラル電子制御ユニット10の処理部17は、ステップS204において行ったRAM13のアクセス制限を解除する(ステップS218)。これにより、例えば、セントラル電子制御ユニット10の外部からのRAM13のメモリ領域へのアクセスは許可される。
 次に、通信モジュール20の通信部21は、ステップS201において受信した更新用のソフトウェアを、セントラル電子制御ユニット10に対して供給する(ステップS219)。セントラル電子制御ユニット10の通信部11は、この更新用のソフトウェアを受け取る。
 そして、セントラル電子制御ユニット10の処理部17は、ステップS220において受け取った更新用のソフトウェアを用いて、更新対象である電子制御ユニット19のソフトウェアを更新する(ステップS220)。
 以上により、この処理は終了する。ここで、認証鍵KB11は、本開示の一実施の形態における「第3の認証鍵」の一具体例に対応する。認証鍵KB21は、本開示の一実施の形態における「第4の認証鍵」の一具体例に対応する。
 このように、制御システム1では、第1の暗号鍵(暗号鍵KA1)が記憶され、外部からのアクセスが制限された第1のセキュリティ回路(セキュリティモジュール15)と、第1の記憶回路(記憶部12)とを有するセントラル電子制御ユニット10と、第2の暗号鍵(暗号鍵KA2)が記憶され、外部からのアクセスが制限された第2のセキュリティ回路(セキュリティモジュール25)と、第2の記憶回路(記憶部22)とを有する通信モジュール20とを備えるようにした。セントラル電子制御ユニット10は、セントラル電子制御ユニット10および通信モジュール20の間の認証処理に使用される認証鍵KBを生成可能であり、認証鍵KBを第1の暗号鍵(暗号鍵KA1)を用いて暗号化することにより第1の認証鍵(認証鍵KB1)を生成可能であり、第1の認証鍵(認証鍵KB1)を第1の記憶回路(記憶部12)に記憶させることが可能であるようにした。セントラル電子制御ユニット10は、生成した認証鍵KBを通信モジュール20に供給可能なようにした。通信モジュール20は、セントラル電子制御ユニット10から供給された認証鍵KBを第2の暗号鍵(暗号鍵KA2)を用いて暗号化することにより第2の認証鍵(認証鍵KB2)を生成可能であり、第2の認証鍵(認証鍵KB2)を第2の記憶回路(記憶部22)に記憶させることが可能なようにした。これにより、セキュリティを高めつつ、利便性を高めることができる。
 すなわち、セキュリティを高めるためには、生成した認証鍵をセキュリティモジュール15,25に記憶させる方法もあり得る。この場合、例えば、診断装置30が、セキュリティモジュール15に認証鍵を記憶させるためには、セキュリティモジュール15に記憶された暗号鍵KA1を使用する必要がある。よって、診断装置30は、この暗号鍵KA1を記憶しておく必要がある。すなわち、診断装置30は、複数の車両9の暗号鍵KA1をそれぞれ管理する必要があるので、管理コストがかかり、利便性を損なってしまう。
 一方、本実施の形態にかかる制御システム1では、セキュリティモジュール15に認証鍵を記憶させるのではなく、セキュリティモジュール15に記憶された暗号鍵KA1を用いて認証鍵KBを暗号化することにより認証鍵KB1を生成し、この認証鍵KB1を記憶部12に記憶させるようにした。同様に、制御システム1では、セキュリティモジュール25に記憶された暗号鍵KA2を用いて認証鍵KBを暗号化することにより認証鍵KB2を生成し、この認証鍵KB2を記憶部22に記憶させるようにした。これにより、診断装置30は、暗号鍵KA1,KA2を記憶する必要がないので、管理コストを抑えることができ、利便性を高めることができる。
 また、制御システム1では、セントラル電子制御ユニット10は、生成した認証鍵(認証鍵KB)を第1の記憶回路(記憶部12)に一旦記憶させることが可能であり、第1の認証鍵(認証鍵KB1)を第1の記憶回路(記憶部12)に記憶させた後に、第1の記憶回路(記憶部12)に記憶された認証鍵(認証鍵KB)を削除可能であるようにした。通信モジュール20は、セントラル電子制御ユニット10から供給された認証鍵(認証鍵KB)を第2の記憶回路(記憶部22)に一旦記憶させることが可能であり、第2の認証鍵(認証鍵KB2)を第2の記憶回路(記憶部22)に記憶させた後に、第2の記憶回路(記憶部22)に記憶された認証鍵(認証鍵KB)を削除可能であるようにした。これにより、制御システム1では、記憶部12では、暗号化された認証鍵KB1が記憶されるとともに暗号化されていない認証鍵KBは削除され、記憶部22では、暗号化された認証鍵KB2が記憶されるとともに暗号化されていない認証鍵KBは削除されるので、セキュリティを高めることができる。
 また、制御システム1では、セントラル電子制御ユニット10は、診断装置30からの指示に基づいて認証鍵KBを生成可能なようにした。すなわち、例えば、セントラル電子制御ユニット10が故障した場合に、診断装置30からの指示に基づいて認証鍵KBを生成する。これにより、例えば以前の認証鍵KBをそのまま使用し続けることなく、認証鍵KBを再度生成することができるので、セキュリティを高めることができる。
 また、制御システム1では、セントラル電子制御ユニット10は、第1の認証鍵(認証鍵KB1)を第1の暗号鍵(暗号鍵KA1)を用いて復号することにより第3の認証鍵(認証鍵KB11)を生成可能であり、第3の認証鍵(認証鍵KB11)に基づいて第1の処理を行うことが可能であるようにした。また、通信モジュール20は、第2の認証鍵(認証鍵KB2)を第2の暗号鍵(暗号鍵KA2)を用いて復号することにより第4の認証鍵(認証鍵KB21)を生成可能であり、第4の認証鍵(認証鍵KB21)に基づいて第2の処理を行うことが可能であるようにした。そして、セントラル電子制御ユニット10および通信モジュール20は、第1の処理および第2の処理を行うことにより、認証処理を行うようにした。これにより、例えば、認証鍵KB11および認証鍵KB21が互いに同じである場合に、認証処理が成功し、認証処理が成功した場合に所定の処理を行うことができるので、セキュリティを高めることができる。
[効果]
 以上のように本実施の形態では、第1の暗号鍵が記憶され、外部からのアクセスが制限された第1のセキュリティ回路と、第1の記憶回路とを有するセントラル電子制御ユニットと、第2の暗号鍵が記憶され、外部からのアクセスが制限された第2のセキュリティ回路と、第2の記憶回路とを有する通信モジュールとを備えるようにした。セントラル電子制御ユニットは、セントラル電子制御ユニットおよび通信モジュールの間の認証処理に使用される認証鍵を生成可能であり、認証鍵を第1の暗号鍵を用いて暗号化することにより第1の認証鍵を生成可能であり、第1の認証鍵を第1の記憶回路に記憶させることが可能であるようにした。セントラル電子制御ユニットは、生成した認証鍵を通信モジュールに供給可能なようにした。通信モジュールは、セントラル電子制御ユニットから供給された認証鍵を第2の暗号鍵を用いて暗号化することにより第2の認証鍵を生成可能であり、第2の認証鍵を第2の記憶回路に記憶させることが可能なようにした。これにより、セキュリティを高めつつ、利便性を高めることができる。
 本実施の形態では、セントラル電子制御ユニットは、生成した認証鍵を第1の記憶回路に一旦記憶させることが可能であり、第1の認証鍵を第1の記憶回路に記憶させた後に、第1の記憶回路に記憶された認証鍵を削除可能であるようにした。通信モジュールは、セントラル電子制御ユニットから供給された認証鍵を第2の記憶回路に一旦記憶させることが可能であり、第2の認証鍵を第2の記憶回路に記憶させた後に、第2の記憶回路に記憶された認証鍵を削除可能であるようにした。これにより、セキュリティを高めることができる。
 本実施の形態では、セントラル電子制御ユニットは、診断装置からの指示に基づいて認証鍵を生成可能なようにしたので、セキュリティを高めることができる。
 本実施の形態では、セントラル電子制御ユニットは、第1の認証鍵を第1の暗号鍵を用いて復号することにより第3の認証鍵を生成可能であり、第3の認証鍵に基づいて第1の処理を行うことが可能であるようにした。通信モジュールは、第2の認証鍵を第2の暗号鍵を用いて復号することにより第4の認証鍵を生成可能であり、第4の認証鍵に基づいて第2の処理を行うことが可能であるようにした。そして、セントラル電子制御ユニットおよび通信モジュールは、第1の処理および第2の処理を行うことにより、認証処理を行うようにした。これにより、セキュリティを高めることができる。
 以上、本開示の実施の形態について添付図面を参照しつつ一例を説明したが、本開示は上記実施の形態に決して限定されるものではない。当業者であれば、添付の請求の範囲によって定義される範囲から逸脱することなく、各種変形や変更をなし得ることが理解される。本開示は、そのような各種変形や変更が、添付の請求の範囲およびその均等物の範囲に属する限り、それらを包含することを意図するものである。
 例えば、上記実施の形態では、図6A,6Bに示した方法で認証処理を行うようにしたが、これに限定されるものではなく、セントラル電子制御ユニット10の記憶部22に記憶された認証鍵KB1、および通信モジュール20の記憶部22に記憶された認証鍵KB2を用いた認証方法であれば、どのようなものであってもよい。
 例えば、上記実施の形態では、セントラル電子制御ユニット10および通信モジュール20が認証処理を行うようにしたが、これに限定されるものではなく、車両9における他の様々な回路が認証処理を行うようにしてもよい。
 例えば、上記実施の形態では、本技術を車両9に適用したが、これに限定されるものではなく、車両9以外に適用してもよい。
 本明細書中に記載された効果はあくまで例示であり、本開示の効果は、本明細書中に記載された効果に限定されない。よって、本開示に関して、他の効果が得られてもよい。
 さらに、本開示は、以下の態様を取り得る。
(1)
 第1の暗号鍵が記憶され、外部からのアクセスが制限された第1のセキュリティ回路と、第1の記憶回路とを有する第1の制御装置と、
 第2の暗号鍵が記憶され、外部からのアクセスが制限された第2のセキュリティ回路と、第2の記憶回路とを有する第2の制御装置と
 を備え、
 前記第1の制御装置は、前記第1の制御装置および前記第2の制御装置の間の認証処理に使用される認証鍵を生成可能であり、前記認証鍵を前記第1の暗号鍵を用いて暗号化することにより第1の認証鍵を生成可能であり、前記第1の認証鍵を前記第1の記憶回路に記憶させることが可能であり、
 前記第1の制御装置は、生成した前記認証鍵を前記第2の制御装置に供給可能であり、
 前記第2の制御装置は、前記第1の制御装置から供給された前記認証鍵を前記第2の暗号鍵を用いて暗号化することにより第2の認証鍵を生成可能であり、前記第2の認証鍵を前記第2の記憶回路に記憶させることが可能である
 制御システム。
(2)
 前記第1の制御装置は、生成した前記認証鍵を前記第1の記憶回路に一旦記憶させることが可能であり、前記第1の認証鍵を前記第1の記憶回路に記憶させた後に、前記第1の記憶回路に記憶された前記認証鍵を削除可能であり、
 前記第2の制御装置は、前記第1の制御装置から供給された前記認証鍵を前記第2の記憶回路に一旦記憶させることが可能であり、前記第2の認証鍵を前記第2の記憶回路に記憶させた後に、前記第2の記憶回路に記憶された前記認証鍵を削除可能である
 前記(1)に記載の制御システム。
(3)
 前記第1の制御装置は、外部装置からの指示に基づいて前記認証鍵を生成可能である
 前記(1)または(2)に記載の制御システム。
(4)
 前記第1の制御装置は、前記第1の認証鍵を前記第1の暗号鍵を用いて復号することにより第3の認証鍵を生成可能であり、前記第3の認証鍵に基づいて第1の処理を行うことが可能であり、
 前記第2の制御装置は、前記第2の認証鍵を前記第2の暗号鍵を用いて復号することにより第4の認証鍵を生成可能であり、前記第4の認証鍵に基づいて第2の処理を行うことが可能であり、
 前記第1の制御装置および前記第2の制御装置は、前記第1の処理および前記第2の処理を行うことにより、前記認証処理を行う
 前記(1)から(3)のいずれかに記載の制御システム。
(5)
 請求項1から請求項4のいずれか一項に記載の制御システムを備え、
 前記第1の制御装置は、車両を制御する電子制御ユニットを含む
 車両。
 図2に示す処理部17は、少なくとも1つのプロセッサ(例えば、中央演算処理装置(CPU))、少なくとも1つの特定用途向け集積回路(ASIC)および/または少なくとも1つのフィールドプログラマブルゲートアレイ(FPGA)等の、少なくとも1つの半導体集積回路を含む回路によって実施可能である。少なくとも1つのプロセッサは、少なくとも1つの非一時的かつ有形のコンピュータ可読媒体から指示を読み込むことによって、図2に示す処理部17における各種機能のうちの全部または一部を実行するように構成可能である。そのような媒体は、ハードディスク等の各種磁気媒体、CDまたはDVD等の各種光媒体、揮発性メモリまたは不揮発性メモリ等の各種半導体メモリ(すなわち、半導体回路)を含む様々な形態をとり得るが、これらには限定されない。揮発性メモリは、DRAMおよびSRAMを含み得る。不揮発性メモリは、ROMおよびNVRAMを含み得る。ASICは、図2に示す処理部17における各種機能のうちの全部または一部を実行するように特化された集積回路(IC)である。FPGAは、図2に示す処理部17における各種機能のうちの全部または一部を実行するように、製造後に構成可能に設計された集積回路である。なお、以上では、処理部17を例に挙げて説明したが、これに限定されるものではなく、処理部27についても同様である。

Claims (5)

  1.  第1の暗号鍵が記憶され、外部からのアクセスが制限された第1のセキュリティ回路と、第1の記憶回路とを有する第1の制御装置と、
     第2の暗号鍵が記憶され、外部からのアクセスが制限された第2のセキュリティ回路と、第2の記憶回路とを有する第2の制御装置と
     を備え、
     前記第1の制御装置は、前記第1の制御装置および前記第2の制御装置の間の認証処理に使用される認証鍵を生成可能であり、前記認証鍵を前記第1の暗号鍵を用いて暗号化することにより第1の認証鍵を生成可能であり、前記第1の認証鍵を前記第1の記憶回路に記憶させることが可能であり、
     前記第1の制御装置は、生成した前記認証鍵を前記第2の制御装置に供給可能であり、
     前記第2の制御装置は、前記第1の制御装置から供給された前記認証鍵を前記第2の暗号鍵を用いて暗号化することにより第2の認証鍵を生成可能であり、前記第2の認証鍵を前記第2の記憶回路に記憶させることが可能である
     制御システム。
  2.  前記第1の制御装置は、生成した前記認証鍵を前記第1の記憶回路に一旦記憶させることが可能であり、前記第1の認証鍵を前記第1の記憶回路に記憶させた後に、前記第1の記憶回路に記憶された前記認証鍵を削除可能であり、
     前記第2の制御装置は、前記第1の制御装置から供給された前記認証鍵を前記第2の記憶回路に一旦記憶させることが可能であり、前記第2の認証鍵を前記第2の記憶回路に記憶させた後に、前記第2の記憶回路に記憶された前記認証鍵を削除可能である
     請求項1に記載の制御システム。
  3.  前記第1の制御装置は、外部装置からの指示に基づいて前記認証鍵を生成可能である
     請求項1に記載の制御システム。
  4.  前記第1の制御装置は、前記第1の認証鍵を前記第1の暗号鍵を用いて復号することにより第3の認証鍵を生成可能であり、前記第3の認証鍵に基づいて第1の処理を行うことが可能であり、
     前記第2の制御装置は、前記第2の認証鍵を前記第2の暗号鍵を用いて復号することにより第4の認証鍵を生成可能であり、前記第4の認証鍵に基づいて第2の処理を行うことが可能であり、
     前記第1の制御装置および前記第2の制御装置は、前記第1の処理および前記第2の処理を行うことにより、前記認証処理を行う
     請求項1に記載の制御システム。
  5.  請求項1から請求項4のいずれか一項に記載の制御システムを備え、
     前記第1の制御装置は、車両を制御する電子制御ユニットを含む
     車両。
PCT/JP2023/011933 2023-03-24 2023-03-24 制御システムおよび車両 Ceased WO2024201600A1 (ja)

Priority Applications (4)

Application Number Priority Date Filing Date Title
PCT/JP2023/011933 WO2024201600A1 (ja) 2023-03-24 2023-03-24 制御システムおよび車両
CN202380045863.8A CN119343890A (zh) 2023-03-24 2023-03-24 控制系统以及车辆
JP2025509237A JPWO2024201600A1 (ja) 2023-03-24 2023-03-24
US18/979,893 US20250112775A1 (en) 2023-03-24 2024-12-13 Control system and vehicle

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2023/011933 WO2024201600A1 (ja) 2023-03-24 2023-03-24 制御システムおよび車両

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US18/979,893 Continuation US20250112775A1 (en) 2023-03-24 2024-12-13 Control system and vehicle

Publications (1)

Publication Number Publication Date
WO2024201600A1 true WO2024201600A1 (ja) 2024-10-03

Family

ID=92904164

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2023/011933 Ceased WO2024201600A1 (ja) 2023-03-24 2023-03-24 制御システムおよび車両

Country Status (4)

Country Link
US (1) US20250112775A1 (ja)
JP (1) JPWO2024201600A1 (ja)
CN (1) CN119343890A (ja)
WO (1) WO2024201600A1 (ja)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2016075865A1 (ja) * 2014-11-12 2016-05-19 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ 更新管理方法、更新管理装置及び制御プログラム
JP2017130908A (ja) * 2016-01-18 2017-07-27 Kddi株式会社 車載コンピュータシステム、車両、鍵生成装置、管理方法、鍵生成方法、及びコンピュータプログラム
JP2018196080A (ja) * 2017-05-22 2018-12-06 株式会社デンソー 電子制御装置および電子制御装置における鍵登録方法
JP2021135817A (ja) * 2020-02-27 2021-09-13 日立Astemo株式会社 車載機器の電子制御装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2016075865A1 (ja) * 2014-11-12 2016-05-19 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ 更新管理方法、更新管理装置及び制御プログラム
JP2017130908A (ja) * 2016-01-18 2017-07-27 Kddi株式会社 車載コンピュータシステム、車両、鍵生成装置、管理方法、鍵生成方法、及びコンピュータプログラム
JP2018196080A (ja) * 2017-05-22 2018-12-06 株式会社デンソー 電子制御装置および電子制御装置における鍵登録方法
JP2021135817A (ja) * 2020-02-27 2021-09-13 日立Astemo株式会社 車載機器の電子制御装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
KENJI SUGASHIMA, KENGO OKA, CAMILLE VIOMME: "4F2-4 Approaches for Secure and Efficient In-Vehicle Key Management", PROCEEDINGS OF THE 2016 SYMPOSIUM ON CRYPTOGRAPHY AND INFORMATION SECURITY; JANUARY 19–22, 2016, IEICE TECHNICAL COMMITTEE ON INFORMATION SECURITY (ISEC), JP, 19 January 2016 (2016-01-19) - 22 January 2016 (2016-01-22), JP, pages 1 - 6, XP009557876 *

Also Published As

Publication number Publication date
US20250112775A1 (en) 2025-04-03
JPWO2024201600A1 (ja) 2024-10-03
CN119343890A (zh) 2025-01-21

Similar Documents

Publication Publication Date Title
US11182485B2 (en) In-vehicle apparatus for efficient reprogramming and controlling method thereof
JP6173411B2 (ja) 管理装置、車両、管理システム、管理方法、及びコンピュータプログラム
CN103685214B (zh) 用于汽车电子控制单元的安全访问方法
JP6228093B2 (ja) システム
CN115066868B (zh) 车辆安全系统
US20190028267A1 (en) In-vehicle computer system, vehicle, key generation device, management method, key generation method, and computer program
US12347243B2 (en) Method and system for replacing vehicle parts using in-vehicle network based on vehicle ethernet
CN107925568A (zh) 管理装置、管理系统、密钥生成装置、密钥生成系统、密钥管理系统、车辆、管理方法、密钥生成方法以及计算机程序
WO2016152556A1 (ja) 管理装置、車両、管理方法、及びコンピュータプログラム
US11748275B2 (en) Method for securely updating control units
WO2016093368A1 (ja) 管理装置、鍵生成装置、車両、メンテナンスツール、管理システム、管理方法、及びコンピュータプログラム
JP2018093370A (ja) 車載電子制御装置、車載電子制御システム、中継装置
EP4305835B1 (en) Method and system for performing identity checks in a distributed system
JP6860464B2 (ja) システム及び管理方法
WO2020090418A1 (ja) 電子制御装置、電子制御装置のリプログラミング方法
US20250112775A1 (en) Control system and vehicle
CN119892342A (zh) 一种硬件安全模块的刷写方法、装置、设备、介质及产品
JP6926671B2 (ja) 電子制御装置および電子制御装置における鍵登録方法
JPWO2024201600A5 (ja)
JP7511492B2 (ja) 自動車用電子制御装置
JP2022150140A (ja) 車両プログラム更新管理システム、リプログラミング端末、車両プログラム更新管理方法
US12634262B2 (en) Method for controlling access of external devices to in-vehicle network and gateway therefor
US11804981B2 (en) Method and apparatus for providing an individually secure system to multiple distrusting parties
CN111142902A (zh) 处理器的升级固件保护方法、装置及车辆
CN114329506B (zh) 具有增强的安全性的系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23930241

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 202380045863.8

Country of ref document: CN

WWP Wipo information: published in national office

Ref document number: 202380045863.8

Country of ref document: CN

ENP Entry into the national phase

Ref document number: 2025509237

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 2025509237

Country of ref document: JP

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 23930241

Country of ref document: EP

Kind code of ref document: A1