WO2024252705A1 - 通信計画装置、制御方法およびコンピュータプログラム - Google Patents

通信計画装置、制御方法およびコンピュータプログラム Download PDF

Info

Publication number
WO2024252705A1
WO2024252705A1 PCT/JP2024/000034 JP2024000034W WO2024252705A1 WO 2024252705 A1 WO2024252705 A1 WO 2024252705A1 JP 2024000034 W JP2024000034 W JP 2024000034W WO 2024252705 A1 WO2024252705 A1 WO 2024252705A1
Authority
WO
WIPO (PCT)
Prior art keywords
communication
information
planning
unit
fragmented
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2024/000034
Other languages
English (en)
French (fr)
Inventor
健太 栗山
明紘 小川
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Sumitomo Wiring Systems Ltd
AutoNetworks Technologies Ltd
Sumitomo Electric Industries Ltd
Original Assignee
Sumitomo Wiring Systems Ltd
AutoNetworks Technologies Ltd
Sumitomo Electric Industries Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Sumitomo Wiring Systems Ltd, AutoNetworks Technologies Ltd, Sumitomo Electric Industries Ltd filed Critical Sumitomo Wiring Systems Ltd
Priority to CN202480037153.5A priority Critical patent/CN121263794A/zh
Priority to JP2025525938A priority patent/JPWO2024252705A1/ja
Publication of WO2024252705A1 publication Critical patent/WO2024252705A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60—Protecting data

Definitions

  • This disclosure relates to a communication planning device, a control method, and a computer program.
  • This application claims priority to Japanese Application No. 2023-095150, filed on June 9, 2023, and incorporates all of the contents of said Japanese application by reference.
  • Encryption is a commonly known method of concealment, but there is another method called secret sharing.
  • Secret sharing achieves information confidentiality by distributing and managing the data to be protected.
  • Patent Document 1 discloses a distributed information transfer system that uses a secret sharing method to distribute and hold secret information among multiple node groups in a network where there are full-mesh secure communication paths between all node pairs.
  • this distributed information transfer system prevents the attacker from collecting a sufficient number of shares by redistributing and distributing the first share, thereby maintaining a secure state.
  • a communication planning device is a communication planning device mounted on a system including a first device, a second device, and a communication device, and includes a planning unit that plans communication of specific information between the first device and the second device, and a detection unit that detects state-specific information required for the planning unit to plan the communication, and the planning unit plans communication of multiple pieces of fragmented information between the first device and the second device based on the detection result by the detection unit, and the fragmented information is information generated by dividing the specific information.
  • FIG. 1 is a block diagram showing a configuration of an in-vehicle system according to an embodiment of the present disclosure.
  • FIG. 2 is a block diagram illustrating a functional configuration of the second relay device illustrated in FIG.
  • FIG. 3 is a flowchart showing a process executed by the second relay device shown in FIG.
  • FIG. 4 is a block diagram showing a functional configuration of the second relay device according to the first modified example.
  • FIG. 5 is a diagram showing, in table format, communication information taken into consideration for determining security strength.
  • FIG. 6 is a diagram showing, in a table format, information on available ports and the presence or absence of connections of unexpected communication devices, which are taken into consideration for determining the security strength.
  • FIG. 1 is a block diagram showing a configuration of an in-vehicle system according to an embodiment of the present disclosure.
  • FIG. 2 is a block diagram illustrating a functional configuration of the second relay device illustrated in FIG.
  • FIG. 3 is a flowchart showing a process executed by the second
  • FIG. 7 is a flowchart showing a process executed by the second relay device according to the first modified example.
  • FIG. 8 is a block diagram showing an example of the configuration of an in-vehicle system according to the first modified example.
  • FIG. 9 is a block diagram showing a functional configuration of a second relay device according to the second modified example.
  • FIG. 10 is a flowchart showing a process executed by the second relay device according to the second modification.
  • Patent Literature 1 it is assumed that the communication path is secure, but in reality, there are cases where the communication path is not secure. In such cases, the technology disclosed in Patent Literature 1 cannot avoid the risk of information leakage due to unauthorized access on the communication path.
  • the present disclosure therefore aims to provide a communication planning device, control method, and computer program that can prevent leakage and tampering when communicating divided information in information management in which confidential information is divided into multiple pieces and stored in multiple nodes.
  • a communication planning device in which secret information is divided into multiple pieces and stored in multiple nodes, a communication planning device, a control method, and a computer program can be provided that can prevent leakage and tampering when communicating the divided information.
  • a communication planning device is a communication planning device mounted on a system including a first device, a second device, and a communication device, and includes a planning unit that plans communication of specified information between the first device and the second device, and a detection unit that detects state-specific information required for the planning unit to plan the communication, and the planning unit plans communication of multiple pieces of fragmented information between the first device and the second device based on a detection result by the detection unit, and the fragmented information is information generated by dividing the specified information.
  • secret information information that should be kept secret
  • the state-specific information includes information that indicates at least one of the following states: the communication state of external communication, which is communication by the communication device with outside the system; the state of the input/output ports of each of the communication planning device and the first device; and the presence or absence of a connection of an unexpected communication device to a communication path within the system. This makes it possible to further prevent leakage and tampering when communicating fragmentation information.
  • the planning unit determines based on the detection result that the multiple pieces of fragmented information will not be communicated, the planning unit can plan to communicate the multiple pieces of fragmented information after the first predetermined period has elapsed. This makes it possible to avoid a situation in which the multiple pieces of fragmented information cannot be communicated continuing indefinitely.
  • the first predetermined period may be determined based on the real-time nature of a function that requires communication of multiple pieces of fragmentation information. This makes it possible to avoid compromising the real-time nature required for the function.
  • the communication planning device may further include a security strength evaluation unit that evaluates security strength regarding information leakage from the system, and when the planning unit determines based on the detection result that the multiple fragmented information is not to be communicated, if the security strength evaluated by the security strength evaluation unit is equal to or higher than a predetermined level, the planning unit may plan to communicate the multiple fragmented information. This makes it possible to avoid unnecessarily suppressing the communication of the multiple fragmented information, and to control the communication of the multiple fragmented information according to the risk of information leakage.
  • the security strength evaluation unit may evaluate the security strength based on the detection result by the detection unit. This allows the security strength to be appropriately evaluated.
  • the communication planning device may further include a communication control unit that causes the communication device to restrict external communication, which is communication by the communication device with outside the system, and if external communication can be restricted, the planning unit may cause the communication control unit to restrict external communication for a second predetermined period and plan to communicate the multiple pieces of fragmented information for the second predetermined period. This makes it possible to avoid a state in which the multiple pieces of fragmented information cannot be communicated continuing indefinitely.
  • the planning unit may determine that the external communication can be restricted if the external communication is not being executed for a function that requires real-time performance. This allows multiple pieces of fragmented information to be communicated while avoiding the loss of real-time performance required for the function.
  • the planning unit may determine that the external communication can be restricted if the period from when a predetermined amount of data is stored in the buffer in the external communication to when the use of the data ends is longer than the period required to communicate the multiple pieces of fragmented information. This allows the multiple pieces of fragmented information to be communicated without affecting the function that is executing the external communication.
  • the communication planning device may further include an information processing unit that divides the specified information into a plurality of pieces of fragmented information, and the specified information may be transmitted from the first device to the second device via the communication planning device, and the information processing unit may generate the fragmented information by a secret sharing scheme. This can further prevent information leakage and tampering.
  • the communication planning device may further include a communication destination determination unit that determines communication destination devices from among the plurality of second devices, the number of which is equal to or less than the number of pieces of fragmentation information, and the plurality of pieces of fragmentation information may be communicated between the communication destination devices and the communication planning device based on a plan by the planning unit. This makes it possible to further prevent information leakage and tampering.
  • the communication destination determination unit may determine, from among the communication destination devices, a plurality of partner devices that will receive the fragmented information in response to a request for the specified information being input from the first device to the communication planning device, and the communication planning device may further include a restoration unit that generates the specified information from the fragmented information received from the plurality of partner devices. This allows the specified information to be generated from the fragmented information that is distributed and stored in the plurality of second devices, and provided to the first device.
  • the communication planning device may be mounted on a vehicle. This makes it possible to prevent leakage and tampering when communicating fragmented information in information management in which specific information (e.g., secret information) in the vehicle is divided into multiple pieces and stored in multiple second devices.
  • specific information e.g., secret information
  • a control method is a control method for communication between a first device and a second device in a system including a first device, a second device, and a communication device, the control method including a planning step in which a control unit plans communication of specific information between the first device and the second device, and a detection step in which the control unit detects state-specific information required for communication to be planned by the planning step, the planning step including a step in which the control unit plans communication of multiple pieces of fragmented information between the first device and the second device based on a detection result by the detection step, the fragmented information being information generated by dividing the specific information.
  • a computer program causes a computer mounted in a system including a first device, a second device, and a communication device to execute a planning function for planning communication of specific information between the first device and the second device, and a detection function for detecting state-specific information required for the communication to be planned by the planning function, the planning function including a function for planning communication of multiple pieces of fragmented information between the first device and the second device based on the detection result by the detection function, the fragmented information being information generated by dividing the specific information.
  • an in-vehicle system 100 is mounted on a vehicle.
  • the in-vehicle system 100 includes a first relay device 102, a second relay device 104, an E-ECU (End-Electronic Control Unit) 106, an E-ECU 108, and an E-ECU 110, an external communication unit 120, and a bus 122.
  • the first relay device 102 is, for example, a C-ECU (Central-Electronic Control Unit).
  • the second relay device is, for example, a Z-ECU (Zone-Electronic Control Unit).
  • the external device 130 is, for example, a server computer (hereinafter simply referred to as a server), a roadside device, and an in-vehicle device of another vehicle.
  • the in-vehicle system 100 communicates with an external device 130 via the external communication unit 120 to receive various information (traffic information and information to assist the driver (hereinafter referred to as driving assistance information)).
  • driving assistance information various information (traffic information and information to assist the driver (hereinafter referred to as driving assistance information)).
  • the in-vehicle system 100 realizes various functions using information acquired from the external device 130 and information obtained from sensors mounted on the vehicle in which the in-vehicle system 100 is mounted (hereinafter referred to as the vehicle itself).
  • the vehicle itself the vehicle itself.
  • the in-vehicle system 100 presents driving assistance information to the driver of the vehicle itself. If the vehicle itself is capable of autonomous driving, the in-vehicle system 100 realizes autonomous driving.
  • the external vehicle communication unit 120 performs two-way communication between the in-vehicle system 100 and the outside (i.e., the external device 130). For example, the external vehicle communication unit 120 performs wide-area wireless communication (4G and 5G, etc.) and close-proximity wireless communication (Wi-Fi and Bluetooth (registered trademark), etc.).
  • the external vehicle communication unit 120 performs wide-area wireless communication (4G and 5G, etc.) and close-proximity wireless communication (Wi-Fi and Bluetooth (registered trademark), etc.).
  • the second relay device 104 includes a control unit 140 and a memory 142, and functions as a communication planning device.
  • the control unit 140 includes a CPU (Central Processing Unit) and controls the memory 142.
  • the memory 142 is, for example, a rewritable non-volatile semiconductor memory, and stores a computer program (hereinafter simply referred to as a program) executed by the control unit 140.
  • the memory 142 provides a work area for the program executed by the control unit 140.
  • the second relay device 104 also includes multiple input/output ports. In FIG. 1, input/output port 144 and input/output port 146 are shown as representatives. The input/output ports can be connected to devices for testing and adjusting the in-vehicle system 100.
  • the second relay device 104 coordinates data exchange between the external communication unit 120 and the E-ECU 106, E-ECU 108, E-ECU 110, etc. That is, the second relay device 104 transmits data received from the external device 130 via the external communication unit 120 to the E-ECU that requires the data via the bus 122.
  • the second relay device 104 also acquires E-ECU data (e.g., sensor data from an on-board sensor) via the bus 122 and transmits the data to the external device 130 that requires the data via the external communication unit 120.
  • E-ECU data e.g., sensor data from an on-board sensor
  • communication between the second relay device 104 and the E-ECU 106, E-ECU 108, E-ECU 110, etc. may be performed via a wire harness instead of a bus.
  • the in-vehicle system 100 includes multiple E-ECUs, and FIG. 1 shows E-ECU 106, E-ECU 108, and E-ECU 110 as representatives.
  • Each E-ECU is a circuit for realizing the functions of the in-vehicle system 100 (control of vehicle driving, control of in-vehicle sensors, etc.), and includes a control unit and memory.
  • a control unit and memory For example, there is an engine control ECU, a stop-start control ECU, a transmission control ECU, an airbag control ECU, a power steering control ECU, a hybrid control ECU, etc.
  • An automatic driving ECU is also installed in a vehicle capable of automatic driving. The automatic driving ECU communicates with the outside as appropriate and obtains necessary information (traffic information and driving assistance information).
  • Information received from an external device 130 via the external communication unit 120 is used, for example, by the automatic driving ECU.
  • the sensor data acquired by the E-ECU, which controls the on-board sensors, is transmitted to an external device 130 (e.g., a server or another vehicle) via the second relay device 104 and the external communication unit 120, and is used to generate driving assistance information, etc.
  • the first relay device 102 like the second relay device 104, includes a control unit and memory, and executes a program for implementing the functions of the in-vehicle system 100.
  • the first relay device 102 may also include multiple input/output ports, like the second relay device 104.
  • the external device 130 includes an electronic key for a vehicle (hereinafter simply referred to as the electronic key), the external communication unit 120 has a function of communicating the electronic key, and the first relay device 102 recognizes the electronic key. If the user has the electronic key and is within a specified range of the vehicle (including the interior of the vehicle), the user can lock and unlock the doors, turn on the vehicle's power, start the engine, etc. In addition, the first relay device 102 receives a code corresponding to the user's operation of the electronic key via the external communication unit 120, and locks and unlocks the doors of the vehicle and automatically opens and closes the sliding door according to the code.
  • the electronic key an electronic key for a vehicle
  • the external communication unit 120 has a function of communicating the electronic key
  • the first relay device 102 recognizes the electronic key. If the user has the electronic key and is within a specified range of the vehicle (including the interior of the vehicle), the user can lock and unlock the doors, turn on the vehicle's power, start the engine, etc.
  • the in-vehicle system 100 may manage secret information. For example, to realize the above-mentioned operation using the electronic key, it is necessary to properly recognize the electronic key for the vehicle. For this purpose, a uniquely determined ID (hereinafter, referred to as an authentication ID) is exchanged between the electronic key and the in-vehicle system 100. Specifically, the electronic key transmits the authentication ID stored in the electronic key, and the in-vehicle system 100 judges whether the received authentication ID matches the authentication ID stored in the in-vehicle system 100. If they match, the user can perform the above-mentioned operations on the vehicle.
  • This authentication ID is secret information, and the in-vehicle system 100 plays a role in safely managing the secret information for a long period of time.
  • biometric information e.g., fingerprints and face images
  • personal information such as name, address, telephone number, and email address
  • the second relay device 104 includes a data division and restoration unit 200, a communication destination determination unit 202, a communication monitoring unit 204, and a secret distribution control unit 206. Each unit is realized by the control unit 140 and the memory 142 shown in FIG. 1.
  • the data division and restoration unit 200 receives a request from the first relay device 102 and executes a process corresponding to the request.
  • the data division and restoration unit 200 divides the target data 210 (information to be confidential, for example, confidential information) input together with the code into a plurality of pieces of fragmented information 212 as shown within a dashed line. After that, the data division and restoration unit 200 receives an instruction from a secret distribution control unit 206 described later, transmits the plurality of pieces of fragmented information 212 to a plurality of E-ECUs (for example, the E-ECU 108 and the E-ECU 110), and stores the pieces of fragmented information in each E-ECU.
  • a confidentiality request a code requesting confidentiality of information
  • a plurality of (e.g., n) pieces of fragmented information 212 are transmitted one-to-one to a plurality of (n) E-ECUs, the number of which is equal to the number of pieces of fragmented information 212, determined by the communication destination determination unit 202. Since the target data 210 is restored from the fragmented information 212, the target data 210 is also referred to as original data. Any method can be used to divide the target data 210 into the fragmented information 212, and for example, a secret sharing method can be used. Therefore, "division” does not only mean simply dividing one piece of target data into multiple pieces of data, but also means generating multiple pieces of data by converting and adding data.
  • the fragmented information 212 transmitted to the E-ECU is promptly erased from the data division and restoration unit 200 (memory 142 in FIG. 1) together with the original data.
  • the data division and restoration unit 200 acquires the fragmentation information 212 from the E-ECU that stores the corresponding fragmentation information 212. Specifically, the data division and restoration unit 200 requests the E-ECU that stores the fragmentation information 212 to transmit the fragmentation information 212. The data division and restoration unit 200 restores the original data from the multiple pieces of fragmentation information 212 received from the E-ECU.
  • the data division and restoration unit 200 can restore the original data if it can acquire from the E-ECU a number (k pieces) of fragmentation information that is less than the number (n pieces) of fragmentation information into which the original data was divided. After transmitting the restored original data to the first relay device 102, the data splitting and restoration unit 200 promptly deletes the original data and fragmentation information 212 from the data splitting and restoration unit 200 (memory 142 in FIG. 1).
  • a secret sharing method e.g., a (k, n) threshold method
  • the first relay device 102 can send a confidentiality request accompanied by information identifying the target data 210 (hereinafter referred to as original data identification information) to the data division and restoration unit 200.
  • original data identification information information identifying the target data 210
  • the data division and restoration unit 200 stores a table that matches the original data identification information with information identifying the E-ECU that transmitted the corresponding fragmentation information (shares in the secret sharing scheme) into which the target data 210 was divided (hereinafter referred to as E-ECU identification information)
  • the data division and restoration unit 200 can refer to the table to identify the E-ECU that will obtain the fragmentation information.
  • the communication destination determination unit 202 receives instructions from the data division and restoration unit 200 and determines an E-ECU in which to store each of the multiple fragmented information 212 in a one-to-one correspondence.
  • the communication destination determination unit 202 determines, from among the multiple E-ECUs mounted on the vehicle and capable of communicating with the second relay device 104, the same number of E-ECUs as the multiple fragmented information 212 as the multiple fragmented information 212 as communication destination devices.
  • the communication destination determination unit 202 stores information that identifies the determined communication destination device (E-ECU).
  • the method of determining the communication destination device is arbitrary, and the communication destination determination unit 202 may determine the communication destination device according to a predetermined rule or randomly.
  • the communication destination determination unit 202 may also determine the communication destination device taking into consideration the characteristics of each E-ECU (such as the real-time characteristics and memory capacity required for the function of each E-ECU).
  • the communication monitoring unit 204 monitors the communication state of the vehicle exterior communication unit 120, the state of the free ports (e.g., input/output port 144 and input/output port 146) among the multiple input/output ports, and the presence or absence of an unexpected communication device.
  • the communication monitoring unit 204 outputs information (hereinafter referred to as state identification information) indicating the detected communication state of the vehicle exterior communication unit 120, the state of the free ports, and the presence or absence of an unexpected communication device to the secret distribution control unit 206.
  • the communication monitoring unit 204 can be said to be a detection unit for the communication state of the vehicle exterior communication unit 120, the state of the free ports, and the presence or absence of an unexpected communication device.
  • the communication monitoring unit 204 may store the latest state identification information and output the state identification information to the secret distribution control unit 206 upon request from the secret distribution control unit 206.
  • the communication state of the vehicle exterior communication unit 120 means whether the vehicle exterior communication unit 120 is communicating with the external device 130 or not.
  • the state of the free port basically means whether or not a device is connected.
  • the communication state of the vehicle exterior communication unit 120 may include the type of communication (e.g., wide area wireless communication, close proximity wireless communication, and wired communication) and the communication speed (e.g., in Mbps) when the vehicle exterior communication unit 120 is communicating.
  • the state of the free port may include the nature of the device when a device is connected.
  • the wire harness may be modified and an unexpected communication device may be connected. Therefore, the communication monitoring unit 204 monitors whether an unexpected communication device is connected, that is, whether an unexpected communication device is connected to the communication path in the vehicle.
  • the secret distribution control unit 206 controls the timing at which the data division and restoration unit 200 communicates fragmentation information with the communication destination device (E-ECU) determined by the communication destination determination unit 202.
  • "Communication of fragmentation information” includes both communication in which the data division and restoration unit 200 transmits fragmentation information 212 to the communication destination device, and communication in which the data division and restoration unit 200 receives fragmentation information 212 stored in the communication destination device.
  • the secret distribution control unit 206 identifies the current communication state of the outside-vehicle communication unit 120, the connection state of an unused port, and the presence or absence of a connection of an unexpected communication device from the state identification information input from the communication monitoring unit 204, and accordingly determines whether or not to communicate fragmentation information (plans communication).
  • the secret distribution control unit 206 determines to communicate fragmentation information, it instructs the data division and restoration unit 200 to communicate, and the data division and restoration unit 200 executes the communication of the fragmentation information.
  • the data division and restoration unit 200 decides to communicate the fragmented information. If the vehicle exterior communication unit 120 is performing external communication (communication with the external device 130), a device is connected to an available port of the input/output port, or an unexpected communication device is connected, there is a relatively high risk of information leakage (hereinafter referred to as a dangerous state). Therefore, the data division and restoration unit 200 does not decide to communicate the fragmented information.
  • the data splitting and restoring unit 200 may decide to communicate the fragmentation information even if the dangerous state continues.
  • This predetermined period may be determined based on the characteristics (e.g., real-time performance) of the function of the first relay device 102 that uses the original data requested by the first relay device 102. If the required real-time performance is high, the predetermined period is set to be relatively short. If the required real-time performance is low, the predetermined period can be set to be relatively long.
  • the second relay device 104 can communicate fragmentation information with the E-ECU in a safe state, and can prevent the fragmentation information from leaking outside the vehicle during the communication process. Even in a dangerous state, the second relay device 104 can communicate fragmentation information with the E-ECU without impairing the real-time nature of the functions provided by the first relay device 102, and can avoid any disruption to the functions of the first relay device 102.
  • the operation of the second relay device 104 will be further described with reference to Fig. 3.
  • the process shown in Fig. 3 is realized by the control unit 140 of the second relay device 104 shown in Fig. 1 reading a predetermined program from the memory 142 and executing it.
  • the control unit 140 executes a program for realizing the function of the communication monitoring unit 204 shown in Fig. 2 in parallel with this program. That is, this program is for realizing the functions of the data division and restoration unit 200, the communication destination determination unit 202, and the secret distribution control unit 206 shown in Fig. 2.
  • a secret sharing scheme is used to generate the fragmentation information.
  • step 300 the control unit 140 determines whether or not a request has been received from the first relay device 102. As described above, the first relay device 102 outputs a concealment request or a restoration request to the second relay device 104. If it is determined that a request has been received, control proceeds to step 302. If not, control proceeds to step 324. As a result, while this program is being executed, the control unit 140 waits for a request from the first relay device 102. Note that, as described above, when the first relay device 102 outputs a concealment request, it also outputs the data to be concealed. Therefore, the control unit 140 receives the target data along with the concealment request.
  • step 302 the control unit 140 determines whether the request received in step 300 is a confidentiality request. If it is determined to be a confidentiality request, control proceeds to step 304. Otherwise (i.e., a restoration request has been received), control proceeds to step 308.
  • step 304 the control unit 140 selects an E-ECU from among the multiple E-ECUs that will store the share (fragmentation information) generated in a step described below as the communication destination device. Control then proceeds to step 306.
  • step 306 the control unit 140 divides the target data received in step 300 into multiple shares, as described above.
  • the control unit 140 generates multiple shares from the target data using a secret sharing scheme. After that, control proceeds to step 310.
  • step 308 the control unit 140 determines, from among the multiple E-ECUs, an E-ECU that stores a share for restoring the requested original data as the collection destination device (the device from which the share is obtained). Thereafter, control proceeds to step 310.
  • the communication destination device and the collection destination device include the same E-ECU.
  • the control unit 140 can receive original data identification information along with the restoration request as described above, and determine the collection destination device by referring to a table that associates original data identification information with E-ECU identification information.
  • shares are generated by a secret sharing method (e.g., a (k, n) threshold method)
  • the number of shares is n, while the number of shares to be collected may be k, which is less than or equal to n.
  • step 310 the control unit 140 acquires state identification information.
  • the state identification information includes information indicating the external vehicle communication state, the port connection state, and the presence or absence of a connection of an unexpected communication device.
  • the state identification information is information obtained by monitoring by the communication monitoring unit 204 shown in FIG. 2.
  • the function of the communication monitoring unit 204 is realized by a program executed by the control unit 140 in parallel with this program.
  • the state identification information is passed to this program, for example, via a specified area of the memory 142.
  • step 312 the control unit 140 determines whether the external communication state, the state of the available port, and the presence or absence of a connection of an unexpected communication device, which are represented by the state identification information acquired in step 310, are in the above-mentioned safe state. If it is determined that the safe state is present, control proceeds to step 316. If not, control proceeds to step 314.
  • step 314 the control unit 140 determines whether or not the predetermined period has elapsed. If it is determined that the predetermined period has elapsed, control proceeds to step 316. If not, control returns to step 310, and steps 310 and 312 are repeated.
  • the predetermined period may be determined based on the characteristics (e.g., real-time characteristics) of the function of the first relay device 102 that uses the original data requested by the first relay device 102.
  • step 316 the control unit 140 executes the same process as in step 302. If it is determined to be a confidentiality request, control proceeds to step 318. If not (i.e., a restoration request is received), control proceeds to step 320.
  • step 318 the control unit 140 transmits the multiple shares generated in step 306 to the destination device (E-ECU) determined in step 304.
  • the destination device E-ECU
  • either one share or multiple shares may be transmitted to one destination device.
  • care must be taken to ensure that one share is not transmitted in duplicate to multiple destination devices.
  • it is necessary to limit the number of shares transmitted to one destination device so that the original data is not restored by the multiple shares transmitted to one destination device. For example, when shares are generated using the (k, n) threshold method, less than k shares are transmitted to one destination device.
  • the control unit 140 erases all shares. Control then proceeds to step 324.
  • step 320 the control unit 140 obtains the share from the collection destination device (E-ECU) determined in step 308 and restores the original data. After that, control proceeds to step 322.
  • step 322 the control unit 140 transmits the original data restored in step 320 to the first relay device 102. Thereafter, control proceeds to step 324.
  • the first relay device 102 can obtain the data requested from the second relay device 104, and passes the data to the application software (hereinafter simply referred to as the application) that requires it.
  • step 324 the control unit 140 determines whether or not an instruction to end has been received. If it is determined that an instruction to end has been received, the program ends. If not, control returns to step 300, and the above processing is repeated.
  • An instruction to end is given, for example, by turning off a start button or the like of the vehicle in which the in-vehicle system 100 is mounted.
  • the second relay device 104 communicates multiple fragmented information (shares) in a safe state, thereby preventing leakage and tampering during communication.
  • the second relay device 104 communicates fragmentation information with the E-ECU after a predetermined period of time has elapsed so as not to impair the real-time nature of the functions provided by the first relay device 102, thereby preventing a state in which multiple pieces of fragmentation information cannot be communicated from continuing indefinitely. This makes it possible to avoid any disruption to the functions of the first relay device 102.
  • the specified period based on the characteristics (e.g., real-time performance) of the function of the first relay device 102 that requires the original data to be restored using the fragmentation information, it is possible to avoid compromising the real-time performance required for the function of the first relay device 102.
  • the system includes a data division and restoration unit 200 that divides the target data into multiple pieces of fragmented information, and the target data is input from the first relay device 102 to the second relay device 104, and the data division and restoration unit 200 generates the fragmented information using a secret sharing scheme. This makes it possible to further prevent information leakage and tampering.
  • the second relay device 104 includes a communication destination determination unit 202 that determines, from among the multiple E-ECUs, E-ECUs whose number is equal to or less than the number of pieces of fragmentation information as communication destination devices, and each of the multiple pieces of fragmentation information is communicated between the communication destination device and the second relay device 104 based on a plan set by the secret distribution control unit 206. This makes it possible to further prevent information leakage and tampering.
  • the communication destination determination unit 202 determines from among the multiple communication destination devices (E-ECUs) multiple partner devices (E-ECUs) from which to obtain fragmented information, and the data division and restoration unit 200 has a restoration function that generates specific information from the fragmented information received from the multiple partner devices. This makes it possible to generate original data from the fragmented information stored in a distributed manner in the multiple E-ECUs and provide it to the first relay device 102.
  • the second relay device 104 is mounted on the vehicle. This makes it possible to prevent leakage and tampering when communicating fragmented information in information management in which specific information (e.g., secret information) in the vehicle is divided into multiple pieces and stored in multiple E-ECUs.
  • specific information e.g., secret information
  • the authentication ID (secret information) of the electronic key described above may be divided to generate a plurality of pieces of fragmented information, and each of the plurality of pieces of fragmented information may be stored in a plurality of E-ECUs of the in-vehicle system 100.
  • the first relay 102 of the in-vehicle system 100 performs an authentication process of the electronic key held by the user in advance.
  • the second relay 104 of the in-vehicle system 100 receives a restoration request from the first relay 102, acquires the fragmented information from the E-ECU that stores the fragmented information, decomposes the in-vehicle authentication ID, and outputs it to the first relay 102.
  • the first relay 102 determines whether the authentication ID received from the electronic key matches the restored authentication ID.
  • the second relay device 104 acquires the fragmentation information via communication from the E-ECU that stores the fragmentation information, thereby avoiding the risk that the fragmentation information will be acquired by a third party during the process of communicating the fragmentation information, and that the authentication ID will become known to the third party.
  • the specified period is set to be relatively short.
  • the in-vehicle system according to the first modification has the same configuration as the in-vehicle system 100 shown in FIG. 1, and the configuration of the second relay device according to the first modification is different from that shown in FIG. 2.
  • the second relay device 104A according to the first modification includes a data division and restoration unit 200, a communication destination determination unit 202, a communication monitoring unit 204, a secret distribution control unit 206, and a security strength evaluation unit 220, and functions as a communication planning device. Each unit is realized by the control unit 140 and memory 142 shown in FIG. 1.
  • the second relay device 104A shown in FIG. 4 is the second relay device 104 shown in FIG. 2 to which a security strength evaluation unit 220 has been added.
  • FIG. 4 The second relay device 104A shown in FIG. 4 is the second relay device 104 shown in FIG. 2 to which a security strength evaluation unit 220 has been added.
  • the components with the same reference numerals as those in FIG. 2 have the same functions as those in FIG. 2. Therefore, the following description will not be repeated, and mainly the differences will be described. Also, the second relay device 104 in FIG. 1 will be read as the second relay device 104A, and the reference numerals shown in FIG. 1 will be referred to as appropriate.
  • the security strength evaluation unit 220 evaluates the security strength based on the state identification information input from the communication monitoring unit 204, and outputs the evaluation result to the secret distribution control unit 206.
  • the state identification information is information that represents the communication state of the exterior communication unit 120, the state of free ports such as the input/output port 144 and the input/output port 146, and whether or not an unexpected communication device is connected, which are detection results by the communication monitoring unit 204.
  • the security strength evaluation unit 220 stores evaluation tables such as those shown in Figures 5 and 6, for example, in order to determine the security strength from the communication state of the exterior communication unit 120, the state of free ports, and whether or not an unexpected communication device is connected.
  • the communication state of the vehicle exterior communication unit 120 is represented by a combination of communication type and communication speed.
  • the security strength for the combination of communication type and communication speed is represented by three levels: “high”, “medium” and “low”.
  • the communication types shown are physical communication (wired communication), close proximity wireless communication and wide area wireless communication.
  • the communication speed is divided into three ranges: less than a (Mbps), a (Mbps) or more and less than b (Mbps), and b (Mbps) or more.
  • a and b are real numbers that satisfy 0 ⁇ a ⁇ b.
  • the setting of each level for example, when the communication speed is high, the risk of information leakage due to unauthorized access increases, so the security strength is set relatively low.
  • the communication type unauthorized access is relatively easy during wide area wireless communication, so the security strength is set relatively low.
  • FIG. 6 shows an example of setting security strength for a combination of the state of an empty port and the presence or absence of a connection of an unexpected communication device.
  • the state of an empty port is represented by the presence or absence of a connection of a device, and, if a device is connected, whether the device is an expected device.
  • an expected device means a device that is known to be safe
  • an unexpected device means a device that is not known to be safe.
  • the presence or absence of a connection of an unexpected communication device is represented by connected and not connected.
  • "minimum" is used to represent a level lower than the three levels shown in FIG. 5.
  • the security strength is set to "minimum". "-" is shown for the case where no device is connected to an empty port and no unexpected communication device is connected. In such a case, secret sharing is possible without calculating the security strength, so "-" is shown to represent that it is not taken into consideration, that is, that the security strength is not calculated. Furthermore, whether or not a device connected to an available port is an expected device can be determined by storing information about expected devices (devices known to be safe) in advance.
  • the security strength evaluation unit 220 identifies the communication state of the exterior communication unit 120, the state of the free port, and whether or not an unexpected communication device is connected based on the state identification information received from the communication monitoring unit 204, and identifies the levels of each of the communication state and the state of the free port of the exterior communication unit 120 by referring to the evaluation table (see Figures 5 and 6). Since two levels are identified, the security strength evaluation unit 220 determines the lower of the two levels as the security strength.
  • the secret distribution control unit 206 determines whether or not to communicate fragmented information with each E-ECU, depending on the security strength input from the security strength evaluation unit 220. Even if the detection result of the communication monitoring unit 204 is a dangerous state, the secret distribution control unit 206 decides to communicate fragmented information with each E-ECU if the security strength is at or above a predetermined level. This makes it possible to avoid unnecessarily suppressing communication of multiple pieces of fragmented information, and to control communication of multiple pieces of fragmented information depending on the risk of information leakage.
  • security strength is evaluated based on the communication state of the external communication unit 120, the state of the free port, and whether or not an unexpected communication device is connected, but this is not limiting.
  • Security strength may also be evaluated based on at least one of the communication state of the external communication unit 120, the state of the free port, and whether or not an unexpected communication device is connected. This allows the security strength to be appropriately evaluated.
  • the security strength is determined based on the communication state of the external communication unit 120, the connection state of free ports, and whether or not an unexpected communication device is connected, but this is not limiting.
  • the security strength may be determined according to the nature of the data to be concealed. For example, if the data is highly confidential or important, the security strength is set low in consideration of the impact of information leakage.
  • FIG. 7 A secret sharing scheme is used to generate fragmentation information.
  • the process shown in FIG. 7 is realized by the control unit 140 reading a predetermined program from the memory 142 and executing it, similar to the second relay device 104 shown in FIG. 1.
  • the control unit 140 executes a program for implementing the function of the communication monitoring unit 204 shown in FIG. 2 in parallel with this program. That is, this program is for implementing the functions of the data division and restoration unit 200, the communication destination determination unit 202, the secret sharing control unit 206, and the security strength evaluation unit 220 shown in FIG. 4.
  • the flowchart in FIG. 7 is the flowchart shown in FIG. 3 to which steps 340 and 342 have been added. In FIG. 7, the steps with the same reference numerals as those in FIG. 3 execute the same process as in FIG. 3. Therefore, the following description will not be repeated and will be mainly focused on the differences.
  • step 340 the control unit 140 evaluates the security strength S. Then, control proceeds to step 312. This corresponds to the function of the security strength evaluation unit 220 described above.
  • the control unit 140 determines the security strength by referring to the evaluation table as described above.
  • the security strength is represented by, for example, four levels, "high,” “medium,” “low,” and “lowest,” as described above.
  • step 312 the control unit 140 determines whether the external vehicle communication state, the state of the available port, and the presence or absence of an unexpected communication device connection are in a safe state, as described above. If the safe state is determined, control proceeds to step 316; if not, control proceeds to step 342.
  • step 342 the control unit 140 determines whether the security strength determined in step 340 is equal to or greater than a predetermined threshold value Th. If it is determined that S ⁇ Th (security strength is equal to or greater than the predetermined threshold value Th), control proceeds to step 316. Otherwise, control proceeds to step 314.
  • security strength is represented by four levels: “high”, “medium”, “low” and “lowest”, so the threshold value Th is set to one of “high”, “medium”, “low” and “lowest”. For example, if the threshold value Th is set to "medium”, and the security strength S is "high” or "medium”, it is determined that S ⁇ Th.
  • the second relay device 104A like the second relay device 104, manages information by dividing specific information (e.g., secret information) into multiple pieces and storing them in multiple E-ECUs, and communicates multiple fragmented information (shares) in a safe state, thereby preventing leakage and tampering during communication.
  • specific information e.g., secret information
  • the second relay device 104A determines whether or not to communicate fragmented information with each E-ECU according to the security strength (see step 342). Even if the state is not safe, the second relay device 104A decides to communicate fragmented information with each E-ECU if the security strength is at or above a predetermined level (the determination result in step 342 is YES). This makes it possible to avoid unnecessarily suppressing communication of multiple pieces of fragmented information, and to control communication of multiple pieces of fragmented information according to the risk of information leakage.
  • the first relay 102 executes an application for monitoring the inside of the vehicle.
  • the camera 160 is, for example, a digital video camera.
  • the first relay 102 divides a large amount of in-vehicle monitoring video data captured by the camera 160 into fragmented information, and stores the fragmented information in a plurality of E-ECUs from the second relay 104A.
  • the security strength can be set relatively high.
  • a drive recorder when a drive recorder is connected to an available port of the second relay device 104A or the first relay device 102, if the drive recorder is provided by a dealer, it is included in the expected equipment, so the security strength can be set relatively high.
  • a dealer means, for example, a reliable sales company that has a contract with an automobile manufacturer or a sales company affiliated with the automobile manufacturer.
  • Information for identifying a drive recorder provided by a dealer can be stored in advance in the memory of the second relay device 104A.
  • the second relay device 104A can access the connected equipment and obtain information about the equipment (function of the communication monitoring unit 204) to determine whether it is a dealer's drive recorder.
  • the security strength evaluation unit 220 can receive the judgment result of the communication monitoring unit 204, refer to the evaluation table described above, and determine the security strength.
  • security strength is expressed by four levels, "high,” “medium,” “low,” and “lowest,” has been described, but is not limited to this.
  • Security strength may be expressed by multiple levels, and may be expressed by three or fewer levels, or five or more levels.
  • Security strength may also be expressed by a numerical value (such as a positive integer). In this case, each level may be set as a predetermined numerical range.
  • the in-vehicle system according to the second modification has the same configuration as the in-vehicle system 100 shown in FIG. 1, and the configuration of the second relay device according to the second modification is different from that shown in FIG. 2.
  • the second relay device 104B according to the second modification includes a data division and restoration unit 200, a communication destination determination unit 202, a communication monitoring unit 204, a secret distribution control unit 206, and a communication control unit 230, and functions as a communication planning device. Each unit is realized by the control unit 140 and memory 142 shown in FIG. 1.
  • the second relay device 104B shown in FIG. 9 is the second relay device 104 shown in FIG. 2 to which a communication control unit 230 has been added. In FIG.
  • the components with the same reference numerals as those in FIG. 2 have the same functions as those in FIG. 2. Therefore, the following description will not be repeated, and mainly the differences will be described. Also, the second relay device 104 in FIG. 1 will be read as the second relay device 104B, and the reference numerals shown in FIG. 1 will be referred to as appropriate.
  • the communication control unit 230 judges whether or not communication by the vehicle exterior communication unit 120 can be temporarily disconnected.
  • the communication control unit 230 outputs the judgment result to the secret distribution control unit 206.
  • the secret distribution control unit 206 judges whether or not to communicate fragmented information with each E-ECU according to the judgment result input from the communication control unit 230. If the judgment result input from the communication control unit 230 indicates that disconnection is possible, the secret distribution control unit 206 instructs the communication control unit 230 to disconnect communication by the vehicle exterior communication unit 120 and decides to communicate fragmented information with each E-ECU.
  • the communication control unit 230 Upon receiving the instruction to disconnect communication, the communication control unit 230 causes the vehicle exterior communication unit 120 to disconnect communication and maintain the disconnected state for a predetermined period (second predetermined period). Once the specified period has elapsed, the communication control unit 230 causes the exterior communication unit 120 to resume communication.
  • the specified period for disconnecting communication by the external communication unit 120 is set to a period equal to or longer than the period during which communication of fragmentation information between the second relay device 104 and the E-ECU can be completed. If set in this manner, communication by the external communication unit 120 is maintained in a disconnected state while communication of fragmentation information is in progress.
  • the communication control unit 230 determines whether or not the communication by the vehicle exterior communication unit 120 can be temporarily cut off. For example, when the vehicle is using a service that communicates with an external device and cutting off the communication would make the vehicle unable to travel, the communication control unit 230 determines that the communication by the vehicle exterior communication unit 120 cannot be cut off. For example, when a function such as remote control and blind spot information sharing is being executed, the communication control unit 230 determines that the communication by the vehicle exterior communication unit 120 cannot be cut off.
  • the communication control unit 230 determines that the communication by the vehicle exterior communication unit 120 can be cut off.
  • the communication by the vehicle exterior communication unit 120 is related to a function that requires real-time performance, not limited to the autonomous traveling function, the communication control unit 230 determines that the communication by the vehicle exterior communication unit 120 cannot be cut off.
  • the communication control unit 230 may determine that communication with the exterior communication unit 120 can be disconnected. For example, if the second relay device 104 can complete communication of fragmentation information with each E-ECU during the period from when the data is stored in the buffer to when the use (playback) of the data ends (hereinafter referred to as the buffer period), the communication control unit 230 may determine that communication with the exterior communication unit 120 can be disconnected. Also, the communication control unit 230 may determine that communication with the exterior communication unit 120 can be disconnected when a block of music data or video data can be downloaded in a lump and then played back.
  • the secret distribution control unit 206 decides to cut off communication with the exterior communication unit 120 and to communicate fragmented information with each E-ECU. This makes it possible to avoid a state in which fragmented information cannot be communicated continuing indefinitely.
  • the above describes a case in which communication with the exterior communication unit 120 is cut off, this is not limiting. It is sufficient if communication with the exterior communication unit 120 can be restricted. By restricting communication with the exterior communication unit 120, leakage of fragmented information during the communication process of fragmented information can be suppressed.
  • the communication control unit 230 may determine that communication by the vehicle exterior communication unit 120 can be blocked. This allows multiple pieces of fragmented information to be communicated while avoiding loss of the real-time performance required for the function.
  • the buffer period for a predetermined amount of data in communication by the vehicle exterior communication unit 120 is longer than the period required to communicate multiple pieces of fragmented information, it may be determined that communication by the vehicle exterior communication unit 120 can be restricted. This allows multiple pieces of fragmented information to be communicated without affecting the function that is executing the external communication.
  • the operation of the second relay device 104B will be further described with reference to FIG. 10.
  • a secret sharing scheme is used to generate fragmentation information.
  • the process shown in FIG. 10 is realized by the control unit 140 reading a predetermined program from the memory 142 and executing it, similar to the second relay device 104 shown in FIG. 1.
  • the control unit 140 executes a program for implementing the function of the communication monitoring unit 204 shown in FIG. 2 in parallel with this program. That is, this program is for implementing the functions of the data division and restoration unit 200, the communication destination determination unit 202, the secret sharing control unit 206, and the communication control unit 230 shown in FIG. 9.
  • the flowchart in FIG. 10 is the flowchart shown in FIG.
  • step 314 is replaced by step 350, and step 352 and step 354 are added.
  • step 352 and step 354 are added.
  • FIG. 10 the steps with the same reference numerals as those in FIG. 3 execute the same process as in FIG. 3. Therefore, the following description will not be repeated, and mainly the differences will be described.
  • step 312 the control unit 140 determines whether the communication state of the external communication unit 120, the state of the free port, and the presence or absence of a connection of an unexpected communication device are in a safe state, as described above. If it is determined that the communication state is in a safe state, control proceeds to step 316. If not, control proceeds to step 350.
  • step 350 the control unit 140 determines whether or not communication of the external-vehicle communication unit 120 can be disconnected. If it is determined that communication can be disconnected, control proceeds to step 352. If not, control returns to step 310, and steps 310 and 312 are executed. As a result, if it is not a safe state (the determination result of step 312 is NO), the standby state is maintained and sharing communication is not performed until communication of the external-vehicle communication unit 120 can be disconnected.
  • step 352 the control unit 140 temporarily disconnects communication from the external communication unit 120. Then, control proceeds to step 316. Steps 350 and 352 correspond to the functions of the communication control unit 230 described above.
  • step 316 the process according to the request from the first relay device 102 is executed as described above. That is, the share is transmitted to the E-ECU (step 318), or the share is collected from the E-ECU and the original data is restored (steps 320 and 322). After that, control proceeds to step 354.
  • step 354 the control unit 140 causes the exterior communication unit 120 to resume the communication that was disconnected in step 352. Then, control proceeds to step 324.
  • the second relay device 104B decides to cut off communication with the external communication unit 120 and communicate fragmentation information (share) with each E-ECU. This makes it possible to avoid a situation in which it is not possible to communicate fragmentation information continuing indefinitely.
  • the communication planning device is described as being the second relay device 104, the second relay device 104A, and the second relay device 104B mounted on a vehicle, but is not limited to this.
  • the communication planning device may be mounted on a device or system that has the function of communicating with the outside of the device.
  • the communication planning device executes the above-mentioned operation. This makes it possible to suppress information leakage during the communication process of the fragmented information within the device or system.
  • each process (each function) of the above-mentioned embodiments and variations may be realized by a processing circuit (circuitry) including one or more processors.
  • the processing circuit may be configured by an integrated circuit or the like that combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors.
  • the one or more memories store programs (instructions) that cause the one or more processors to execute each of the above processes.
  • the one or more processors may execute each of the above processes according to the programs read from the one or more memories, or may execute each of the above processes according to a logic circuit that has been designed in advance to execute each of the above processes.
  • the processor may be any of various processors suitable for computer control, such as a CPU, a GPU (Graphics Processing Unit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), or an ASIC (Application Specific Integrated Circuit).
  • the physically separated processors may cooperate with each other to execute the above processes.
  • the processors mounted on each of the physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), or the Internet to execute the above processes.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Small-Scale Networks (AREA)

Abstract

通信計画装置は、第1装置、第2装置および通信装置を含むシステムに搭載される通信計画装置であって、第1装置および第2装置の間における所定情報の通信を計画する計画部と、計画部が通信を計画するために必要となる状態特定情報を検知する検知部とを含み、計画部は、検知部による検知結果に基づいて、第1装置および第2装置の間における複数の断片化情報の通信を計画し、断片化情報は、所定情報が分割されることにより生成される情報である。

Description

通信計画装置、制御方法およびコンピュータプログラム
 本開示は、通信計画装置、制御方法およびコンピュータプログラムに関する。本出願は、2023年6月9日出願の日本出願第2023-095150号に基づく優先権を主張し、前記日本出願に記載された全ての記載内容を援用するものである。
 車載システムにおいてセキュリティは重要である。そのために、情報の秘匿化が行われる。秘匿化の方法として暗号化が一般に知られているが、それ以外の方法として秘密分散法がある。秘密分散法は、保護対象データを分散させて管理することにより、情報の秘匿化を実現する。
 下記特許文献1には、全ノードペア間にフルメッシュのセキュアな通信路が存在するネットワークにおいて、秘密分散法を用いて秘密情報を複数のノード群に分散して保持する分散情報転送システムが開示されている。この分散情報転送システムは、攻撃者が操作するノードが複数存在する場合に、第1のシェアを再度分散して配布することによって、攻撃者が必要十分なシェアを収集することを防ぎ、セキュアな状態を維持する。
特開2012-100140号公報
 本開示のある局面に係る通信計画装置は、第1装置、第2装置および通信装置を含むシステムに搭載される通信計画装置であって、第1装置および第2装置の間における所定情報の通信を計画する計画部と、計画部が通信を計画するために必要となる状態特定情報を検知する検知部とを含み、計画部は、検知部による検知結果に基づいて、第1装置および第2装置の間における複数の断片化情報の通信を計画し、断片化情報は、所定情報が分割されることにより生成される情報である。
図1は、本開示の実施形態に係る車載システムの構成を示すブロック図である。 図2は、図1に示した第2中継装置の機能的構成を示すブロック図である。 図3は、図1に示した第2中継装置により実行される処理を示すフローチャートである。 図4は、第1変形例に係る第2中継装置の機能的構成を示すブロック図である。 図5は、セキュリティ強度を決定するために考慮される通信情報をテーブル形式により示す図である。 図6は、セキュリティ強度を決定するために考慮される空きポートの情報および想定外の通信装置の接続の有無をテーブル形式により示す図である。 図7は、第1変形例に係る第2中継装置により実行される処理を示すフローチャートである。 図8は、第1変形例に係る車載システムの構成例を示すブロック図である。 図9は、第2変形例に係る第2中継装置の機能的構成を示すブロック図である。 図10は、第2変形例に係る第2中継装置により実行される処理を示すフローチャートである。
 [本開示が解決しようとする課題]
 特許文献1においては、通信経路がセキュアであることを前提としているが、現実には通信経路がセキュアでない場合が存在する。その場合には、特許文献1に開示された技術によっては、通信経路において不正アクセスにより情報漏洩する危険性を回避できない問題がある。
 したがって、本開示は、秘密情報を複数に分割して複数のノードに保存する情報管理において、分割された情報を通信する際に漏洩および改竄の発生を防止できる通信計画装置、制御方法およびコンピュータプログラムを提供することを目的とする。
 [本開示の効果]
 本開示によれば、秘密情報を複数に分割して複数のノードに保存する情報管理において、分割された情報を通信する際に漏洩および改竄の発生を防止できる通信計画装置、制御方法およびコンピュータプログラムを提供できる。
 [本開示の実施形態の説明]
 本開示の実施形態の内容を列記して説明する。以下に記載する実施形態の少なくとも一部を任意に組合せてもよい。
 (1)本開示の第1の局面に係る通信計画装置は、第1装置、第2装置および通信装置を含むシステムに搭載される通信計画装置であって、第1装置および第2装置の間における所定情報の通信を計画する計画部と、計画部が通信を計画するために必要となる状態特定情報を検知する検知部とを含み、計画部は、検知部による検知結果に基づいて、第1装置および第2装置の間における複数の断片化情報の通信を計画し、断片化情報は、所定情報が分割されることにより生成される情報である。これにより、所定情報(例えば、秘密にすべき情報(以下、秘密情報という))を複数に分割して複数の装置に保存する情報管理において、分割された情報である断片化情報を通信する際に漏洩および改竄の発生を防止できる。
 (2)上記(1)において、状態特定情報は、通信装置によるシステム外との通信である外部通信の通信状態、通信計画装置および第1装置の各々が有する入出力ポートの状態、ならびに、システム内の通信経路への想定外の通信装置の接続の有無のうちの少なくともいずれかの状態を表す情報を含む。これにより、断片化情報を通信する際に漏洩および改竄の発生をより防止できる。
 (3)上記(1)または(2)において、計画部は、検知結果に基づいて複数の断片化情報の通信を行わないとの計画になる場合においては、第1所定期間が経過すれば、複数の断片化情報を通信するように計画することができる。これにより、複数の断片化情報を通信できない状態がいつまでも持続することを回避できる。
 (4)上記(3)において、第1所定期間は、複数の断片化情報の通信を必要とする機能のリアルタイム性に基づいて決定されてもよい。これにより、機能に要求されるリアルタイム性が損なわれることを回避できる。
 (5)上記(1)から(4)のいずれか1つにおいて、通信計画装置は、システムからの情報漏洩に関するセキュリティ強度を評価するセキュリティ強度評価部をさらに含んでいてもよく、計画部は、検知結果に基づいて複数の断片化情報の通信を行わないとの計画になる場合においては、セキュリティ強度評価部により評価されたセキュリティ強度が所定レベル以上であれば、複数の断片化情報を通信するように計画してもよい。これにより、複数の断片化情報の通信が、必要以上に抑制されることを回避でき、情報漏洩の危険度に応じて、複数の断片化情報の通信を制御できる。
 (6)上記(5)において、セキュリティ強度評価部は、検知部による検知結果に基づいて、セキュリティ強度を評価してもよい。これにより、セキュリティ強度を適切に評価できる。
 (7)上記(1)から(6)のいずれか1つにおいて、通信計画装置は、通信装置に、通信装置によるシステム外との通信である外部通信を制限させる通信制御部をさらに含んでいてもよく、計画部は、外部通信が制限可能であれば、通信制御部に、第2所定期間において外部通信を制限させ、第2所定期間において、複数の断片化情報を通信するように計画してもよい。これにより、複数の断片化情報を通信できない状態がいつまでも持続することを回避できる。
 (8)上記(7)において、計画部は、外部通信が、リアルタイム性が要求される機能のために実行されていなければ、外部通信が制限可能であると判定してもよい。これにより、機能に要求されるリアルタイム性が損なわれることを回避しつつ、複数の断片化情報を通信できる。
 (9)上記(7)において、計画部は、外部通信において所定量のデータがバッファに記憶されてから当該データの利用が終了するまでの期間が、複数の断片化情報の通信に要する期間よりも長ければ、外部通信が制限可能であると判定してもよい。これにより、外部通信を実行している機能に影響することなく、複数の断片化情報を通信できる。
 (10)上記(1)から(9)のいずれか1つにおいて、通信計画装置は、所定情報を複数の断片化情報に分割する情報処理部をさらに含んでいてもよく、所定情報は、第1装置から通信計画装置を介して第2装置に送信されてもよく、情報処理部は、秘密分散法により断片化情報を生成してもよい。これにより、情報の漏洩および改竄の発生をより防止できる。
 (11)上記(10)において、通信計画装置は、複数の第2装置の中から、複数の断片化情報の個数以下の個数の通信先装置を決定する通信先決定部をさらに含んでいてもよく、複数の断片化情報は、通信先装置と通信計画装置との間において、計画部による計画に基づいて通信されてもよい。これにより、情報の漏洩および改竄の発生をより一層防止できる。
 (12)上記(11)において、通信先決定部は、第1装置から通信計画装置に所定情報の要求が入力されたことを受けて、複数の通信先装置の中から、断片化情報を受信する複数の相手装置を決定してもよく、通信計画装置は、複数の相手装置から受信した断片化情報から、所定情報を生成する復元部をさらに含んでいてもよい。これにより、複数の第2装置に分散させて記憶している断片化情報から所定情報を生成して第1装置に提供できる。
 (13)上記(1)から(12)のいずれか1つにおいて、通信計画装置は、車両に搭載されていてもよい。これにより、車両における所定情報(例えば秘密情報)を複数に分割して複数の第2装置に保存する情報管理において、断片化情報を通信する際に漏洩および改竄の発生を防止できる。
 (14)本開示の第2の局面に係る制御方法は、第1装置、第2装置および通信装置を含むシステムにおける第1装置および第2装置間の通信の制御方法であって、制御部が、第1装置および第2装置の間における所定情報の通信を計画する計画ステップと、制御部が、計画ステップにより通信が計画されるために必要となる状態特定情報を検知する検知ステップとを含み、計画ステップは、制御部が、検知ステップによる検知結果に基づいて、第1装置および第2装置の間における複数の断片化情報の通信を計画するステップを含み、断片化情報は、所定情報が分割されることにより生成される情報である。これにより、所定情報(例えば秘密情報)を複数に分割して複数の第2装置に保存する情報管理において、分割された情報である断片化情報を通信する際に漏洩および改竄の発生を防止できる。
 (15)本開示の第3の局面に係るコンピュータプログラムは、第1装置、第2装置および通信装置を含むシステムに搭載されるコンピュータに、第1装置および第2装置の間における所定情報の通信を計画する計画機能と、計画機能により通信が計画されるために必要となる状態特定情報を検知する検知機能とを実行させ、計画機能は、検知機能による検知結果に基づいて、第1装置および第2装置の間における複数の断片化情報の通信を計画する機能を含み、断片化情報は、所定情報が分割されることにより生成される情報である。これにより、所定情報(例えば秘密情報)を複数に分割して複数の第2装置に保存する情報管理において、分割された情報である断片化情報を通信する際に漏洩および改竄の発生を防止できる。
 [本開示の実施形態の詳細]
 以下の実施形態においては、同一の部品には同一の参照番号を付してある。それらの名称および機能も同一である。したがって、それらについての詳細な説明は繰返さない。
(全体構成)
 図1を参照して、本開示の実施形態に係る車載システム100は、車両に搭載される。車載システム100は、第1中継装置102と、第2中継装置104と、E-ECU(End-Electronic Control Unit)106、E-ECU108およびE-ECU110と、車外通信部120と、バス122とを含む。第1中継装置102は、例えばC-ECU(Central-Electronic Control Unit)である。第2中継装置は、例えば、Z-ECU(Zone-Electronic Control Unit)である。外部装置130は、例えば、サーバコンピュータ(以下、単にサーバという)、路側装置および他車両の車載装置である。車載システム100は、車外通信部120を介して外部装置130と通信し、種々の情報(交通情報および運転者を支援する情報(以下、運転支援情報という))を受信する。車載システム100は、外部装置130から取得した情報と、車載システム100が搭載された車両(以下、自車両という)に搭載されているセンサから得られた情報とを用いて、種々の機能を実現する。例えば、車載システム100は、自車両の運転者に運転支援情報を提示する。自車両が自動運転可能であれば、車載システム100は自動運転を実現する。
 車外通信部120は、搭載されている車載システム100と、その外部(即ち外部装置130)との双方向通信を行う。例えば、車外通信部120は、広域無線通信(4Gおよび5G等)および近接無線通信(Wi-FiおよびBluetooth(登録商標)等)を行う。
 第2中継装置104は、制御部140およびメモリ142を含み、通信計画装置として機能する。制御部140は、CPU(Central Processing Unit)を含んで構成されており、メモリ142を制御する。メモリ142は、例えば、書換可能な不揮発性の半導体メモリであり、制御部140が実行するコンピュータプログラム(以下、単にプログラムという)を記憶している。メモリ142は、制御部140が実行するプログラムのワーク領域を提供する。また、第2中継装置104は、複数の入出力ポートを含む。図1においては、代表的に入出力ポート144および入出力ポート146を示している。入出力ポートは、車載システム100の試験および調整等のための機器が接続され得る。
 第2中継装置104は、車外通信部120およびE-ECU106、E-ECU108およびE-ECU110等との間のデータ交換を調整する。即ち、第2中継装置104は、外部装置130から車外通信部120を介して受信されたデータを、そのデータを必要とするE-ECUに、バス122を介して伝送する。また、第2中継装置104は、E-ECUのデータ(例えば、車載センサのセンサデータ)を、バス122を介して取得し、車外通信部120を介してそのデータを必要とする外部装置130に送信する。なお、第2中継装置104と、E-ECU106、E-ECU108およびE-ECU110等との間の通信は、バスではなくワイヤーハーネスを介して行われてもよい。
 車載システム100は、複数のE-ECUを含み、図1においては、代表的にE-ECU106、E-ECU108およびE-ECU110を示す。各E-ECUは、車載システム100の機能(車両走行の制御、車載センサの制御等)を実現するための回路であり、制御部およびメモリを含む。例えば、エンジン制御ECU、ストップスタート制御ECU、トランスミッション制御ECU、エアバッグ制御ECU、パワーステアリング制御ECU、ハイブリッド制御ECU等がある。自動運転可能な車両には、自動運転用ECUも搭載されている。自動運転用ECUは、適宜外部と通信し、必要な情報(交通情報および運転支援情報)の取得を行う。車外通信部120を介して、外部装置130から受信した情報は、例えば、自動運転用ECUにより利用される。車載センサの制御を担うE-ECUにより取得されたセンサデータは、第2中継装置104および車外通信部120を介して、外部装置130(例えばサーバまたは他車両)に送信され、運転支援情報の生成等に利用される。
 第1中継装置102は、第2中継装置104と同様に、制御部およびメモリを含み、車載システム100の機能を実現するためのプログラムを実行する。また、第1中継装置102は、第2中継装置104と同様に複数の入出力ポートを備え得る。
 例えば、外部装置130は、車両用電子キー(以下、単に電子キーという)を含み、車外通信部120は電子キーを通信する機能を有し、第1中継装置102は電子キーを認識する。ユーザは、電子キーを所持して自車両から所定範囲内(車室内を含む)にいれば、ドアの施錠および開錠、車両の電源のオン、ならびにエンジンの始動等が可能になる。また、第1中継装置102は、ユーザによる電子キーの操作に応じたコードを、車外通信部120を介して受信し、コードに応じて、自車両のドアの施錠および開錠、ならびにスライドドアの自動開閉等を行う。
 車載システム100において、秘密情報を管理することがある。例えば、上記した電子キーによる操作を実現するには、自車両用の電子キーを適切に認識することが必要になる。そのために、電子キーと車載システム100との間において、一意に定められたID(以下、認証用IDという)が交換される。具体的には、電子キーが、電子キーに記憶されている認証用IDを送信し、車載システム100は、受信した認証用IDが、車載システム100が記憶している認証用IDと一致するか否かを判定する。一致すれば、ユーザは、車両に対して上記した操作が可能になる。この認証用IDは秘密情報であり、車載システム100は、秘密情報を安全に長期間管理する役割を担う。生体情報(例えば、指紋および顔画像)および個人情報(氏名、住所、電話番号および電子メールアドレス等)を車載システム100に登録することにより、種々の機能を提供する場合、それらの情報も秘密情報であり、安全に管理される必要がある。
(秘密情報の管理)
 秘密情報の管理における第2中継装置104の機能に関して説明する。図2を参照して、第2中継装置104は、データ分割復元部200、通信先決定部202、通信監視部204および秘密分散制御部206を含む。各部は、図1に示した制御部140およびメモリ142により実現される。データ分割復元部200は、第1中継装置102からの要求を受けて、要求に対応する処理を実行する。即ち、データ分割復元部200は、情報の秘匿を要求するコード(以下、秘匿要求という)が入力されると、それと共に入力される対象データ210(秘匿の対象情報であり、例えば秘密情報)を、一点鎖線内に示すように複数の断片化情報212に分割する。その後、データ分割復元部200は、後述する秘密分散制御部206からの指示を受けて、複数の断片化情報212を複数のE-ECU(例えば、E-ECU108およびE-ECU110)に送信し、各E-ECUに記憶させる。複数(例えばn個)の断片化情報212は、通信先決定部202により決定された、断片化情報212の数と同数の複数(n個)のE-ECUに、1対1に送信される。なお、断片化情報212から対象データ210が復元されるので、対象データ210を元データともいう。対象データ210を断片化情報212に分割するには、任意の方法を用いることができ、例えば、秘密分散法を用いることができる。したがって、「分割」とは、1つの対象データを複数のデータに単に分ける場合に限らず、データの変換および付加を伴い、複数のデータを生成することを意味する。E-ECUに送信された断片化情報212は、元データと共に、データ分割復元部200(図1のメモリ142)から速やかに消去される。
 また、データ分割復元部200は、第1中継装置102から元データを要求するコード(以下、復元要求という)が入力されると、対応する断片化情報212を記憶しているE-ECUから断片化情報212を取得する。具体的には、データ分割復元部200は、断片化情報212を記憶しているE-ECUに、断片化情報212の送信を要求する。データ分割復元部200は、E-ECUから受信した複数の断片化情報212から元データを復元する。断片化情報212が秘密分散法(例えば(k,n)しきい値法)により生成されていれば、データ分割復元部200は、元データを分割した断片化情報の数(n個)よりも少ない数(k個)の断片化情報をE-ECUから取得できれば、元データを復元できる。データ分割復元部200は、復元した元データを第1中継装置102に送信した後、データ分割復元部200(図1のメモリ142)から速やかに元データおよび断片化情報212を消去する。
 複数の秘密情報を管理する場合、第1中継装置102は、データ分割復元部200に対して、対象データ210を特定する情報(以下、元データ特定情報という)を付した秘匿要求を送信すればよい。データ分割復元部200は、元データ特定情報と、それに対応する対象データ210を分割した断片化情報(秘密分散法におけるシェア)を送信したE-ECUを特定する情報(以下、E-ECU特定情報という)を対応させたテーブルを記憶しておけば、そのテーブルを参照して、断片化情報を取得するE-ECUを特定できる。
 通信先決定部202は、データ分割復元部200からの指示を受けて、複数の断片化情報212の各々を1対1に記憶させるE-ECUを決定する。通信先決定部202は、自車両に搭載されており、第2中継装置104と通信可能である複数のE-ECUの中から、複数の断片化情報212と同数のE-ECUを通信先装置として決定する。通信先決定部202は、決定した通信先装置(E-ECU)を特定する情報を記憶する。通信先装置の決定方法は任意であり、通信先決定部202は、所定の規則に従って通信先装置を決定しても、ランダムに通信先装置を決定してもよい。また、通信先決定部202は、各E-ECUの特性(各E-ECUの機能に要求されるリアルタイム性およびメモリ容量等)を考慮して通信先装置を決定してもよい。
 通信監視部204は、車外通信部120の通信状態、複数の入出力ポートのうちの空きポート(例えば、入出力ポート144および入出力ポート146)の状態、および、想定外の通信装置の接続の有無を監視する。通信監視部204は、検知した車外通信部120の通信状態、空きポートの状態および想定外の通信装置の有無を表す情報(以下、状態特定情報という)を秘密分散制御部206に出力する。通信監視部204は、車外通信部120の通信状態、空きポートの状態および想定外の通信装置の有無の検知部といえる。通信監視部204は、最新の状態特定情報を記憶し、秘密分散制御部206からの要求を受けて、状態特定情報を秘密分散制御部206に出力してもよい。車外通信部120の通信状態とは、車外通信部120が外部装置130と通信しているか否かを意味する。空きポートの状態とは、基本的には、機器の接続の有無を意味する。なお、車外通信部120の通信状態には、車外通信部120が通信している場合、通信の種類(例えば、広域無線通信、近接無線通信および有線通信)および通信速度(例えばMbps単位)等が含まれてもよい。空きポートの状態には、機器が接続されている場合、その機器の性質が含まれてもよい。また、車載システム100を構成する各部間(例えば、第1中継装置102および第2中継装置104の間)がワイヤーハーネスにより接続されている場合、そのワイヤーハーネスが加工され、想定外の通信装置が接続される可能性がある。したがって、通信監視部204は、想定外の通信装置の接続の有無、即ち、自車両内の通信経路に、想定外の通信装置が接続されているか否かを監視する。これらは、情報漏洩の可能性に関係する情報である。
 秘密分散制御部206は、データ分割復元部200が、通信先決定部202により決定された通信先装置(E-ECU)と、断片化情報の通信を行うタイミングを制御する。「断片化情報の通信」には、データ分割復元部200が、断片化情報212を通信先装置に送信する通信と、データ分割復元部200が、通信先装置に記憶されている断片化情報212を受信する通信との両方が含まれる。秘密分散制御部206は、通信監視部204から入力される状態特定情報から、現在の車外通信部120の通信状態、空きポートの接続状態および想定外の通信装置の接続の有無を特定し、それに応じて、断片化情報の通信を行うか否かを決定する(通信を計画)。秘密分散制御部206は、断片化情報を通信すると決定した場合、データ分割復元部200に通信を指示し、データ分割復元部200は、断片化情報の通信を実行する。
 例えば、車外通信部120が外部通信(外部装置130との通信)を行っておらず、入出力ポートの空きポートに機器の接続がなく、想定外の通信装置の接続が存在しなければ、情報漏洩の危険性はないまたは比較的低い(以下、安全状態という)。したがって、データ分割復元部200は、断片化情報の通信を行うと決定する。車外通信部120が外部通信(外部装置130との通信)中である、入出力ポートの空きポートに機器が接続されている、または、想定外の通信装置の接続が存在する場合、情報漏洩の危険性は比較的高い(以下、危険状態という)。したがって、データ分割復元部200は、断片化情報の通信を決定しない。危険状態が続く場合、データ分割復元部200が複数の断片化情報を記憶していることは安全ではない。また、第1中継装置102から元データとして、電子キーのIDを要求されている場合、速やかに、E-ECUから断片化情報を取得して復元し、第1中継装置102に出力する必要がある。したがって、所定期間待機した後には、危険状態が続いていても、データ分割復元部200は、断片化情報の通信を行うと決定してもよい。この所定期間(第1所定期間)は、第1中継装置102が要求する元データを利用する第1中継装置102の機能の特性(例えばリアルタイム性)に基づいて決定されていればよい。要求されるリアルタイム性が高い場合には、所定期間を比較的短く設定する。要求されるリアルタイム性が低い場合には、所定期間を比較的長く設定できる。
 これにより、第2中継装置104は、安全状態において、E-ECUと断片化情報を通信でき、断片化情報の通信過程において、断片化情報が車外に漏洩することを抑制できる。また、危険状態であっても、第1中継装置102が提供する機能のリアルタイム性を損なわないように、E-ECUと断片化情報を通信でき、第1中継装置102の機能に支障が生じることを回避できる。
(第2中継装置の動作)
 図3を参照して、第2中継装置104の動作に関してさらに説明する。図3に示した処理は、図1に示した第2中継装置104の制御部140が、所定のプログラムをメモリ142から読出して実行することにより実現される。なお、制御部140は、本プログラムと並行して、図2に示した通信監視部204の機能を実現するためのプログラムを実行している。即ち、本プログラムは、図2に示したデータ分割復元部200、通信先決定部202および秘密分散制御部206の機能を実現するためのものである。断片化情報の生成には秘密分散法が用いられる。
 ステップ300において、制御部140は、第1中継装置102からの要求を受信したか否かを判定する。第1中継装置102から第2中継装置104には、上記したように、秘匿要求または復元要求が出力される。要求を受信したと判定された場合、制御はステップ302に移行する。そうでなければ、制御はステップ324に移行する。これにより、本プログラムが実行されている間、制御部140は、第1中継装置102からの要求を待ち受ける。なお、上記したように、第1中継装置102は、秘匿要求を出力する場合、秘匿の対象データも出力する。したがって、制御部140は、秘匿要求と共に、対象データを受信する。
 ステップ302において、制御部140は、ステップ300により受信された要求が秘匿要求であるか否かを判定する。秘匿要求であると判定された場合、制御はステップ304に移行する。そうでなければ(即ち、復元要求を受信)、制御はステップ308に移行する。
 ステップ304において、制御部140は、複数のE-ECUの中から、後述のステップにおいて生成されるシェア(断片化情報)を記憶させるE-ECUを、通信先装置として決定する。その後、制御はステップ306に移行する。
 ステップ306において、制御部140は、上記したように、ステップ300により受信した対象データを複数のシェアに分割する。制御部140は、秘密分散法により、対象データから複数のシェアを生成する。その後、制御はステップ310に移行する。
 ステップ300により受信された要求が復元要求であれば、ステップ308において、制御部140は、複数のE-ECUの中から、要求される元データを復元するためのシェアを記憶しているE-ECUを、収集先装置(シェアを取得する相手装置)として決定する。その後、制御はステップ310に移行する。1つの秘密情報を扱う場合、通信先装置と収集先装置とは同じE-ECUを含む。複数の秘密情報を扱う場合、制御部140は、上記したように、復元要求と共に元データ特定情報を受信し、元データ特定情報とE-ECU特定情報とを対応させたテーブルを参照して、収集先装置を決定できる。秘密分散法(例えば(k,n)しきい値法)によりシェアが生成された場合、シェアの個数はnであるのに対して、収集されるシェアの個数はn以下のkであればよい。
 ステップ310において、制御部140は、状態特定情報を取得する。その後、制御はステップ312に移行する。状態特定情報は、上記したように、車外通信状態、ポート接続状態および想定外の通信装置の接続の有無を表す情報を含む。状態特定情報は、図2に示した通信監視部204による監視により得られる情報である。通信監視部204の機能は、上記したように、本プログラムと並行して制御部140が実行しているプログラムにより、実現される。状態特定情報は、例えば、メモリ142の所定領域を介して、本プログラムに渡される。
 ステップ312において、制御部140は、ステップ310により取得された状態特定情報により表される車外通信状態、空きポートの状態および想定外の通信装置の接続の有無が、上記した安全状態であるか否かを判定する。安全状態であると判定された場合、制御はステップ316に移行する。そうでなければ、制御はステップ314に移行する。
 ステップ314において、制御部140は、所定期間が経過したか否かを判定する。経過したと判定された場合、制御はステップ316に移行する。そうでなければ、制御はステップ310に戻り、ステップ310およびステップ312が繰返される。所定期間は、上記したように、第1中継装置102が要求する元データを利用する第1中継装置102の機能の特性(例えばリアルタイム性)に基づいて決定されていればよい。
 ステップ316において、制御部140は、ステップ302と同様の処理を実行する。秘匿要求であると判定された場合、制御はステップ318に移行する。そうでなければ(即ち、復元要求を受信)、制御はステップ320に移行する。
 ステップ318において、制御部140は、ステップ306により生成された複数のシェアを、ステップ304により決定された通信先装置(E-ECU)に送信する。このとき、1つの通信先装置には、1つのシェアが送信されても複数のシェアが送信されてもよい。但し、1つのシェアが複数の通信先装置に重複して送信されないようにする。また、1つの通信先装置に複数のシェアを送信する場合、1つの通信先装置に送信した複数のシェアにより元データが復元されないように、1つの通信先装置に送信するシェアの個数を制限することが必要である。例えば、(k,n)しきい値法を用いてシェアを生成する場合、1つの通信先装置にはk未満の個数のシェアを送信する。送信完了後、制御部140は、全てのシェアを消去する。その後、制御はステップ324に移行する。
 ステップ316の判定結果がNO(復元要求を受信)であれば、ステップ320において、制御部140は、ステップ308により決定された収集先装置(E-ECU)からシェアを取得し、元データを復元する。その後、制御はステップ322に移行する。
 ステップ322において、制御部140は、ステップ320により復元された元データを、第1中継装置102に送信する。その後、制御はステップ324に移行する。これにより、第1中継装置102は、第2中継装置104に要求したデータを取得でき、そのデータを必要とするアプリケーションソフトウェア(以下、単にアプリケーションという)に引き渡す。
 ステップ324において、制御部140は、終了の指示を受けたか否かを判定する。終了の指示を受けたと判定された場合、本プログラムは終了する。そうでなければ、制御はステップ300に戻り、上記の処理が繰返される。終了の指示は、例えば、車載システム100が搭載されている車両のスタートボタン等がオフされることにより成される。
 以上により、第2中継装置104は、所定情報(例えば秘密情報)を複数に分割して複数のE-ECUに保存する情報管理において、安全状態において複数の断片化情報(シェア)を通信するので、通信の際に漏洩および改竄の発生を防止できる。
 また、第2中継装置104は、危険状態が持続している場合、第1中継装置102が提供する機能のリアルタイム性を損なわないように、所定期間が経過すれば、E-ECUと断片化情報を通信するので、複数の断片化情報を通信できない状態がいつまでも持続することを回避できる。したがって、第1中継装置102の機能に支障が生じることを回避できる。
 また、所定期間を、断片化情報により復元される元データを必要とする第1中継装置102の機能の特性(例えばリアルタイム性)に基づいて設定することにより、第1中継装置102の機能に要求されるリアルタイム性が損なわれることを回避できる。
 また、上記したように、対象データを複数の断片化情報に分割するデータ分割復元部200を含み、対象データは第1中継装置102から第2中継装置104に入力され、データ分割復元部200は、秘密分散法により断片化情報を生成する。これにより、情報の漏洩および改竄の発生をより防止できる。
 また、上記したように、第2中継装置104は、複数のE-ECUの中から、複数の断片化情報の個数以下の個数のE-ECUを通信先装置として決定する通信先決定部202を含み、複数の断片化情報の各々は、通信先装置と第2中継装置104との間において、秘密分散制御部206による計画に基づいて通信される。これにより、情報の漏洩および改竄の発生をより一層防止できる。
 また、通信先決定部202は、第1中継装置102から第2中継装置104に所定情報の要求(復元要求)が入力されたことを受けて、複数の通信先装置(E-ECU)の中から、断片化情報を取得する複数の相手装置(E-ECU)を決定し、データ分割復元部200は、複数の相手装置から受信した断片化情報から、所定情報を生成する復元機能を有する。これにより、複数のE-ECUに分散させて記憶している断片化情報から元データを生成して第1中継装置102に提供できる。
 上記したように、第2中継装置104は、車両に搭載されている。これにより、車両における所定情報(例えば秘密情報)を複数に分割して複数のE-ECUに保存する情報管理において、断片化情報を通信する際に漏洩および改竄の発生を防止できる。
(適用例)
 上記した、電子キーにより車両のドアの施錠および開錠等を行う場合、第三者に認証用IDを知られると、ユーザ不在時に第三者により不正にドアが開錠される危険性がある。その対策として、例えば、車両の出荷時に、上記した電子キーの認証用ID(秘密情報)を分割して複数の断片化情報を生成し、複数の断片化情報の各々を車載システム100の複数のE-ECUに記憶させることができる。ユーザが車両を操作(開錠および施錠等)する際には、例えば車載システム100の第1中継装置102は、事前にユーザが所持した電子キーの認証処理を実行する。認証過程において、車載システム100の第2中継装置104は、第1中継装置102からの復元要求を受信し、断片化情報を記憶しているE-ECUから断片化情報を取得して車載側の認証用IDを複合し、第1中継装置102に出力する。第1中継装置102は、電子キーから受信した認証用IDが、復元された認証IDと一致するか否かを判定する。このとき、第2中継装置104は、安全状態において、断片化情報を記憶しているE-ECUから断片化情報を通信により取得するので、断片化情報を通信する過程において、第三者により断片化情報が取得され、認証用IDを第三者に知られてしまうリスクを回避できる。
 なお、認証過程において、上記したように、安全状態でなければ、認証用IDを復元するための断片化情報の通信を所定期間行わない。電子キーの認証は速やかに実行される必要があり、比較的高いリアルタイム制が要求される。したがって、所定期間は比較的短く設定される。
(第1変形例)
 上記においては、危険状態であれば断片化情報を通信しない(即ち、所定期間待機する)場合を説明したが、これに限定されない。第1変形例においては、危険状態の程度に応じて、断片化情報の通信を実行する。
 第1変形例に係る車載システムは、図1に示した車載システム100と同じ構成を有し、第1変形例に係る第2中継装置の構成は、図2と異なる。図4を参照して、第1変形例に係る第2中継装置104Aは、データ分割復元部200、通信先決定部202、通信監視部204、秘密分散制御部206およびセキュリティ強度評価部220を含み、通信計画装置として機能する。各部は、図1に示した制御部140およびメモリ142により実現される。図4に示した第2中継装置104Aは、図2に示した第2中継装置104に、セキュリティ強度評価部220が追加されたものである。図4において、図2と同じ符号を付した構成は、図2と同じ機能を有する。したがって、以下においては、重複説明を繰返さず、主として異なる点に関して説明する。また、図1において第2中継装置104を第2中継装置104Aと読み替えて、適宜図1に示した符号を参照する。
 セキュリティ強度評価部220は、通信監視部204から入力される状態特定情報に基づいて、セキュリティ強度を評価し、評価結果を秘密分散制御部206に出力する。上記したように、状態特定情報は、通信監視部204による検知結果である、車外通信部120の通信状態、入出力ポート144および入出力ポート146等の空きポートの状態、ならびに、想定外の通信装置の接続の有無を表す情報である。セキュリティ強度評価部220は、車外通信部120の通信状態、空きポートの状態、ならびに、想定外の通信装置の接続の有無から、セキュリティ強度を決定するために、例えば図5および図6に示すような評価テーブルを記憶している。
 図5を参照して、車外通信部120の通信状態は、通信種別および通信速度の組合せにより表される。通信種別および通信速度の組合せに対するセキュリティ強度を、「高」、「中」および「低」の3つのレベルにより表している。図5においては、通信種別として物理的通信(有線通信)、近接無線通信および広域無線通信を示している。通信速度は、a(Mbps)未満、a(Mbps)以上b(Mbps)未満、および、b(Mbps)以上の3つの範囲に区分されている。aおよびbは、0<a<bを満たす実数である。各レベルの設定に関して、例えば、通信速度が高い場合、不正アクセスによる情報漏洩の危険度が高くなるので、セキュリティ強度を相対的に低く設定する。通信種別に関しては、広域無線通信時には、不正アクセスが比較的容易になるので、セキュリティ強度は相対的に低く設定される。
 図6に、空きポートの状態と想定外の通信装置の接続の有無との組合せに対して、セキュリティ強度を設定する例を示す。図6を参照して、空きポートの状態は、機器の接続の有無と、機器が接続されている場合においてその機器が想定内の機器であるか否かとにより表される。なお、想定内の機器とは、安全であることが既知である機器を意味し、想定外の機器とは、安全であることが既知でない機器を意味する。想定外の通信装置の接続の有無に関しては、接続あり、および接続なしにより表される。図6においては、図5に示した3つのレベルよりも低いレベルを表すために、「最低」を用いている。空きポートに機器が接続されているか否かにかかわらず、想定外の通信装置が接続されていれば、セキュリティ強度は「最低」に設定される。空きポートに機器が接続されておらず、想定外の通信装置の接続もない場合に関して、「-」が示されている。そのような場合には、セキュリティ強度を算出しなくても秘密分散が可能であるので、考慮されないこと、即ち、セキュリティ強度が算出されないことを表すために「-」が示されている。なお、空きポートに接続されている機器が想定内の機器であるか否かは、予め想定内とする機器(安全であることが既知の機器)の情報を記憶しておくことにより、判定できる。
 セキュリティ強度評価部220は、上記したように、通信監視部204から受信した状態特定情報に基づいて、車外通信部120の通信状態、空きポートの状態および想定外の通信装置の接続の有無を特定し、評価テーブル(図5および図6参照)を参照して、車外通信部120の通信状態および空きポートの状態の各々のレベルを特定する。2つのレベルが特定されるので、セキュリティ強度評価部220は、2つのレベルのうちより低いレベルをセキュリティ強度として決定する。
 秘密分散制御部206は、通信監視部204の検知結果が危険状態であり、各E-ECUとの断片化情報の通信を行うことにより、通信過程における情報漏洩の危険性がある場合、セキュリティ強度評価部220から入力されるセキュリティ強度に応じて、各E-ECUとの断片化情報の通信を行うか否かを判定する。通信監視部204の検知結果が危険状態であっても、秘密分散制御部206は、セキュリティ強度が所定レベル以上であれば、各E-ECUとの断片化情報の通信を行うように決定する。これにより、複数の断片化情報の通信が、必要以上に抑制されることを回避でき、情報漏洩の危険性に応じて、複数の断片化情報の通信を制御できる。
 上記においては、車外通信部120の通信状態、空きポートの状態および想定外の通信装置の接続の有無により、セキュリティ強度を評価する場合を説明したが、これに限定されない。車外通信部120の通信状態、空きポートの状態および想定外の通信装置の接続の有無のうちの少なくともいずれかに応じて、セキュリティ強度を評価してもよい。これにより、セキュリティ強度を適切に評価できる。
 上記においては、セキュリティ強度を、車外通信部120の通信状態、空きポートの接続状態、および想定外の通信装置の接続の有無に基づいて決定する場合を説明したが、これに限定されない。例えば、秘匿化の対象データの性質に応じて、セキュリティ強度を決定してもよい。例えば、対象データの機密性または重要性が高い場合、情報漏洩した場合の影響に鑑み、セキュリティ強度を低く設定する。
(第2中継装置の動作)
 図7を参照して、第2中継装置104Aの動作に関してさらに説明する。断片化情報の生成には秘密分散法を用いる。図7に示した処理は、図1に示した第2中継装置104と同様に、制御部140が、所定のプログラムをメモリ142から読出して実行することにより実現される。なお、制御部140は、本プログラムと並行して、図2に示した通信監視部204の機能を実現するためのプログラムを実行している。即ち、本プログラムは、図4に示したデータ分割復元部200、通信先決定部202、秘密分散制御部206およびセキュリティ強度評価部220の機能を実現するためのものである。図7のフローチャートは、図3に示したフローチャートにおいて、ステップ340およびステップ342が追加されたものである。図7において、図3と同じ符号を付したステップは、図3と同じ処理を実行する。したがって、以下においては、重複説明を繰返さず、主として異なる点に関して説明する。
 ステップ310が実行された後、ステップ340において、制御部140は、セキュリティ強度Sを評価する。その後、制御はステップ312に移行する。これは、上記したセキュリティ強度評価部220の機能に対応する。制御部140は、上記したように評価テーブルを参照して、セキュリティ強度を決定する。セキュリティ強度は、例えば、上記したように「高」、「中」、「低」および「最低」の4つのレベルにより表される。
 ステップ312において、制御部140は、上記したように、車外通信状態、空きポートの状態および想定外の通信装置の接続の有無が安全状態であるか否かを判定する。安全状態であれば、制御はステップ316に移行し、そうでなければ、制御はステップ342に移行する。
 ステップ342において、制御部140は、ステップ340により決定されたセキュリティ強度が所定のしきい値Th以上であるか否かを判定する。S≧Th(セキュリティ強度が所定のしきい値Th以上)であると判定された場合、制御はステップ316に移行する。そうでなければ、制御はステップ314に移行する。上記したように、キュリティ強度は「高」、「中」、「低」および「最低」の4つのレベルにより表されるので、しきい値Thには、「高」、「中」、「低」および「最低」のいずれかが設定される。例えば、しきい値Thに「中」が設定されていれば、セキュリティ強度Sが「高」または「中」であれば、S≧Thと判定される。
 以上により、第2中継装置104Aは、第2中継装置104と同様に、所定情報(例えば秘密情報)を複数に分割して複数のE-ECUに保存する情報管理において、安全状態において複数の断片化情報(シェア)を通信するので、通信の際に漏洩および改竄の発生を防止できる。
 また、第2中継装置104Aは、車外通信状態、空きポートの状態および想定外の通信装置の接続の有無が安全状態でなく、各E-ECUとの断片化情報の通信を行うことにより、通信過程における情報漏洩の危険性がある場合、セキュリティ強度に応じて、各E-ECUとの断片化情報の通信を行うか否かを判定する(ステップ342参照)。安全状態でなくても、第2中継装置104Aは、セキュリティ強度が所定レベル以上であれば、各E-ECUとの断片化情報の通信を行うように決定する(ステップ342の判定結果がYES)。これにより、複数の断片化情報の通信が、必要以上に抑制されることを回避でき、情報漏洩の危険性に応じて、複数の断片化情報の通信を制御できる。
(セキュリティ強度の具体例)
 セキュリティ強度の設定に関する具体例を示す。例えば、図8を参照して、図1に示した車載システム100にカメラ160が追加されて構成された車載システム100Aにおいて、第1中継装置102は、車両内を監視するアプリケーションを実行する。カメラ160は、例えばデジタルビデオカメラである。例えば、第1中継装置102は、カメラ160により撮像された大容量の車内監視用の映像データを、断片化情報に分割して、第2中継装置104Aから複数のE-ECUに記憶させる。このとき、車外通信部120による外部装置130との通信速度が比較的低速であれば、第2中継装置104AとE-ECUとの間において大容量の断片化情報を通信しても、通信過程において、不正アクセスにより断片化情報が車外に漏洩する可能性は低い。したがって、セキュリティ強度は比較的高く設定できる。
 また、第2中継装置104Aまたは第1中継装置102の空きポート等に、ドライブレコーダが接続される場合、ディーラが提供するドライブレコーダであれば、想定内の機器に含まれるので、セキュリティ強度を比較的高く設定できる。ディーラとは、例えば、自動車メーカまたはその系列の販売会社と契約を結んだ信頼できる販売会社を意味する。ディーラが提供するドライブレコーダを特定するための情報は、予め第2中継装置104Aのメモリに記憶しておけばよい。第2中継装置104Aは、接続された機器にアクセスしてその機器の情報を取得し(通信監視部204の機能)、ディーラのドライブレコーダであるか否かを判定できる。セキュリティ強度評価部220は、通信監視部204の判定結果を受けて、上記した評価テーブルを参照し、セキュリティ強度を決定できる。
 上記においては、セキュリティ強度が、「高」、「中」、「低」および「最低」の4つのレベルにより表される場合を説明したが、これに限定されない。セキュリティ強度は、複数レベルであればよく、3つ以下のレベルにより表されても、5つ以上のレベルにより表されてもよい。また、セキュリティ強度は、数値(正の整数等)により表されてもよい。その場合、各レベルを所定の数値範囲として設定しておけばよい。
(第2変形例)
 上記においては、危険状態であれば断片化情報を通信しない(即ち、所定期間待機する)場合、および、危険状態の程度(セキュリティ強度)に応じて、断片化情報の通信を実行する場合を説明したが、これらに限定されない。第2変形例においては、危険状態において、通信を切断可能であれば、一時的に通信を切断して断片化情報の通信を実行する。
 第2変形例に係る車載システムは、図1に示した車載システム100と同じ構成を有し、第2変形例に係る第2中継装置の構成は、図2と異なる。図9を参照して、第2変形例に係る第2中継装置104Bは、データ分割復元部200、通信先決定部202、通信監視部204、秘密分散制御部206および通信制御部230を含み、通信計画装置として機能する。各部は、図1に示した制御部140およびメモリ142により実現される。図9に示した第2中継装置104Bは、図2に示した第2中継装置104に、通信制御部230が追加されたものである。図9において、図2と同じ符号を付した構成は、図2と同じ機能を有する。したがって、以下においては、重複説明を繰返さず、主として異なる点に関して説明する。また、図1において第2中継装置104を第2中継装置104Bと読み替えて、適宜図1に示した符号を参照する。
 通信制御部230は、車外通信部120による通信を一時的に切断可能か否かを判定する。通信制御部230は、判定結果を秘密分散制御部206に出力する。秘密分散制御部206は、通信監視部204の検知結果が危険状態であり、各E-ECUとの断片化情報の通信を行うことにより、通信過程における情報漏洩の危険性がある場合、通信制御部230から入力される判定結果に応じて、各E-ECUとの断片化情報の通信を行うか否かを判定する。入力される通信制御部230の判定結果が切断可能を表していれば、秘密分散制御部206は、通信制御部230に車外通信部120の通信切断を指示し、各E-ECUとの断片化情報の通信を行うように決定する。通信切断の指示を受けて通信制御部230は、車外通信部120に、通信を切断させ、所定期間(第2所定期間)切断状態を維持させる。所定期間が経過すれば、通信制御部230は、車外通信部120に通信を再開させる。
 車外通信部120の通信を切断する所定期間は、第2中継装置104およびE-ECUの間における断片化情報の通信を完了できる期間以上の期間に設定される。そのように設定しておけば、断片化情報の通信中において、車外通信部120による通信は切断された状態に維持される。
 通信制御部230は、例えば、車載システム100が実行している機能(例えば、第1中継装置102が実行しているアプリケーション)に、車外通信部120の通信状態が関係している場合、車外通信部120による通信を一時的に切断できるか否かを判定する。例えば、自車両が車外装置と通信するサービスを使用中であり、通信を切断すると走行不能になる場合、通信制御部230は、車外通信部120の通信を切断できないと判定する。例えば、遠隔制御および死角情報共有等の機能が実行されていれば、通信制御部230は、車外通信部120の通信を切断できないと判定する。自車両が自律走行中であれば、通信制御部230は、車外通信部120の通信を切断できると判定する。自律走行機能に限らず、車外通信部120の通信が、リアルタイム性が要求される機能に関係している場合には、通信制御部230は、車外通信部120の通信を切断できないと判定する。
 また、例えば、第1中継装置102が、外部装置130(例えばサーバ)から音楽データまたは映像データ等をダウンロードしつつ再生するアプリケーションを実行している場合、所定量のデータがバッファに保持されていれば、通信制御部230は、車外通信部120の通信を切断できると判定してもよい。例えば、データがバッファに記憶されてからそのデータの利用(再生)が終了するまでの期間(以下、バッファ期間という)に、第2中継装置104が各E-ECUとの断片化情報の通信を完了できる場合、通信制御部230は、車外通信部120の通信を切断できると判定する。また、まとまった音楽データまたは映像データを一括ダウンロードした後、再生できる場合にも、通信制御部230は、車外通信部120の通信を切断できると判定してもよい。
 このように、通信監視部204の検知結果が危険状態であっても、秘密分散制御部206は、車外通信部120の通信を切断して、各E-ECUとの断片化情報の通信を行うように決定する。これにより、断片化情報を通信できない状態がいつまでも持続することを回避できる。なお、上記においては、車外通信部120の通信を切断する場合を説明したが、これに限定されない。車外通信部120の通信を制限できればよい。車外通信部120の通信を制限すれば、断片化情報の通信過程における、断片化情報の漏洩を抑制できる。
 上記したように、車外通信部120による通信が、リアルタイム性が要求される機能のために実行されていなければ、通信制御部230は、車外通信部120の通信を遮断可能であると判定してもよい。これにより、機能に要求されるリアルタイム性が損なわれることを回避しつつ、複数の断片化情報を通信できる。
 上記したように、車外通信部120による通信において所定量のデータのバッファ期間が、複数の断片化情報の通信に要する期間よりも長ければ、車外通信部120の通信が制限可能であると判定してもよい。これにより、外部通信を実行している機能に影響することなく、複数の断片化情報を通信できる。
(第2中継装置の動作)
 図10を参照して、第2中継装置104Bの動作に関してさらに説明する。断片化情報の生成には秘密分散法を用いる。図10に示した処理は、図1に示した第2中継装置104と同様に、制御部140が、所定のプログラムをメモリ142から読出して実行することにより実現される。なお、制御部140は、本プログラムと並行して、図2に示した通信監視部204の機能を実現するためのプログラムを実行している。即ち、本プログラムは、図9に示したデータ分割復元部200、通信先決定部202、秘密分散制御部206および通信制御部230の機能を実現するためのものである。図10のフローチャートは、図3に示したフローチャートにおいて、ステップ314がステップ350により代替され、ステップ352およびステップ354が追加されたものである。図10において、図3と同じ符号を付したステップは、図3と同じ処理を実行する。したがって、以下においては、重複説明を繰返さず、主として異なる点に関して説明する。
 ステップ312において、制御部140は、上記したように、車外通信部120の通信状態、空きポートの状態および想定外の通信装置の接続の有無が安全状態であるか否かを判定する。安全状態であると判定された場合、制御はステップ316に移行する。そうでなければ、制御はステップ350に移行する。
 ステップ350において、制御部140は、車外通信部120の通信を切断可能か否かを判定する。切断可能と判定された場合、制御はステップ352に移行する。そうでなければ、制御はステップ310に戻り、ステップ310およびステップ312が実行される。これにより、安全状態でなければ(ステップ312の判定結果がNO)、車外通信部120が切断可能になるまで、待機状態が維持され、シェアの通信は行われない。
 ステップ352において、制御部140は、車外通信部120の通信を一時的に切断させる。その後、制御はステップ316に移行する。ステップ350およびステップ352は、上記した通信制御部230の機能に対応する。
 ステップ316に移行すれば、上記したように、第1中継装置102からの要求に応じた処理が実行される。即ち、シェアのE-ECUへの送信(ステップ318)、または、E-ECUからシェアの収集および元データの復元(ステップ320およびステップ322)が実行される。その後、制御はステップ354に移行する。
 ステップ354において、制御部140は、車外通信部120に、ステップ352により切断していた通信を再開させる。その後、制御はステップ324に移行する。
 以上により、第2中継装置104Bは、通信監視部204の検知結果が危険状態であっても、車外通信部120の通信を切断して、各E-ECUとの断片化情報(シェア)の通信を行うように決定する。これにより、断片化情報を通信できない状態がいつまでも持続することを回避できる。
 上記において、通信計画装置が、車両に搭載された第2中継装置104、第2中継装置104Aおよび第2中継装置104Bである場合を説明したが、これに限定されない。通信計画装置は、装置外部と通信する機能を有する装置またはシステムに搭載されていればよい。その装置またはシステムの内部に秘密情報を、断片化情報として分散させて記憶する必要がある場合に、通信計画装置は上記した動作を実行する。これにより、その装置またはシステムの内部における断片化情報の通信過程において、情報漏洩を抑制できる。
 なお、上述の実施形態および変形例の各処理(各機能)は、1または複数のプロセッサを含む処理回路(Circuitry)により実現されてもよい。上記処理回路は、上記1または複数のプロセッサに加え、1または複数のメモリ、各種アナログ回路および各種デジタル回路のいずれかが組合された集積回路等により構成されてもよい。上記1または複数のメモリは、上記各処理を上記1または複数のプロセッサに実行させるプログラム(命令)を格納する。上記1または複数のプロセッサは、上記1または複数のメモリから読出した上記プログラムに従い上記各処理を実行してもよいし、予め上記各処理を実行するように設計された論理回路に従って上記各処理を実行してもよい。上記プロセッサは、CPU、GPU(Graphics Processing Unit)、DSP(Digital Signal Processor)、FPGA(Field Programmable Gate Array)、ASIC(Application Specific Integrated Circuit)等、コンピュータの制御に適合する種々のプロセッサであってよい。なお物理的に分離した上記複数のプロセッサが互いに協働して上記各処理を実行してもよい。例えば物理的に分離した複数のコンピュータのそれぞれに搭載された上記プロセッサがLAN(Local Area Network)、WAN(Wide Area Network)およびインターネット等のネットワークを介して互いに協働して上記各処理を実行してもよい。
 以上、実施の形態を説明することにより本開示を説明したが、上記した実施の形態は例示であって、本開示は上記した実施の形態のみに制限されるわけではない。本開示の範囲は、発明の詳細な説明の記載を参酌した上で、請求の範囲の各請求項によって示され、そこに記載された文言と均等の意味および範囲内における全ての変更を含む。
100、100A  車載システム
102  第1中継装置
104、104A、104B  第2中継装置
106、108、110  E-ECU
120  車外通信部
122  バス
130  外部装置
140  制御部
142  メモリ
144、146  入出力ポート
160  カメラ
200  データ分割復元部
202  通信先決定部
204  通信監視部
206  秘密分散制御部
210  対象データ
212  断片化情報
220  セキュリティ強度評価部
230  通信制御部
300、302、304、306、308、310、312、314、316、318、320、322、324、340、342、350、352、354  ステップ
 

Claims (15)

  1.  第1装置、第2装置および通信装置を含むシステムに搭載される通信計画装置であって、
     前記第1装置および前記第2装置の間における所定情報の通信を計画する計画部と、
     前記計画部が前記通信を計画するために必要となる状態特定情報を検知する検知部とを含み、
     前記計画部は、前記検知部による検知結果に基づいて、前記第1装置および前記第2装置の間における複数の断片化情報の通信を計画し、
     前記断片化情報は、前記所定情報が分割されることにより生成される情報である、通信計画装置。
  2.  前記状態特定情報は、前記通信装置による前記システム外との通信である外部通信の通信状態、前記通信計画装置および前記第1装置の各々が有する入出力ポートの状態、ならびに、前記システム内の通信経路への想定外の通信装置の接続の有無のうちの少なくともいずれかの状態を表す情報を含む、請求項1に記載の通信計画装置。
  3.  前記計画部は、前記検知結果に基づいて前記複数の断片化情報の通信を行わないとの計画になる場合においては、第1所定期間が経過すれば、前記複数の断片化情報を通信するように計画する、請求項1または請求項2に記載の通信計画装置。
  4.  前記第1所定期間は、前記複数の断片化情報の通信を必要とする機能のリアルタイム性に基づいて決定される、請求項3に記載の通信計画装置。
  5.  前記システムからの情報漏洩に関するセキュリティ強度を評価するセキュリティ強度評価部をさらに含み、
     前記計画部は、前記検知結果に基づいて前記複数の断片化情報の通信を行わないとの計画になる場合においては、前記セキュリティ強度評価部により評価された前記セキュリティ強度が所定レベル以上であれば、前記複数の断片化情報を通信するように計画する、請求項1から請求項4のいずれか1項に記載の通信計画装置。
  6.  前記セキュリティ強度評価部は、前記検知結果に基づいて、前記セキュリティ強度を評価する、請求項5に記載の通信計画装置。
  7.  前記通信装置に、前記通信装置による前記システム外との通信である外部通信を制限させる通信制御部をさらに含み、
     前記計画部は、
      前記外部通信が制限可能であれば、前記通信制御部に、第2所定期間において前記外部通信を制限させ、
      前記第2所定期間において、前記複数の断片化情報を通信するように計画する、請求項1から請求項6のいずれか1項に記載の通信計画装置。
  8.  前記計画部は、前記外部通信が、リアルタイム性が要求される機能のために実行されていなければ、前記外部通信が制限可能であると判定する、請求項7に記載の通信計画装置。
  9.  前記計画部は、前記外部通信において所定量のデータがバッファに記憶されてから当該データの利用が終了するまでの期間が、前記複数の断片化情報の通信に要する期間よりも長ければ、前記外部通信が制限可能であると判定する、請求項7に記載の通信計画装置。
  10.  前記所定情報を前記複数の断片化情報に分割する情報処理部をさらに含み、
     前記所定情報は、前記第1装置から前記通信計画装置を介して前記第2装置に送信され、
     前記情報処理部は、秘密分散法により前記断片化情報を生成する、請求項1から請求項9のいずれか1項に記載の通信計画装置。
  11.  複数の前記第2装置の中から、前記複数の断片化情報の個数以下の個数の通信先装置を決定する通信先決定部をさらに含み、
     前記複数の断片化情報は、前記通信先装置と前記通信計画装置との間において、前記計画部による計画に基づいて通信される、請求項10に記載の通信計画装置。
  12.  前記通信先決定部は、前記第1装置から前記通信計画装置に前記所定情報の要求が入力されたことを受けて、複数の前記通信先装置の中から、前記断片化情報を受信する複数の相手装置を決定し、
     複数の前記相手装置から受信した前記断片化情報から、前記所定情報を生成する復元部をさらに含む、請求項11に記載の通信計画装置。
  13.  車両に搭載される、請求項1から請求項12のいずれか1項に記載の通信計画装置。
  14.  第1装置、第2装置および通信装置を含むシステムにおける前記第1装置および前記第2装置間の通信の制御方法であって、
     制御部が、前記第1装置および前記第2装置の間における所定情報の通信を計画する計画ステップと、
     前記制御部が、前記計画ステップにより前記通信が計画されるために必要となる状態特定情報を検知する検知ステップとを含み、
     前記計画ステップは、前記制御部が、前記検知ステップによる検知結果に基づいて、前記第1装置および前記第2装置の間における複数の断片化情報の通信を計画するステップを含み、
     前記断片化情報は、前記所定情報が分割されることにより生成される情報である、制御方法。
  15.  第1装置、第2装置および通信装置を含むシステムに搭載されるコンピュータに、
     前記第1装置および前記第2装置の間における所定情報の通信を計画する計画機能と、
     前記計画機能により前記通信が計画されるために必要となる状態特定情報を検知する検知機能とを実行させ、
     前記計画機能は、前記検知機能による検知結果に基づいて、前記第1装置および前記第2装置の間における複数の断片化情報の通信を計画する機能を含み、
     前記断片化情報は、前記所定情報が分割されることにより生成される情報である、コンピュータプログラム。
     
PCT/JP2024/000034 2023-06-09 2024-01-05 通信計画装置、制御方法およびコンピュータプログラム Ceased WO2024252705A1 (ja)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN202480037153.5A CN121263794A (zh) 2023-06-09 2024-01-05 通信计划装置、控制方法以及计算机程序
JP2025525938A JPWO2024252705A1 (ja) 2023-06-09 2024-01-05

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2023095150 2023-06-09
JP2023-095150 2023-06-09

Publications (1)

Publication Number Publication Date
WO2024252705A1 true WO2024252705A1 (ja) 2024-12-12

Family

ID=93795861

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2024/000034 Ceased WO2024252705A1 (ja) 2023-06-09 2024-01-05 通信計画装置、制御方法およびコンピュータプログラム

Country Status (3)

Country Link
JP (1) JPWO2024252705A1 (ja)
CN (1) CN121263794A (ja)
WO (1) WO2024252705A1 (ja)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005171538A (ja) * 2003-12-09 2005-06-30 Oki Electric Ind Co Ltd 鍵装置、錠制御装置、及び錠制御システム
JP2018205809A (ja) * 2017-05-30 2018-12-27 株式会社日立システムズエンジニアリングサービス データ転送システム、及びデータ転送方法
JP2019114916A (ja) * 2017-12-22 2019-07-11 株式会社デンソー 通信装置

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005171538A (ja) * 2003-12-09 2005-06-30 Oki Electric Ind Co Ltd 鍵装置、錠制御装置、及び錠制御システム
JP2018205809A (ja) * 2017-05-30 2018-12-27 株式会社日立システムズエンジニアリングサービス データ転送システム、及びデータ転送方法
JP2019114916A (ja) * 2017-12-22 2019-07-11 株式会社デンソー 通信装置

Also Published As

Publication number Publication date
CN121263794A (zh) 2026-01-02
JPWO2024252705A1 (ja) 2024-12-12

Similar Documents

Publication Publication Date Title
JP7197638B2 (ja) セキュリティ処理方法及びサーバ
JP7496404B2 (ja) セキュリティ処理方法及びサーバ
US12470406B2 (en) Internal certificate authority for electronic control unit
US10279775B2 (en) Unauthorized access event notification for vehicle electronic control units
US11456874B2 (en) Vehicle control system for cybersecurity and financial transactions
US9126601B2 (en) Method and system for a vehicle information integrity verification
KR102450811B1 (ko) 차량 내부 네트워크의 키 관리 시스템
GB2561689A (en) End-to-end vehicle secure ECU unlock in a semi-offline environment
JP2017174111A (ja) 車載ゲートウェイ装置、蓄積制御方法およびプログラム
JP2008271506A (ja) 機密保護装置
JP2024540548A (ja) ロバストな無線リプログラミング
US20230356614A1 (en) Mobile energy delivery management
JP7086257B2 (ja) 通信制御システム、マスター装置、通信制御方法及び通信制御プログラム
US11218309B2 (en) Vehicle communication system and vehicle communication method
JP2023170125A (ja) セキュリティ方法、および、セキュリティ装置
JP6769270B2 (ja) 車載電子制御装置、車載電子制御システム、中継装置
Morano et al. A blockchain technology for protection and probative value preservation of vehicle driver data
CN108632356B (zh) 基于车联网的车辆控制方法及系统、车载终端及服务器
CN107968707B (zh) 一种用于对密钥进行分类存储的方法及系统
US12370923B2 (en) Electric vehicle auxiliary battery usage for energy consumption events
WO2018192818A1 (en) A method for managing the reputation level of a communication device
WO2020090418A1 (ja) 電子制御装置、電子制御装置のリプログラミング方法
US11815870B2 (en) Carrying out calculation methods with a control unit of a transportation vehicle
US20240275581A1 (en) Data storage system, mobile object, and non-transitory computer readable storage medium
CN120128894A (zh) 用于管理车辆系统内的设备的系统和方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24818948

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2025525938

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: CN2024800371535

Country of ref document: CN

NENP Non-entry into the national phase

Ref country code: DE