EP4254875A2

Key management method, vehicle-mounted network system, and key management device

Abstract

Provided is a key management method to secure security in an onboard network system having multiple electronic control units storing a shared key. In the key management method of the onboard network system including multiple electronic units (ECUs) that perform communication by frames via a bus, a master ECU (400) stores a shared key to be mutually shared with one or more ECUs (100a through 100d). Each of the ECUs (100a through 100d) acquire a session key by communication with the master ECU (400) based on the stored shared key, and after this acquisition, executes encryption processing regarding a frame transmitted or received via the bus, using this session key. In a case where a vehicle in which the onboard network system is installed is in a particular state, the master ECU (400) executes inspection (e.g., steps S1201, S1203) of a security state of the shared key stored by the ECU (100a) or the like.

EP4254875A2, drawing sheet 1
Sheet 1 of 23

Term

9.1 yearsto projected expiry

Projected expiry 16 October 2035, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

13 claims: 6 independent, 7 dependent

  1. 1
    A key management method in a first-type electronic control unit (400) out of a plurality of electronic control units (ECUs) in an onboard network system (10) installed in a vehicle, the onboard network system (10) having the plurality of electronic control units (ECUs) that perform communication by frames via a network, the method comprising:storing a shared key to be mutually shared with one or more second-type electronic control units (100a-100d) other than the first-type electronic control unit (400), for transmission of a session key used for encryption relating to a frame transmitted or received via the network, the shared key also being stored in the one or more second-type electronic control units (100a-100d) other than the first-type electronic control unit (400);and skipping inspection of a security state of the shared key stored by driving system electronic control units (100a) related to driving, out of the one or more second-type electronic control units (100a-100d) other than the first-type electronic control unit (400), and executing inspection of a security state of the shared key stored by the second-type electronic control units (100b-100d) other than the driving system electronic control units (100a) , in a state where the vehicle is driving.
  2. 9
    The key management method according to any one of claims 1 through 8, wherein the inspection is executed by communication with a server located externally from the vehicle.
  3. 10
    The key management method according to any one of claims 1 through 9, wherein the plurality of electronic control units perform communication by frames via the network, following a CAN, Controller Area Network, protocol.
  4. 11
    The key management method according to any one of claims 1 through 10, further comprising executing inspection of a security state of the shared key stored by the second-type electronic control units (100a-100d) immediately after entering an accessory-on, ACC-ON, state of the vehicle, immediately after entering an accessory-off, ACC-OFF, state of the vehicle, immediately after a vehicle engine is started, in a state where the vehicle engine is off, while the vehicle is being fueled, while the vehicle is being charged, or while the vehicle is parked.
  5. 12
    An onboard network system (10) installed in a vehicle, the onboard network system (10) having a plurality of electronic control units (ECUs) that perform communication by frames via a network, the system comprising:a first-type electronic control unit (400), out of the plurality of electronic control units, configured to store a shared key to be mutually shared with one or more second-type electronic control units (100a-100d) other than the first -type electronic control unit (400), the shared key also being stored in the one or more second-type electronic control units (100a-100d) other than the first -type electronic control unit (400);and each of the second-type electronic control units (100a-100d) configured to (i) acquire a session key by communication with the first-type electronic control unit (400) based on the stored shared key, and after this acquisition, (ii) execute encryption processing regarding a frame transmitted or received via the network, using this session key, wherein the first-type electronic control unit (400) skips inspection of a security state of the shared key stored by driving system electronic control units (100a) related to driving, out of the one or more second-type electronic control units (100a-100d) other than the first-type electronic control units (400) and executes inspection of a security state of the shared key stored by the second-type electronic control units (100b-100d) other than the driving system electronic control units (100a), in a state where the vehicle is driving.
  6. 13
    A key management device serving as an electronic control unit (ECU) connectable to an onboard network system (10) installed in a vehicle, the network system (10) having a plurality of electronic control units (ECUs) that perform communication by frames via a network, the key management device executing operations comprising:storing a shared key to be mutually shared with one or more second-type electronic control units (100a-100d) other than itself out of the plurality of electronic control units, for transmission of a session key used for encryption relating to a frame transmitted or received via the network, the shared key also being stored in the one or more second-type electronic control units (100a-100d) other than the key management device being a first-type electronic control unit (400), and skipping inspection of a security state of the shared key stored by driving system electronic control units (100a) related to driving, out of the one or more second-type electronic control units (100a-100d) other than the first-type electronic control unit (400), and inspecting of a security state of the shared key stored by the second-type electronic control units (100b-100d) other than the driving system electronic control units (100a), in a state where the vehicle is driving.