MÉTODO E SISTEMA DE APRIMORAMENTO OVER-THE-AIR, DISPOSITIVO DE COMPUTADOR E VEÍCULO
Patent Information
- Application Number
- BR112025019989
- Authority / Receiving Office
- BR · BR
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-30
- Filing Date
- 2024-07-31
- Publication Date
- 2026-08-04
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
1 / 64 OVER-THE-AIR ENHANCEMENT METHOD AND SYSTEM, COMPUTER DEVICE AND VEHICLE
[001] The present application claims priority over Chinese Patent Application No. 202410688373.6, filed with the National Intellectual Property Administration of China on May 30, 2024, and entitled Over-The-Air Upgrade Method and System, Computer Device, and Vehicle, which is incorporated into the present invention by reference in its entirety. TECHNICAL FIELD
[002] The present application relates to the field of over-the-air (OTA) enhancement technology and, in particular, to an OTA enhancement method and system, a computer device and a vehicle. BACKGROUND
[003] With the rapid development of connected intelligent vehicles, in order to quickly capture market share and achieve rapid iteration of functionalities, a common industry practice is to perform rapid over-the-air (OTA) enhancements based on reserved hardware resources, thus enabling iterative enhancements of intelligent functionalities and timely vulnerability fixes. However, during an OTA enhancement process, issues arise such as insufficient software quality, inadequate testing, instability of a new version, and incompatibility between an enhanced version and other vehicle components. Therefore, in OTA enhancement operations, there is a business requirement to revert to a lower version.However, according to information security risk analysis, hackers can illegally exploit the system's functional support to upgrade to a lower version in order to maliciously perform unauthorized enhancements. Petition 870250084323, dated 09 / 18 / 2025, page 16 / 100 2 / 64 officially released versions with known vulnerabilities, and then use those vulnerabilities to attack vehicles.
[004] Currently, issues of protecting the legitimacy, integrity, and confidentiality of enhancement packages are often resolved by encryption during the OTA enhancement process. However, regarding the potential security vulnerabilities that may arise when users upgrade to a lower version of software, it is often impossible to meet the needs of users upgrading to lower version software and avoid such security vulnerabilities that may result from the enhancements. SUMMARY OF THE INVENTION
[005] In view of this, the present application provides an over-the-air enhancement method and system, a computer device and a vehicle, to solve the problem that traditional methods cannot guarantee system security when users upgrade to a lower version software.
[006] In a first aspect, the present application provides an over-the-air enhancement method applied to a network side. The method includes: Generate a software enhancement key and send the software enhancement key to a vehicle side; Upon receiving a software enhancement task sent from the vehicle side, update an initial software enhancement count and detect if the software enhancement task is a lower-version software enhancement task to obtain a software enhancement rollback flag; Encrypt enhancement information, including the first software enhancement count, using the software enhancement key. Petition 870250084323, dated 09 / 18 / 2025, page 17 / 100 3 / 64 to generate encrypted enhancement information; and send the enhancement information, the encrypted enhancement information, the software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task to the vehicle side, wherein the vehicle side, upon determining, based on the software enhancement rollback flag, to upgrade to a lower version software, decrypts the encrypted enhancement information based on the software enhancement key to obtain new enhancement information and the first software enhancement count, and upon determining that the over-the-air (OTA) enhancement is legitimate based on a magnitude ratio between the first software enhancement count and a second software enhancement count stored on the vehicle side,as well as a corresponding relationship between the new enhancement information and the enhancement information, it enhances the lower-version software using the software enhancement package.
[007] A network side is used to generate an initial software enhancement count that records a software enhancement count, a software enhancement rollback flag indicating whether a task is a down-version software enhancement task, as well as enhancement information, encrypted enhancement information, and a software enhancement package that are required by a vehicle side, such that the vehicle side, upon determining, based on the software enhancement rollback flag, to enhance to a down-version software, decrypts the encrypted enhancement information sent by the network side and performs authentication and, upon determining that the OTA enhancement is legitimate, enhances to the software of Petition 870250084323, dated 09 / 18 / 2025, page 18 / 100 4 / 64 lower version using the software enhancement package, thus ensuring the security and legitimacy of the enhancement when a user upgrades to the lower version software.
[008] In an optional implementation, the software enhancement key includes a software enhancement master key; enhancement information additionally includes software information and certification information for enhancement certification, and encrypted enhancement information includes encrypted certification information; and encrypting enhancement information including the first software enhancement count using the software enhancement key to generate encrypted enhancement information includes: Generate certification information based on software enhancement count; Perform symmetric encryption on software information using the software enhancement master key to obtain a rollback service key, wherein the software information is generated based on a software enhancement version corresponding to the software enhancement task, a current software version, and the software enhancement rollback flag; and perform symmetric encryption on certification information using the rollback service key to obtain the encrypted certification information.
[009] When certification information for enhancement certification is generated and sent to the vehicle side, the certification information is encrypted to improve transmission security. Petition 870250084323, dated 09 / 18 / 2025, page 19 / 100 5 / 64
[010] In an optional implementation, sending the enhancement information, the encrypted enhancement information, the software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task to the vehicle side includes: Send the software information, certification information, encrypted certification information, software enhancement rollback flag, and the software enhancement package corresponding to the software enhancement task to the vehicle side, whereby the vehicle side, upon determining, based on the software enhancement rollback flag, to upgrade to the lower version software, decrypts the encrypted certification information based on the software enhancement master key and the software information and extracts the first software enhancement count based on the new certification information obtained through decryption and, upon determining that the OTA enhancement is legitimate based on the magnitude ratio between the first software enhancement count and the second software enhancement count stored on the vehicle side,as well as the corresponding relationship between the new certification information and the certification information, it enhances the software for the lower version using the software enhancement package.
[011] In an optional implementation, generating a software enhancement key and sending the software enhancement key to a vehicle side includes: Upon receiving a public key sent from the vehicle side, generate the software enhancement master key and a transmission protection key; Perform asymmetric encryption on the transmission protection key. Petition 870250084323, dated 09 / 18 / 2025, page 20 / 100 6 / 64 using the public key to obtain a ciphertext transmission protection key and perform symmetric encryption on the software enhancement master key based on the ciphertext transmission protection key to obtain a ciphertext software enhancement master key; and send the ciphertext software enhancement master key and the ciphertext transmission protection key to the vehicle side, so that the vehicle side decrypts the ciphertext transmission protection key using a private key corresponding to the public key to obtain the transmission protection key and decrypts the ciphertext software enhancement master key based on the transmission protection key to obtain the software enhancement master key.
[012] The network side generates the software enhancement master key, then encrypts the software enhancement master key and sends the encrypted software enhancement master key to the vehicle side, so that the vehicle side decrypts the encrypted software enhancement master key to obtain the software enhancement master key from the network side. In this way, security is improved.
[013] In an optional implementation, the software enhancement key includes an asymmetric key pair consisting of a public software enhancement key and a private software enhancement key; enhancement information additionally includes certification information for enhancement certification and build certification information, and encrypted enhancement information includes signature certification information; and encrypting enhancement information including the first software enhancement count using the software enhancement key to generate encrypted enhancement information includes: Petition 870250084323, dated 09 / 18 / 2025, page 21 / 100 7 / 64 generate certification information based on software enhancement count; Perform a compilation operation on the certification information to obtain the compilation certification information, and perform asymmetric encryption on the compilation certification information using the software enhancement private key to obtain the signing certification information.
[014] When signature certification information for enhancement certification is generated and sent to the vehicle side, encryption and a compilation operation are performed on the certification information to improve transmission security.
[015] In an optional implementation, sending the enhancement information, the encrypted enhancement information, the software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task to the vehicle side includes: Send the certification information, signature certification information, software enhancement rollback flag, and the software enhancement package corresponding to the software enhancement task to the vehicle side, where the vehicle side, upon determining, based on the software enhancement rollback flag, to upgrade to the lower version software, decrypts the signature certification information based on the software enhancement public key to obtain the build certification information, performs a build operation on the certification information to obtain new build certification information, and extracts the first software enhancement count from the certification information, and upon determining that the Petition 870250084323, dated 09 / 18 / 2025, page 22 / 100 8 / 64 OTA enhancement is legitimate based on the magnitude ratio between the first software enhancement count and the second software enhancement count stored on the vehicle side, as well as the corresponding ratio between the new build certification information and the build certification information, enhancing for the lower version software using the software enhancement package.
[016] In an optional implementation, upon receiving a software enhancement task sent from the vehicle side, updating an initial software enhancement count and detecting whether the software enhancement task is a lower-version software enhancement task to obtain a software enhancement rollback flag includes: Upon receiving the software enhancement task, increment the initial software enhancement count by one and obtain a software enhancement version and a current software version based on the software enhancement task; If it is detected that the software enhancement version is not higher than the current software version, determine that the software enhancement task is a lower-version software enhancement task and set the software enhancement rollback flag to one; and if it is detected that the software enhancement version is not higher than the current software version, determine that the software enhancement task is not a lower-version software enhancement task and set the software enhancement rollback flag to zero.
[017] By comparing the software upgrade version with the current software version, it is determined whether the vehicle side intends to upgrade to a lower software version, and an upgrade rollback flag is displayed. Petition 870250084323, dated 09 / 18 / 2025, page 23 / 100 9 / 64 software is generated, so the vehicle side uses the software enhancement rollback flag to determine whether to perform authentication.
[018] In a second aspect, the present application provides an over-the-air enhancement method applied to a vehicle side. The method includes: receive a software enhancement key sent over one side of the network; Send a software enhancement task to the network side and receive enhancement information, encrypted enhancement information, a software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task, which are returned by the network side, wherein the encrypted enhancement information is obtained by encrypting the enhancement information which includes an initial software enhancement count by the network side using the software enhancement key; the initial software enhancement count is obtained by updating a current software enhancement count by the network side after receiving the software enhancement task; and the software enhancement rollback flag is obtained by detecting whether the software enhancement task is a lower version software enhancement task by the network side; when determining, based on the software enhancement rollback flag, to upgrade to a lower version software, decrypting the encrypted enhancement information based on the software enhancement key to obtain new enhancement information and the first software enhancement count stored on the network side; and when determining that the over-the-air (OTA) enhancement is legitimate with Petition 870250084323, dated 09 / 18 / 2025, page 24 / 100 10 / 64 based on a magnitude ratio between the first software enhancement count and a second software enhancement count stored on the vehicle side, as well as a corresponding ratio between new enhancement information and enhancement information, upgrading to the lower version software using the software enhancement package.
[019] A network side is used to generate an initial software enhancement count that records a software enhancement count, a software enhancement rollback flag indicating whether a task is a downgrade software enhancement task, as well as enhancement information, encrypted enhancement information, and a software enhancement package that are required by a vehicle side, so that the vehicle side, upon determining, based on the software enhancement rollback flag, to upgrade to a downgrade software, decrypts the encrypted enhancement information sent by the network side and performs authentication, and upon determining that the OTA upgrade is legitimate, upgrades to the downgrade software using the software enhancement package, thus ensuring the security and legitimacy of the upgrade when a user upgrades to the downgrade software.
[020] In an optional implementation, the software enhancement key includes a software enhancement master key; enhancement information additionally includes software information and certification information for enhancement certification, and encrypted enhancement information includes encrypted certification information; and receive enhancement information, enhancement information Petition 870250084323, dated 09 / 18 / 2025, page 25 / 100 11 / 64 encrypted data, a software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task, which are returned by the network side, includes: Receive the software information, certification information, encrypted certification information, software enhancement rollback flag, and software enhancement package corresponding to the software enhancement task, which are returned by the network side; and decrypt the encrypted enhancement information based on the software enhancement key to obtain new enhancement information and the first software enhancement count stored on the network side includes: Perform symmetric encryption on the software information based on the software enhancement master key to obtain a rollback service key; and decrypt the encrypted certification information using the rollback service key to obtain new decrypted certification information and extract the first software enhancement count stored on the network side from the new certification information.
[021] Encrypted information sent over the network is decrypted using the software enhancement master key to facilitate subsequent determination of the legitimacy of the OTA enhancement and improve the security of information transmission.
[022] In an optional implementation, before upgrading to the lower version software using the software enhancement package, the method additionally includes: Petition 870250084323, dated 09 / 18 / 2025, page 26 / 100 12 / 64 If the first software enhancement count is detected as higher than the second software enhancement count, determine if the new certification information is consistent with the certification information; If the new certification information is detected as consistent with the certification information, determine that the OTA enhancement is legitimate, assign the value of the first software enhancement count to the second software enhancement count, and perform an enhancement step for the lower-version software using the software enhancement package; and if the new certification information is detected as inconsistent with the certification information, or if the count of the first software enhancement is not greater than the count of the second software enhancement, stop the enhancement.
[023] The magnitude ratio between the first software upgrade count and the second software upgrade count is determined, and the consistency between the new certification information and the certification information is checked, to determine whether the downgrade upgrade is legitimate. This increases security during OTA upgrades and avoids security risks caused by security vulnerabilities in the downgrade software.
[024] In an optional implementation, after receiving the software enhancement key sent from the network side, the method additionally includes: Obtain a software enhancement version and a current software version, and compare the software enhancement version and the current software version to obtain the flag for reverting the software enhancement being used. Petition 870250084323, dated 09 / 18 / 2025, page 27 / 100 13 / 64 to indicate whether the software enhancement task is a down-version software enhancement task; and when determining, based on the software enhancement rollback flag, to upgrade to a down-version, perform symmetric encryption on the software enhancement version, the current software version, and the software enhancement rollback flag to obtain the rollback service key and receive the certification information for enhancement certification, the encrypted certification information, and the software enhancement package, which are entered offline by a user, where the certification information, the encrypted certification information, and the software enhancement package are obtained by the user from the network side;and perform a decryption step on the encrypted certification information using the rollback service key to obtain new decrypted certification information and subsequent steps.
[025] Therefore, in an offline scenario, a legitimate downgrade is performed by receiving the certification information, the encrypted certification information, and the user's input of the software enhancement package.
[026] In an optional implementation, the software enhancement key includes an asymmetric key pair consisting of a public software enhancement key and a private software enhancement key; the enhancement information additionally includes certification information for enhancement certification and build certification information, and the encrypted enhancement information includes signature certification information; receive improvement information, improvement information Petition 870250084323, dated 09 / 18 / 2025, page 28 / 100 14 / 64 encrypted data, a software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task, which are returned by the network side, includes: Receive the certification information, signature certification information, software enhancement rollback flag, and software enhancement package corresponding to the software enhancement task, which are returned by the network side; and decrypt the encrypted enhancement information based on the software enhancement key to obtain new enhancement information and the first software enhancement count stored on the network side includes: decrypt the signature certification information based on the software enhancement public key sent by the network side to obtain the build certification information, perform a build operation on the certification information to obtain new build certification information, and extract the first software enhancement count from the certification information.
[027] The signature certification information sent by the network is decrypted using the software update public key to facilitate subsequent determination of OTA enhancement legitimacy and improve information transmission security.
[028] In an optional implementation, before upgrading to the lower version software using the software enhancement package, the method additionally includes: If the new build certification information is detected as consistent with the build certification information, determine if the initial software enhancement count is greater than Petition 870250084323, dated 09 / 18 / 2025, page 29 / 100 15 / 64 the second software enhancement count; If the first software enhancement count is detected as being greater than the second software enhancement count, determine that the OTA enhancement is legitimate, assign the value of the first software enhancement count to the second software enhancement count, and perform an enhancement step for the lower-version software using the software enhancement package; and if the first software enhancement count is detected as not being greater than the second software enhancement count, or if the new build certification information is detected as inconsistent with the build certification information, stop the enhancement.
[029] The magnitude ratio between the first software enhancement count and the second software enhancement count is determined, and the consistency between the new certification information and the build information is checked, to determine whether the downgrade enhancement is legitimate. This increases security during OTA enhancement and avoids security risks caused by security vulnerabilities in the downgrade software.
[030] In an optional implementation, after receiving the software enhancement public key sent by the network side, the method additionally includes: Obtain a software enhancement version and a current software version, and compare the software enhancement version and the current software version to obtain the software enhancement rollback flag used to indicate whether the software enhancement task is a lower-version software enhancement task; and Petition 870250084323, dated 09 / 18 / 2025, page 30 / 100 16 / 64 when determining, based on the software enhancement rollback flag, to upgrade to a lower version, receiving the certification information for enhancement certification, the signature certification information, and the software enhancement package, which are entered offline by a user, and performing a decryption step of the signature certification information based on the software enhancement public key sent by the network side to obtain the build certification information, and subsequent steps, in which the certification information, the signature certification information, and the software enhancement package are obtained by the user from the network side.
[031] Therefore, in an offline scenario, a legitimate downgrade is performed by receiving the certification information, the signature certification information, and the user's input of the software enhancement package.
[032] In a third aspect, the present application provides an over-the-air enhancement system. The system includes a network side and a vehicle side, wherein the network side is configured to generate a software enhancement key and send the software enhancement key to the vehicle side; upon receiving a software enhancement task sent by the vehicle side, update a first software enhancement count and detect if the software enhancement task is a lower version software enhancement task to obtain a software enhancement rollback flag; encrypt enhancement information including the first software enhancement count using the software enhancement key to generate encrypted enhancement information; and send the enhancement information, the Petition 870250084323, dated 09 / 18 / 2025, page 31 / 100 17 / 64 encrypted enhancement information, the software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task for the vehicle side;and the vehicle side is configured to, upon determining, based on the software upgrade rollback flag, to upgrade to a lower version software, decrypt the encrypted upgrade information based on the software upgrade key to obtain new upgrade information and the first software upgrade count and, upon determining that the over-the-air (OTA) upgrade is legitimate based on a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding ratio between the new upgrade information and the upgrade information, upgrade to the lower version software using the software upgrade package.
[033] The network side is used to generate an initial software enhancement count that records a software enhancement count, a software enhancement rollback flag indicating whether the task is a down-version software enhancement task, as well as enhancement information, encrypted enhancement information, and a software enhancement package that are required by the vehicle side, so that the vehicle side, upon determining, based on the software enhancement rollback flag, to enhance to the down-version software, decrypts the encrypted enhancement information to obtain new enhancement information and an initial software enhancement count, and upon determining that the Petition 870250084323, dated 09 / 18 / 2025, page 32 / 100 18 / 64 OTA upgrades are legitimate based on a magnitude relationship between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding relationship between the new upgrade information and the upgrade information, upgrading to the lower version software using the software upgrade package, thus ensuring the security and legitimacy of the upgrade when a user upgrades to the lower version software.
[034] In a fourth aspect, the present application provides a computer device. The computer device includes a first memory and a first processor, wherein the first memory and the first processor are communicatively connected to each other, and the first memory stores first computer instructions, which are executed by the first processor to perform the OTA enhancement method in the first aspect described above or in any implementation corresponding to the first aspect.
[035] In a fifth aspect, the present application provides a vehicle. The vehicle includes a second memory and a second processor, wherein the second memory and the second processor are communicatively connected to each other, and the second memory stores second computer instructions, which are executed by the second processor to perform the OTA enhancement method in the second aspect described above or in any implementation corresponding to the second aspect.
[036] This application has the following beneficial effects.
[037] The network side is used to generate an initial software enhancement count that records a software enhancement count, a software enhancement rollback flag that indicates Petition 870250084323, dated 09 / 18 / 2025, page 33 / 100 19 / 64 if the task is a downgrade software upgrade task, as well as upgrade information, encrypted upgrade information, and a software upgrade package that are required by the vehicle side, such that the vehicle side, upon determining, based on the software upgrade rollback flag, to upgrade to a downgrade software version, decrypts the encrypted upgrade information sent by the network side to obtain new upgrade information and performs authentication during the upgrade using a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding ratio between the new upgrade information and the upgrade information, and upon determining that the OTA upgrade is legitimate,It upgrades to the lower version software using the software upgrade package, thus ensuring the security and legitimacy of the upgrade when a user upgrades to the lower version software. BRIEF DESCRIPTION OF THE DRAWINGS
[038] In order to illustrate more clearly technical solutions in specific implementations of the present application or of the prior art, the accompanying drawings that need to be used in the description of the specific implementations or of the prior art will be briefly introduced below. Apparently, the drawings in the following description only represent some implementations of the present application, and a person with ordinary skill in the art can still derive other drawings from these drawings without creative effort. Petition 870250084323, dated 09 / 18 / 2025, page 34 / 100 20 / 64
[039] Fig. 1 is a schematic structural diagram of an over-the-air (OTA) enhancement system according to an embodiment of the present application; Fig. 2 is a schematic structural diagram of another OTA enhancement system according to an embodiment of the present application; Fig. 3 is a schematic structural diagram of another OTA enhancement system according to an embodiment of the present application; Fig. 4 is a schematic flow diagram of an OTA enhancement method according to an embodiment of the present application; Fig. 5 is a schematic flow diagram of an online OTA enhancement method based on symmetric authentication according to an embodiment of the present application; Fig. 6 is a schematic flow diagram of an offline OTA enhancement method based on symmetric authentication according to an embodiment of the present application; Fig. 7 is a schematic flow diagram of an online OTA enhancement method based on asymmetric authentication according to an embodiment of the present application; Fig. 8 is a schematic flow diagram of an offline OTA enhancement method based on asymmetric authentication according to an embodiment of the present application; Fig. 9 is a hardware structure diagram of a computer device in an embodiment of the present application; and Fig. 10 is a hardware structure diagram of a vehicle in an embodiment of the present application. DETAILED DESCRIPTION Petition 870250084323, dated 09 / 18 / 2025, page 35 / 100 21 / 64
[040] In order to make clearer the objects, the technical solutions and the advantages of the embodiments of this application, the technical solutions in the embodiments of this application will be described below clearly and completely with reference to the accompanying drawings in the embodiments of this application. Apparently, the embodiments described are merely some of the embodiments of this application, and not all. All other embodiments obtained by those skilled in the art based on embodiments of this application, without creative effort, are within the scope of protection of this application.
[041] During automotive software upgrades, users may need to upgrade to a version lower than their current software version. When upgrading to a lower version of software, traditional methods may introduce security risks due to security vulnerabilities in the lower version software. Therefore, it is necessary to implement permission control for upgrading to legitimate lower version software, so as to meet the need for users to autonomously and legitimately upgrade to lower version software, while preventing other users from illegally upgrading to lower version software.
[042] Therefore, the embodiments of the present application provide an over-the-air (OTA) enhancement solution, in which the legitimacy of an OTA enhancement is determined based on interaction information between a network side and a vehicle side and, after determining that the OTA enhancement is legitimate, the vehicle side enhances to a lower version software. This not only meets the user's need to enhance to a lower version software, but also ensures security and legitimacy. Petition 870250084323, dated 09 / 18 / 2025, page 36 / 100 22 / 64
[043] According to the embodiments of the present application, an OTA enhancement system is provided. As shown in Fig. 1, the OTA enhancement system includes a network side 101 and a vehicle side 102. The network side 101 is an endpoint that receives enhancement requests from the vehicle, such as a cloud server, an edge server, etc. The vehicle side 102 may be a vehicle, an onboard system in a vehicle, a controller or client software installed in a vehicle, etc. The embodiments of the present application are not limited to this.
[044] Network side 101 is configured to generate a software enhancement key and send the software enhancement key to vehicle side 102; upon receiving a software enhancement task sent by vehicle side 102, update a first software enhancement count and detect if the software enhancement task is a lower version software enhancement task to obtain a software enhancement rollback flag; encrypt enhancement information including the first software enhancement count using the software enhancement key to generate encrypted enhancement information; and send the enhancement information, the encrypted enhancement information, the software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task to vehicle side 102.
[045] Vehicle side 102 is configured to, upon determining, based on the software upgrade rollback flag, to upgrade to a lower version software, decrypt the encrypted upgrade information based on the software upgrade key to obtain new upgrade information and the first Petition 870250084323, dated 09 / 18 / 2025, page 37 / 100 23 / 64 software enhancement count and, upon determining that the OTA enhancement is legitimate based on a magnitude ratio between the first software enhancement count and a second software enhancement count stored on the vehicle side, as well as a corresponding ratio between the new enhancement information and the enhancement information, upgrades to the lower version software using the software enhancement package.
[046] In the OTA enhancement system according to the embodiments of the present application, the network side is used to generate an initial software enhancement count that records a software enhancement count, a software enhancement rollback flag indicating whether the task is a down-version software enhancement task, as well as enhancement information, encrypted enhancement information, and a software enhancement package that are required by the vehicle side, such that the vehicle side, upon determining, based on the software enhancement rollback flag, whether to upgrade to the down-version software, decrypts the encrypted enhancement information to obtain new enhancement information and an initial software enhancement count,and by determining that the OTA upgrade is legitimate based on a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding ratio between the new upgrade information and the upgrade information, it upgrades to the lower version software using the software upgrade package, thus ensuring the security and legitimacy of the upgrade when a user upgrades to the lower version software. Petition 870250084323, dated 09 / 18 / 2025, page 38 / 100 24 / 64
[047] In some optional implementations, as shown in Fig. 2, the network side 101 includes a certification unit 201 and an enhancement unit 202, and the vehicle side 102 includes a vehicle-side authentication unit 203 and a display and input unit 204.
[048] It should be noted that when enhancement unit 202 receives the software enhancement task, it needs to perform a series of security operations, such as encryption and signing, on the software package. At the same time, the vehicle-side authentication unit needs to perform operations such as decryption and signature verification to protect the confidentiality and legitimacy of the enhancement package. The process described above is necessary for a secure enhancement process. For more details, reference may be made to the description of the related technique, which will not be repeated here. The implementation steps of the embodiments of this application are carried out based on the process described above.
[049] Optionally, as shown in Fig. 3, the certification unit 201 mainly includes a key generation module 2011, a key storage module 2012, and a certification module 2013. The key generation module 2011 is configured to generate a software enhancement key, such as a software enhancement master key or an asymmetric key pair consisting of a software enhancement public key and a software enhancement private key. The key storage module 2012 is configured to store the software enhancement key generated by the key generation module 2011. The certification module 2013 is mainly configured to encrypt enhancement information to obtain encrypted enhancement information. Petition 870250084323, dated 09 / 18 / 2025, page 39 / 100 25 / 64
[050] Optionally, referring again to Fig. 3, the vehicle-side authentication unit 203 primarily includes a vehicle-side key management module 2031, a vehicle-side key storage module 2032, and an authentication module 2033. The vehicle-side authentication unit 203 is configured to determine whether an operation on a lower-version software is legitimate during a software enhancement process. The vehicle-side key management module 2031 is configured to receive information sent from the network side. The vehicle-side key storage module 2032 is configured to store the information sent from the network side. The authentication module 2033 is configured to decrypt the information sent from the network side and determine whether the OTA enhancement is legitimate based on the decrypted information.
[051] Referring again to Fig. 3, the display and input unit 204 mainly includes a display module 2041 and a vehicle-side authentication input module 2042. The vehicle-side authentication input module 2042 is configured to receive information entered by a user. The display module 2041 is configured to display the information.
[052] In addition, enhancement unit 202 manages the first software enhancement count stored on the network side using OTA_COUNT, with an initial value of 0; and authentication module 2033 on the vehicle side manages the second software enhancement count stored on the vehicle side using V_OTA_COUNT, with an initial value of 0.
[053] In accordance with the provisions of this application, an OTA enhancement method is provided. It should be noted that the Petition 870250084323, dated 09 / 18 / 2025, page 40 / 100 26 / 64 steps illustrated in the flow diagrams of the attached drawings can be performed in a computer system, such as one that includes a set of computer-executable instructions, and although a logical order is illustrated in the flow diagrams, in some cases the steps illustrated or described may be performed in a different order than that presented in the present invention.
[054] In this embodiment, an OTA enhancement method is provided. The method can be used for the network side 101 and the vehicle side 102, as shown in Fig. 1. Fig. 4 is a schematic diagram of an interaction process of the OTA enhancement system according to the embodiments of the present application. The network side 101 is configured to perform steps S101 to S104, and the vehicle side 102 is configured to perform steps S201 to S205. The specific interaction process between the network side 101 and the vehicle side 102 is as follows.
[055] Step S101: Generate a software enhancement key and send the software enhancement key to the vehicle side.
[056] Specifically, the embodiments of the present application are mainly divided into two schemes: symmetric authentication and asymmetric authentication. In the symmetric authentication scheme, the network side generates a software enhancement master key, encrypts it, and sends the software enhancement master key to the vehicle side. In the asymmetric authentication scheme, the network side generates an asymmetric key pair consisting of a software enhancement public key and a software enhancement private key and sends the software enhancement public key to the vehicle side.
[057] Step S201: receive the software enhancement key sent by the network side. Petition 870250084323, dated 09 / 18 / 2025, page 41 / 100 27 / 64
[058] Specifically, in the symmetric authentication scheme, the vehicle side receives the ciphertext obtained by encrypting the software enhancement master key from the network side and decrypts the ciphertext to obtain the software enhancement master key. In the asymmetric authentication scheme, the vehicle side receives the software enhancement public key sent from the network side. The software enhancement public key corresponds to the network side's software enhancement private key.
[059] It should be noted that steps S101 and S201 are essentially a network-side and vehicle-side initialization process. During the initialization process, the network side and the vehicle side are communicatively connected. After initialization is complete, the vehicle can either enhance online or obtain the data required for offline enhancement. During an offline enhancement process, the vehicle side can disable the communication connection with the network side.
[060] In addition, during initialization, the network side manages the first software enhancement count using OTA_COUNT, with an initial value of 0; and the vehicle side manages the second software enhancement count using V_OTA_COUNT, with an initial value of 0.
[061] Step S202: Send a software enhancement task to the network side.
[062] Specifically, the vehicle side generates the software enhancement task based on information such as a current software version installed on a controller and a required software enhancement version, and sends an enhancement request to the network side.
[063] Step S102: upon receiving the software enhancement task sent from the vehicle side, update an initial count of Petition 870250084323, dated 09 / 18 / 2025, page 42 / 100 28 / 64 software enhancement and detect if the software enhancement task is a lower version software enhancement task to obtain a software enhancement rollback flag.
[064] Specifically, each time a software enhancement task is received, the network side logs the first software enhancement count, determines whether the vehicle side intends to enhance to a lower version software, and generates a software enhancement rollback flag, so that the vehicle side uses the software enhancement rollback flag to determine whether to perform authentication.
[065] In some optional implementations, the S102 step described above includes the following steps.
[066] Step a1: upon receiving the software enhancement task, incrementing the first software enhancement count by one and obtaining a software enhancement version and a current software version based on the software enhancement task.
[067] Step a2: if it is detected that the software enhancement version is not higher than the current software version, determine that the software enhancement task is a lower version software enhancement task and set the software enhancement rollback flag to one.
[068] Step a3: if it is detected that the software enhancement version is not higher than the current software version, determine that the software enhancement task is not a lower version software enhancement task and set the software enhancement rollback flag to zero. Petition 870250084323, dated 09 / 18 / 2025, page 43 / 100 29 / 64
[069] For example, referring again to Fig. 2, upon receiving the software enhancement task, the enhancement unit increments an OTA_COUNT counter indicating the first software enhancement count by 1 and then determines the software enhancement version number. If the software enhancement version is higher than the current software version in the vehicle controller, the enhancement unit will set the software enhancement rollback flag RE_OTA_FLAG to 0. If the software enhancement version is lower than or equal to the current software version in the vehicle controller, the enhancement unit will set RE_OTA_FLAG to 1.
[070] Step S103: Encrypt enhancement information including the first software enhancement count using the software enhancement key to generate encrypted enhancement information.
[071] Specifically, in the symmetric authentication scheme, enhancement information mainly includes the first software enhancement count, software information, and certification information for enhancement certification. Encrypted enhancement information mainly includes encrypted certification information obtained by encrypting the certification information. In the asymmetric authentication scheme, enhancement information mainly includes the first software enhancement count, certification information for enhancement certification, and build certification information. Build certification information is obtained by encrypting the certification information. Encrypted enhancement information includes Petition 870250084323, dated 09 / 18 / 2025, page 44 / 100 30 / 64 primarily signature certification information obtained by encrypting the compilation certification information.
[072] Step S104: Send the enhancement information, the encrypted enhancement information, the software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task to the vehicle side.
[073] Specifically, in the symmetric authentication scheme, the network side sends the software information, the certification information, the encrypted certification information, the software enhancement rollback flag, and the software enhancement package corresponding to the software enhancement task to the vehicle side. In the asymmetric authentication scheme, the network side sends the certification information, the signature certification information, the software enhancement rollback flag, and the software enhancement package corresponding to the software enhancement task to the vehicle side.
[074] Step S203: receive the enhancement information, the encrypted enhancement information, the software enhancement rollback flag, and the software enhancement package corresponding to the software enhancement task, which are returned by the network side.
[075] Step S204: when determining, based on the software enhancement rollback flag, to upgrade to a lower version software, decrypt the encrypted enhancement information based on the software enhancement key to obtain new enhancement information and the first software enhancement count stored on the network side. Petition 870250084323, dated 09 / 18 / 2025, page 45 / 100 31 / 64
[076] Specifically, the vehicle side decrypts the encrypted enhancement information based on the software enhancement master key or software enhancement public key to obtain the new enhancement information and the first software enhancement count OTA_COUNT on the network side.
[077] Step S205: upon determining that the OTA upgrade is legitimate based on a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding ratio between the new upgrade information and the upgrade information, upgrade to the lower version software using the software upgrade package.
[078] Specifically, the vehicle side determines whether the OTA upgrade is legitimate based on the magnitude ratio between the first software upgrade count OTA_COUNT and the second software upgrade count V_OTA_COUNT, as well as the corresponding ratio between the new upgrade information and the upgrade information. Only when the OTA upgrade is legitimate will the vehicle be allowed to upgrade to the lower version software using the software upgrade package.
[079] In the OTA enhancement method according to the embodiments of the present application, the network side is used to generate an initial software enhancement count that records a software enhancement count, a software enhancement rollback flag indicating whether the task is a downgrade software enhancement task, as well as enhancement information, encrypted enhancement information, and a software enhancement package that are required. Petition 870250084323, dated 09 / 18 / 2025, page 46 / 100 32 / 64 on the vehicle side, so that the vehicle side, upon determining, based on the software upgrade rollback flag, to upgrade to the lower version software, decrypts the encrypted upgrade information to obtain new upgrade information and a first software upgrade count, and upon determining that the OTA upgrade is legitimate based on a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding ratio between the new upgrade information and the upgrade information, upgrades to the lower version software using the software upgrade package, thus ensuring the security and legitimacy of the upgrade when a user upgrades to the lower version software.
[080] According to the modalities of the present application, when a user upgrades the software to a version lower than the current software version, permission control is implemented for the upgrade to the legitimate lower version software, so as to meet the user's need to autonomously and legitimately upgrade to the lower version software, while at the same time preventing other unauthorized users from illegally upgrading to the lower version software, thus avoiding security risks caused by security vulnerabilities in the lower version software.
[081] In this embodiment, an OTA enhancement method is provided. The method can be used for the network side 101 and the vehicle side 102, shown in Fig. 1. Fig. 5 is a schematic diagram of an OTA enhancement system interaction process according to the embodiments of the present application. The network side 101 is configured to perform the S301 steps. Petition 870250084323, dated 09 / 18 / 2025, page 47 / 100 33 / 64 to S306, and vehicle side 102 is configured to perform steps S401 to S406. The specific interaction process between network side 101 and vehicle side 102 is as follows.
[082] Step S301: Generate a software enhancement master key and send the software enhancement master key to the vehicle side.
[083] In some optional implementations, the S301 step described above includes the following steps: Step b1: upon receiving a public key sent from the vehicle side, generate the software enhancement master key and a transmission protection key.
[084] Step b2: perform asymmetric encryption on the transmission protection key using the public key to obtain a ciphertext transmission protection key and perform symmetric encryption on the software enhancement master key based on the ciphertext transmission protection key to obtain a ciphertext software enhancement master key.
[085] Step b3: sending the ciphertext software enhancement master key and the ciphertext transmission protection key to the vehicle side.
[086] For example, referring again to Fig. 3, the vehicle-side key management module generates asymmetric keys. A private key SK is securely stored in the vehicle-side key management module, and a public key PK is sent to the offline or online certification unit to request OTA_MASTER_KEY from the certification unit.
[087] Referring again to Fig. 3, the certification unit invokes the key generation module to randomly generate a random number. Petition 870250084323, dated 09 / 18 / 2025, page 48 / 100 34 / 64 128-bit or 256-bit as the software enhancement master key OTA_MASTER_KEY. OTA_MASTER_KEY is securely stored in the key storage module and cannot be exported in plain text. Generally, the key generation module can be implemented using a hardware security module (HSM) device. Then, the certification unit invokes the key generation module to randomly generate a 128-bit or 256-bit random number as the transmission protection key TRANS_KEY. TRANS_KEY is used to encrypt and protect OTA_MASTER_KEY.
[088] Optionally, after receiving the public key PK, the certification unit performs asymmetric cryptography on the transmission protection key TRANS_KEY using PK to obtain the ciphertext transmission protection key ENC_TRANS_KEY. An asymmetric cryptography algorithm may be a commonly used and secure algorithm, such as the Rivest-Shamir Adleman (RSA) algorithm and elliptic curve cryptography (ECC). The embodiments of the present application are not limited to this.
[089] Next, the software enhancement master key OTA_MASTER_KEY is symmetrically encrypted using the ciphertext transmission protection key ENC_TRANS_KEY to obtain the ciphertext software enhancement master key ENC_OTA_MASTER_KEY. For example, a symmetric encryption algorithm could be a commonly used and secure algorithm such as the Advanced Encryption Standard (AES) and the SM4 block cipher algorithm (SM4). The embodiments of the present application are not limited to this. Finally, ENC_TRANS_KEY and ENC_OTA_MASTER_KEY are sent to the vehicle-side key management module.
[090] Step S401: Receive the software enhancement master key sent from the network side. Petition 870250084323, dated 09 / 18 / 2025, page 49 / 100 35 / 64
[091] In some optional implementations, the vehicle side decrypts the ciphertext transmission protection key using the private key corresponding to the public key to obtain the transmission protection key and decrypts the ciphertext software enhancement master key based on the transmission protection key to obtain the software enhancement master key.
[092] For example, the vehicle-side key management module invokes the private key SK to decrypt the ciphertext transmission protection key ENC_TRANS_KEY to obtain the transmission protection key TRANS_KEY, then uses the obtained transmission protection key TRANS_KEY to decrypt the ciphertext software enhancement master key ENC_OTA_MASTER_KEY to obtain the software enhancement master key OTA_MASTER_KEY, and securely stores the obtained software enhancement master key OTA_MASTER_KEY in the vehicle-side key storage module.
[093] The network side generates the software enhancement master key, encrypts the software enhancement master key, and sends the encrypted software enhancement master key to the vehicle side, so that the vehicle side decrypts the encrypted software enhancement master key to obtain the software enhancement master key from the network side. In this way, security is improved.
[094] Step S402: Send a software enhancement task to the network side. See step S202 of the mode shown in Fig. 4 for details, which will not be repeated here.
[095] Step S302: upon receiving the software enhancement task sent from the vehicle side, update an initial software enhancement count and detect if the enhancement task Petition 870250084323, dated 09 / 18 / 2025, page 50 / 100 36 / 64 software is a lower-version software enhancement task to obtain a software enhancement rollback flag. See step S102 of the mode shown in Fig. 4 for details, which will not be repeated here.
[096] Step S303: generation of certification information based on the first software enhancement count.
[097] Specifically, the CERT_INFO certification information is information used by the vehicle-side authentication module to determine whether the execution of the OTA enhancement process is a legitimate act. Its content consists primarily of a random RNG number and the first software enhancement count OTA_COUNT.
[098] Step S304: Perform symmetric encryption on software information using the software enhancement master key to obtain a rollback service key.
[099] In some optional implementations, referring again to Fig. 3, the enhancement unit generates the SOFT_INFO software information and the CERT_INFO certification information and then sends the SOFT_INFO software information and the CERT_INFO certification information to the certification module in the certification unit. The certification module invokes OTA_MASTER_KEY to perform a secure operation on SOFT_INFO based on a symmetric cryptographic algorithm, to obtain the OTA_RE_KEY rollback service key for a current software version.
[100] The SOFT_INFO software information is a derivation factor used to generate OTA_RE_KEY, a unique key per enhancement, related to the enhancement service. It consists of information such as the SOFT_VN software version number (including the current software version and Petition 870250084323, dated 09 / 18 / 2025, page 51 / 100 37 / 64 (a software enhancement version) and the RE_OTA_FLAG software enhancement rollback flag.
[101] Step S305: Perform symmetric encryption on certification information using the rollback service key to obtain encrypted certification information.
[102] In some optional implementations, referring again to Fig. 3, the certification unit invokes the OTA_RE_KEY rollback service key to perform a secure operation on the CERT_INFO certification information based on a symmetric cryptographic algorithm, to obtain the encrypted ENC_CERT_INFO certification information and then returns ENC_CERT_INFO to the enhancement unit.
[103] When certification information for certification enhancement is generated and sent to the vehicle side, it is encrypted to improve transmission security.
[104] Step S306: Send the software information, certification information, encrypted certification information, software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task to the vehicle side.
[105] For example, referring again to Fig. 3, upon receiving the encrypted certification information ENC_CERT_INFO, the enhancement unit delivers the encrypted certification information ENC_CERT_INFO, the certification information CERT_INFO, the software information SOFT_INFO, the software enhancement package and the software enhancement rollback flag RE_OTA_FLAG to the vehicle-side authentication unit via an OTA channel.
[106] Step S403: receive software information, certification information, encrypted certification information, flag Petition 870250084323, dated 09 / 18 / 2025, page 52 / 100 38 / 64 software enhancement rollback and the software enhancement package corresponding to the software enhancement task, which are returned by the network side.
[107] Step S404: when determining, based on the software enhancement rollback flag, the upgrade to a lower version software, perform symmetric encryption on the software information based on the software enhancement master key to obtain the rollback service key.
[108] Specifically, the software enhancement rollback flag is used to indicate a software enhancement status. When its value is 0, it indicates that the enhancement version is higher than the current software version on the vehicle side, indicating a normal software enhancement process. When its value is 1, it indicates that the enhancement version is lower than the current software version on the vehicle side, indicating a special enhancement process, and the vehicle side needs to authenticate the enhancement process to determine if the lower-version OTA enhancement is legitimate.
[109] For example, referring again to Fig. 3, when the vehicle-side authentication unit determines that RE_OTA_FLAG=0, this indicates a normal enhancement process and the process is allowed to proceed; and when RE_OTA_FLAG=1, it indicates a special enhancement process and authentication is required. When the vehicle-side authentication unit determines that authentication is required, the authentication module first invokes the software enhancement master key OTA_MASTER_KEY to perform a secure operation on the SOFT_INFO software information based on a symmetric encryption algorithm, using the same method as Petition 870250084323, dated 09 / 18 / 2025, page 53 / 100 39 / 64 operation by which the certification module calculates OTA_RE_KEY, to obtain the OTA_RE_KEY rollback service key.
[110] Step S405: Decrypt the encrypted certification information using the rollback service key to obtain new decrypted certification information and extract the first software enhancement count stored on the network side from the new certification information.
[111] For example, referring again to Fig. 3, the authentication module invokes the OTA_RE_KEY rollback service key to decrypt the encrypted certification information ENC_CERT_INFO, to obtain the new CERT_INFO' and extracts the first software enhancement count OTA_COUNTa from the new CERT_INFO'.
[112] Encrypted information sent over the network is decrypted using the software enhancement master key to facilitate subsequent determination of the legitimacy of the OTA enhancement and improve the security of information transmission.
[113] Step S406: upon determining that the OTA upgrade is legitimate based on a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a matching ratio between the new certification information and the certification information, upgrade to the lower version software using the software upgrade package.
[114] In some optional implementations, the S406 step described above includes the following steps.
[115] Step c1: if the first software enhancement count is detected as greater than the second enhancement count Petition 870250084323, dated 09 / 18 / 2025, page 54 / 100 40 / 64 software, determine if the new certification information is consistent with the existing certification information.
[116] Step c2: if the new certification information is detected as consistent with the certification information, determine that the OTA enhancement is legitimate, assign the value of the first software enhancement count to the second software enhancement count and perform an enhancement step for the lower version software using the software enhancement package.
[117] Step c3: if it is detected that the new certification information is inconsistent with the certification information, or if the count of the first software enhancement is not greater than the count of the second software enhancement, stop the enhancement.
[118] For example, referring again to Fig. 3, after extracting the first software enhancement count OTA_COUNT from the new CERT_INFO', the authentication module compares the first software enhancement count with the second software enhancement count V_OTA_COUNT securely stored in the authentication module. If OTA_COUNT > V_OTA_COUNT, CERT_INFO' will be compared with the delivered CERT_INFO. If they are equal, the upgrade to a lower version will be considered a legitimate act, and the value of OTA_COUNT will be assigned to V_OTA_COUNT. If CERT_INFO' is not the same as the delivered CERT_INFO, the upgrade will be considered abnormal and stopped. If OTA_COUNT < V_OTA_COUNT, the upgrade will be considered illegitimate and terminated.
[119] The magnitude relationship between the first software enhancement count and the second software enhancement count is determined, and the consistency between the new information of Petition 870250084323, dated 09 / 18 / 2025, page 55 / 100 41 / 64 certification and certification information is verified to determine if the downgrade is legitimate. This increases security during OTA upgrades and avoids security risks caused by security vulnerabilities in downgrade software.
[120] In the OTA enhancement method according to the embodiments of the present application, the network side is used to generate an initial software enhancement count that records a software enhancement count, a software enhancement rollback flag indicating whether the task is a down-version software enhancement task, as well as software information, certification information, encrypted certification information, and a software enhancement package that are required by the vehicle side, such that the vehicle side, upon determining, based on the software enhancement rollback flag, whether to upgrade to the down-version software, decrypts the encrypted certification information to obtain new certification information and an initial software enhancement count,And by determining that the OTA upgrade is legitimate based on a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding ratio between the new certification information and the certification information, it upgrades to the lower version software using the software upgrade package, thus ensuring the security and legitimacy of the upgrade when a user upgrades to the lower version software.
[121] In this embodiment, an OTA enhancement method is provided. The method can be used for the network side 101 and the vehicle side 102, shown in Fig. 1. Fig. 6 is a schematic diagram of a process of Petition 870250084323, dated 09 / 18 / 2025, page 56 / 100 42 / 64 interaction of the OTA enhancement system according to the modalities of the present application. Network side 101 is configured to perform step S501, and vehicle side 102 is configured to perform steps S601 to S605. The specific interaction process between network side 101 and vehicle side 102 is as follows.
[122] Step S501: Generate a software enhancement master key and send the software enhancement master key to the vehicle side. See step S301 of the modality shown in Fig. 5 for details, which will not be repeated here.
[123] Step S601: receive the software enhancement master key sent by the network side. See step S401 of the modality shown in Fig. 5 for details, which will not be repeated here.
[124] Step S602: obtain a software enhancement version and a current software version and compare the software enhancement version and the current software version to obtain a software enhancement rollback flag used to indicate whether the task is a lower-version software enhancement task.
[125] Specifically, during the software upgrade process, the vehicle-side authentication unit determines the software version number. If the software upgrade version is higher than the current software version in the vehicle, this indicates a normal upgrade process and the process can proceed. If the software upgrade version is lower than or equal to the current software version on the vehicle side, this indicates a special upgrade process, and authentication is required to determine if the lower-version OTA upgrade is legitimate, thus triggering the RE_OTA_FLAG software upgrade rollback flag. Petition 870250084323, dated 09 / 18 / 2025, page 57 / 100 43 / 64 is used to indicate whether the task is a lower-version software enhancement task.
[126] Step S603: when determining, based on the software enhancement rollback flag, to upgrade to a lower version, perform symmetric encryption on the software enhancement version, the current software version, and the software enhancement rollback flag to obtain a rollback service key and receive certification information for enhancement certification, encrypted certification information, and a software enhancement package, which are entered offline by a user.
[127] For example, referring again to Fig. 3, when the vehicle-side authentication unit determines that authentication is required, the authentication module invokes OTA_MASTER_KEY to perform a secure operation on the software enhancement rollback flag RE_OTA_FLAG and the software version number SOFT_VN, which includes the software enhancement version and the current software version, based on a symmetric cryptography algorithm, to obtain the rollback service key OTA_RE_KEY and then prompts the user, via a display interface, to enter the certification information CERT_INFO, the encrypted certification information ENC_CERT_INFO, and the software enhancement package. The symmetric cryptography operation is performed using the same method by which the certification module calculates OTA_RE_KEY.
[128] It should be noted that certification information, encrypted certification information, and the software enhancement package are obtained by the user from the network side. The user can enter the software enhancement task from the vehicle side to the network side. After obtaining data such as encrypted certification information Petition 870250084323, dated 09 / 18 / 2025, page 58 / 100 44 / 64 ENC_CERT_INFO, the network-side enhancement unit, provides the encrypted ENC_CERT_INFO certification information, the CERT_INFO certification information, and the software enhancement package to the user offline.
[129] Therefore, in an offline scenario, a legitimate downgrade is performed by receiving the certification information, the encrypted certification information and the user's input of the software enhancement package.
[130] Step S604: Decrypt the encrypted certification information using the rollback service key to obtain new decrypted certification information and extract a first software enhancement count stored on the network side from the new certification information. See step S405 of the modality shown in Fig. 5 for details, which will not be repeated here.
[131] Step S605: when determining that the OTA upgrade is legitimate based on a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding ratio between the new certification information and the certification information, upgrade to the lower version software using the software upgrade package. See step S406 of the embodiment shown in Fig. 5 for details, which will not be repeated here.
[132] In the OTA enhancement method according to the embodiments of the present application, the network side is used to generate a software enhancement master key, and the vehicle side receives software information, certification information, encrypted certification information and a software enhancement package, which are inserted Petition 870250084323, dated 09 / 18 / 2025, page 59 / 100 45 / 64 offline by a user, so that the vehicle side, upon determining, based on the software upgrade rollback flag, to upgrade to a lower version software, decrypts the encrypted certification information using the software upgrade master key to obtain new certification information and a first software upgrade count, and upon determining that the OTA upgrade is legitimate based on a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding ratio between the new certification information and the certification information, upgrades to the lower version software using the software upgrade package, thus ensuring the security and legitimacy of the upgrade when the user upgrades to the lower version software.
[133] In this embodiment, an OTA enhancement method is provided. The method can be used for the network side 101 and the vehicle side 102, shown in Fig. 1. Fig. 7 is a schematic diagram of an interaction process of the OTA enhancement system according to the embodiments of the present application. The network side 101 is configured to perform steps S701 to S705, and the vehicle side 102 is configured to perform steps S801 to S805. The specific interaction process between the network side 101 and the vehicle side 102 is as follows.
[134] Step S701: generate an asymmetric key pair consisting of a software enhancement public key and a software enhancement private key and send the software enhancement public key to the vehicle side.
[135] In some optional implementations, referring again to Fig. 3, the certification unit invokes the key generation module to generate Petition 870250084323, dated 09 / 18 / 2025, page 60 / 100 46 / 64 randomly generates the asymmetric key pair composed of the software enhancement public key OTA_MASTER_KEY_P and the software enhancement private key OTA_MASTER_KEY_S. OTA_MASTER_KEY_S is securely stored in the key storage module and cannot be exported in plain text, and OTA_MASTER_KEY_P is sent to the vehicle side. For example, the key generation module is implemented using a hardware security module (HSM) device.
[136] Step S801: receive the software enhancement public key sent by the network side.
[137] Specifically, the network-side certification unit sends the OTA_MASTER_KEY_P public key offline to the vehicle-side authentication unit, and the vehicle-side authentication unit securely stores OTA_MASTER_KEY_P in the vehicle-side key management module.
[138] Step S802: Send a software enhancement task to the network side. See step S402 of the mode shown in Fig. 5 for details, which will not be repeated here.
[139] Step S702: upon receiving the software enhancement task sent from the vehicle side, update an initial software enhancement count and detect if the software enhancement task is a lower version software enhancement task to obtain a software enhancement rollback flag. See step S302 of the modality shown in Fig. 5 for details, which will not be repeated here.
[140] Step S703: generation of certification information based on the first software enhancement count. See step S303 of Petition 870250084323, dated 09 / 18 / 2025, page 61 / 100 47 / 64 mode shown in Fig. 5 for details, which will not be repeated here.
[141] Step S704: Perform a compilation operation on the certification information to obtain compilation certification information and perform asymmetric encryption on the compilation certification information using the software enhancement private key to obtain signing certification information.
[142] In some optional implementations, referring again to Fig. 3, the enhancement unit sends the CERT_INFO certification information to the certification module in the certification unit. The certification module performs the compilation operation on CERT_INFO to obtain the compilation certification information. DIG_CERT_INFO. A compilation operation algorithm used can be any commonly used and secure compilation algorithm, such as SHA256, SM3, etc. The embodiments of the present application are not limited to this. Then, the software enhancement private key OTA_MASTER_KEY_S is invoked to perform a secure operation on the compilation certification information DIG_CERT_INFO based on an asymmetric cryptographic algorithm, to obtain the signature certification information SIG_CERT_INFO. Then, SIG_CERT_INFO is returned to the enhancement unit.
[143] When signature certification information for enhancement certification is generated and sent to the vehicle side, encryption and a compilation operation are performed on the certification information to improve transmission security.
[144] Step S705: send certification information, signature certification information, enhancement rollback flag Petition 870250084323, dated 09 / 18 / 2025, page 62 / 100 48 / 64 software and a software enhancement package corresponding to the software enhancement task for the vehicle side.
[145] For example, referring again to Fig. 3, upon receiving the SIG_CERT_INFO signature certification information, the enhancement unit delivers the SIG_CERT_INFO signature certification information, the CERT_INFO certification information, the software enhancement rollback flag, and the software enhancement package to the vehicle-side authentication unit via an OTA channel.
[146] Step S803: receive the certification information, the signature certification information, the software enhancement rollback flag, and the software enhancement package corresponding to the software enhancement task, which are returned by the network side.
[147] Step S804: when determining, based on the software enhancement rollback flag, to upgrade to a lower version software, decrypt the signature certification information based on the software enhancement public key to obtain the build certification information, perform a build operation on the certification information to obtain new build certification information, and extract the first software enhancement count from the certification information.
[148] Specifically, the software enhancement rollback flag is used to indicate a software enhancement status. When its value is 0, it indicates that the enhancement version is higher than the current software version on the vehicle side, indicating a normal software enhancement process. When its value is 1, it indicates that the enhancement version is lower than the current software version on the vehicle side, indicating a special enhancement process, and the vehicle side needs Petition 870250084323, dated 09 / 18 / 2025, page 63 / 100 49 / 64 authenticate the enhancement process to determine if the downgrade OTA enhancement is legitimate.
[149] For example, referring again to Fig. 3, when the vehicle-side authentication unit determines that RE_OTA_FLAG=0, this indicates a normal enhancement process and the process is allowed to proceed; and when RE_OTA_FLAG=1, it indicates a special enhancement process and authentication is required. When the vehicle-side authentication unit determines that authentication is required, the authentication module invokes the software enhancement public key OTA_MASTER_KEY_P to decrypt the signature certification information SIG_CERT_INFO, to obtain the compilation certification information DIG_CERT_INFO, and then performs the compilation operation on the received certification information CERT_INFO to obtain the new compilation certification information DIG_CERT_INFO. The compilation operation is performed using the same algorithm method used by the certification module.In addition, the first software enhancement count is extracted from the CERT_INFO certification information.
[150] Signature certification information sent over the network is decrypted using the software update public key to facilitate subsequent determination of OTA enhancement legitimacy and improve information transmission security.
[151] Step S805: when determining that the OTA enhancement is legitimate based on a magnitude ratio between the first software enhancement count and a second software enhancement count stored on the vehicle side, as well as a corresponding ratio between the new build certification information and the Petition 870250084323, dated 09 / 18 / 2025, page 64 / 100 50 / 64 build certification information, enhance for lower version software using the software enhancement package.
[152] In some optional implementations, the S805 step described above includes the following steps.
[153] Step d1: if the new build certification information is detected as consistent with the build certification information, determine whether the first software enhancement count is greater than the second software enhancement count.
[154] Step d2: if the first software enhancement count is detected as being greater than the second software enhancement count, determine that the OTA enhancement is legitimate, assign the value of the first software enhancement count to the second software enhancement count, and perform an enhancement step for the lower version software using the software enhancement package.
[155] Step d3: if the first software enhancement count is detected as no greater than the second software enhancement count, or if the new build certification information is detected as inconsistent with the build certification information, stop the enhancement.
[156] For example, the authentication module compares the new build certification information DIG_CERT_INFO' with the build certification information DIG_CERT_INFO. If they are different, the enhancement will be terminated. If they are the same, the first software enhancement count OTA_COUNT will be compared with the second software enhancement count V_OTA_COUNT securely stored in the authentication module. If OTA_COUNT > V_OTA_COUNT, it is determined that this enhancement to a lower version is an act Petition 870250084323, dated 09 / 18 / 2025, page 65 / 100 51 / 64 legitimate, and the value of OTA_COUNT is assigned to V_OTA_COUNT. If OTA_COUNT < V_OTA_COUNT, the enhancement will be considered illegitimate and terminated.
[157] The magnitude ratio between the first software enhancement count and the second software enhancement count is determined, and the consistency between the new certification information and the build information is checked, in order to determine whether the downgraded version enhancement is legitimate. This increases security during OTA enhancement and avoids security risks caused by security vulnerabilities in the downgraded software.
[158] In this embodiment, an OTA enhancement method is provided. The method can be used for the network side 101 and the vehicle side 102, shown in Fig. 1. Fig. 8 is a schematic diagram of an interaction process of the OTA enhancement system according to the embodiments of the present application. The network side 101 is configured to perform step S901, and the vehicle side 102 is configured to perform steps S1001 to S1005. The specific interaction process between the network side 101 and the vehicle side 102 is as follows.
[159] Step S901: generate an asymmetric key pair consisting of a software enhancement public key and a software enhancement private key and send the software enhancement public key to the vehicle side. See step S701 of the modality shown in Fig. 7 for details, which will not be repeated here.
[160] Step S1001: receive the software enhancement public key sent by the network side. See step S801 of the modality shown in Fig. 7 for details, which will not be repeated here.
[161] Step S1002: obtain a software enhancement version and a current software version and compare the enhancement version of Petition 870250084323, dated 09 / 18 / 2025, page 66 / 100 52 / 64 software and the current software version to obtain a software enhancement rollback flag used to indicate whether the task is a downgrade software enhancement task. See step S602 of the modality shown in Fig. 6 for details, which will not be repeated here.
[162] Step S1003: when determining, based on the software enhancement rollback flag, to upgrade to a lower version software, receive certification information for enhancement certification, signature certification information and a software enhancement package, which are entered offline by a user.
[163] For example, referring again to Fig. 3, when the vehicle-side authentication unit determines that authentication is required, the authentication unit suggests to the user, via a display module, that they enter the CERT_INFO certification information, the SIG_CERT_INFO signature certification information, and the software enhancement package.
[164] It should be noted that the CERT_INFO certification information, the SIG_CERT_INFO signature certification information, and the software enhancement package are obtained by the user from the network side. The user can enter the software enhancement task from the vehicle side to the network side. After obtaining data such as the SIG_CERT_INFO signature certification information, the enhancement unit on the network side provides the encrypted ENC_CERT_INFO certification information, the CERT_INFO certification information, and the software enhancement package to the user offline.
[165] Therefore, in an offline scenario, a legitimate downgrade is performed upon receiving the certification information, Petition 870250084323, dated 09 / 18 / 2025, page 67 / 100 53 / 64 signature certification information and user input of the software enhancement package.
[166] Step S1004: decrypt the signature certification information based on the software enhancement public key to obtain the build certification information, perform a build operation on the certification information to obtain new build certification information, and extract the first software enhancement count from the certification information. See step S804 of the modality shown in Fig. 7 for details, which will not be repeated here.
[167] Step S1005: when determining that the OTA enhancement is legitimate based on a magnitude ratio between the first software enhancement count and a second software enhancement count stored on the vehicle side, as well as a corresponding ratio between the new build certification information and the build certification information, enhance to the lower version software using the software enhancement package. See step S805 of the modality shown in Fig. 7 for details, which will not be repeated here.
[168] An OTA enhancement method according to the embodiments of the present application is further described in detail below together with multiple application scenarios. The OTA enhancement method can be applied to the OTA enhancement system shown in Fig. 3.
[169] 1) Use a symmetric cryptographic algorithm The certification unit generates a software enhancement master key, which is used to perform a secure operation on the SOFT_INFO software information entered by the enhancement unit based on a Petition 870250084323, dated 09 / 18 / 2025, page 68 / 100 54 / 64 encryption algorithm, to obtain an OTA_RE_KEY rollback service key for a current software version. The OTA_RE_KEY rollback service key is used to verify the legitimacy of an enhancement version and protect enhancement permissions.
[170] The enhancement unit is configured to manage and deliver an enhancement software version. When it determines that the software enhancement version is lower than the vehicle's current software version, it generates a RE_OTA_FLAG software enhancement rollback flag.
[171] Optionally, the enhancement unit generates CERT_INFO certification information, encrypts CERT_INFO using OTA_RE_KEY to obtain encrypted ENC_CERT_INFO certification information, and then delivers a software enhancement package, the encrypted ENC_CERT_INFO certification information, the CERT_INFO certification information, and the RE_OTA_FLAG software enhancement rollback flag to the vehicle-side authentication unit.
[172] Scenario 1: During an online software upgrade process, this scenario typically occurs after users' vehicles are already on the market. When the new version software exhibits instability during an upgrade to the new version, it becomes necessary to perform a large-scale upgrade of mass-produced vehicle models to an older version. The vehicle-side authentication unit determines a software upgrade version. If the upgrade version to be upgraded is higher than the current software version, the upgrade is allowed to proceed. If the upgrade version is lower than the current software version, the SOFT_INFO software information will be extracted and a secure operation will be performed on the information. Petition 870250084323, dated 09 / 18 / 2025, page 69 / 100 55 / 64 software SOFT_INFO based on a symmetric encryption algorithm using the predefined software enhancement master key OTA_MASTER_KEY. The operation is performed using the same method by which the certification unit generates the rollback service key OTA_RE_KEY, to obtain the rollback service key OTA_RE_KEY. The encrypted certification information ENC_CERT_INFO is decrypted using OTA_RE_KEY to obtain CERT_INFO, which is compared with the delivered CERT_INFO. If they are the same, it is determined that this upgrade to a lower version is a legitimate act. If they are different, the upgrade is determined to be abnormal and stopped.
[173] Scenario 2: During an offline software enhancement process, this scenario is primarily used in a testing phase or for troubleshooting during mass production. It involves authentication to enhance a single vehicle model to a lower version via offline means, such as a USB interface. The vehicle-side authentication unit determines a software enhancement version. If the software enhancement version is less than or equal to a vehicle-side software version number, this indicates a special enhancement process and authentication is required. The authentication module invokes OTA_MASTER_KEY to perform a secure operation on SOFT_VN and RE_OTA_FLAG based on a symmetric cryptographic algorithm. The operation is performed using the same method by which the certification module calculates OTA_RE_KEY, to obtain OTA_RE_KEY.The user is then prompted, through a display interface, to enter information such as CERT_INFO and ENC_CERT_INFO.
[174] The authentication module invokes OTA_RE_KEY to decrypt the encrypted ENC_CERT_INFO certification information to obtain Petition 870250084323, dated 09 / 18 / 2025, page 70 / 100 56 / 64 CERT_INFO' extracts an initial software upgrade count, OTA_COUNT, from CERT_INFO' and compares this first software upgrade count with a second software upgrade count, V_OTA_COUNT, securely stored in the authentication module. If OTA_COUNT > V_OTA_COUNT, then CERT_INFO' is compared with the delivered CERT_INFO. If they are the same, it is determined that this upgrade to a lower version is a legitimate act, and the value of OTA_COUNT is assigned to V_OTA_COUNT. If they are not the same, the upgrade is determined to be abnormal and stopped. If OTA_COUNT < V_OTA_COUNT, the upgrade is determined to be illegitimate and the upgrade is terminated.
[175] 2) Use an asymmetric cryptographic algorithm When receiving a software enhancement task, the enhancement unit increments an OTA_COUNT counter indicating a software enhancement count by 1 and then determines a software enhancement version number. If the software enhancement version number is greater than the current software version, the enhancement unit sets the software enhancement rollback flag RE_OTA_FLAG to 0. If the software enhancement version number is less than or equal to the current software version, the enhancement unit sets RE_OTA_FLAG to 1 and sends the CERT_INFO certification information for certification to the certification module in the certification unit.
[176] The certification module performs a compilation operation on the CERT_INFO certification information to obtain the DIG_CERT_INFO compilation certification information. A compilation operation algorithm used can be any commonly used compilation algorithm. Petition 870250084323, dated 09 / 18 / 2025, page 71 / 100 57 / 64 used and secure, such as SHA256, SM3, etc. Then, the certification module invokes an OTA_MASTER_KEY_S software enhancement private key to perform a secure operation on the DIG_CERT_INFO compilation certification information based on an asymmetric cryptography algorithm, to obtain the SIG_CERT_INFO signature certification information, and then returns SIG_CERT_INFO to the enhancement unit.
[177] Scenario 3: During an online software upgrade, this scenario typically occurs after users’ vehicles are already on the market. When the new version software exhibits instability during an upgrade to the new version, it becomes necessary to perform a large-scale upgrade of mass-produced vehicle models to an older version. After receiving SIG_CERT_INFO, the upgrade unit delivers SIG_CERT_INFO, CERT_INFO, a software upgrade package, a RE_OTA_FLAG software upgrade rollback flag, etc. to the vehicle-side authentication unit via an OTA channel.
[178] When the vehicle-side authentication unit determines that RE_OTA_FLAG=0, this indicates a normal enhancement process and the process is allowed to proceed. When RE_OTA_FLAG=1, it indicates a special enhancement process and authentication is required. When the vehicle-side authentication unit determines that authentication is required, the authentication module invokes OTA_MASTER_KEY_P to decrypt SIG_CERT_INFO to obtain DIG_CERT_INFO and then performs a compilation operation on the received CERT_INFO to obtain DIG_CERT_INFO'. The compilation operation is performed using the same algorithm method used by the certification module. Then, DIG_CERT_INFO' is compared with DIG_CERT_INFO to determine if they are the same. If they are different, the Petition 870250084323, dated 09 / 18 / 2025, page 72 / 100 58 / 64 enhancement will be terminated. If they are the same, OTA_COUNT will be extracted from CERT_INFO and compared with V_OTA_COUNT securely stored in the authentication module. If OTA_COUNT > V_OTA_COUNT, this lower-version enhancement is determined to be a legitimate act, and the value of OTA_COUNT is assigned to V_OTA_COUNT. If OTA_COUNT < V_OTA_COUNT, the enhancement will be considered illegitimate and terminated.
[179] Scenario 4: During an offline software enhancement process, this scenario is primarily used in a testing phase or for troubleshooting during mass production. It involves authentication to enhance a single vehicle model to a lower version via offline means, such as a USB interface. After receiving SIG_CERT_INFO, the enhancement unit provides information as SIG_CERT_INFO to a user offline.
[180] The vehicle-side authentication unit determines the software enhancement version. If the software enhancement version is higher than the current software version, this indicates a normal enhancement process and the process is allowed to proceed. If the software enhancement version is lower than or equal to the current software version, this indicates a special enhancement process and authentication is required. When the vehicle-side authentication unit determines that authentication is required, the authentication unit prompts the user, via a display module, to enter information such as CERT_INFO, SIG_CERT_INFO, etc.
[181] The authentication module invokes OTA_MASTER_KEY_P to decrypt SIG_CERT_INFO, to obtain DIG_CERT_INFO, and then performs a compilation operation on the received CERT_INFO to obtain DIG_CERT_INFO. The compilation operation is performed using the same algorithm method used by the certification module. Then, Petition 870250084323, dated 09 / 18 / 2025, page 73 / 100 59 / 64 DIG_CERT_INFO is compared with DIG_CERT_INFO to determine if they are the same. If they are different, the enhancement will be terminated. If they are the same, OTA_COUNT will be extracted from CERT_INFO and compared with V_OTA_COUNT securely stored in the authentication module. If OTA_COUNT > V_OTA_COUNT, this lower-version enhancement is determined to be a legitimate act, and the value of OTA_COUNT is assigned to V_OTA_COUNT. If OTA_COUNT < V_OTA_COUNT, the enhancement will be considered illegitimate and terminated.
[182] The embodiments of the present application provide a secure OTA upgrade system for upgrading software to a lower version. The system is used to address the issue of preventing unauthorized users from illegally upgrading to older version software by exploiting known vulnerabilities in the lower version software when the new version software has quality issues and upgrading to the lower version software is necessary, as well as providing security protection against unauthorized upgrades of lower version software in online and offline upgrade scenarios.
[183] The embodiments of the present application additionally provide a computer device, which can be applied to the network side.
[184] Referring to Fig. 9, which is a schematic structural diagram of a computer device according to an optional embodiment of the present application, as shown in Fig. 9, the computer device includes: one or more first processors 10, a first memory 20 and interfaces for connecting various components, including a high-speed interface and a low-speed interface. The components are communicatively connected to each other via different buses and can be mounted on a common motherboard or otherwise mounted Petition 870250084323, dated 09 / 18 / 2025, p. 74 / 100 60 / 64 as needed. The processor can process instructions executed on the computer device, including instructions stored in or within memory, to display graphical GUI information on external input / output media (e.g., a display device coupled to the interface). In some optional implementations, a plurality of processors and / or a plurality of buses can be used with a plurality of memories and a plurality of storage devices, if necessary. Similarly, a plurality of computer devices can be connected, and the devices provide part of the necessary operations (e.g., as an array of servers, a group of blade servers, or a multiprocessor system). A first processor 10 is used as an example in FIG. 9.
[185] The first processor 10 may be a central processing unit, a network processing unit, or a combination thereof. The first processor 10 may also include a hardware chip. The aforementioned hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The aforementioned programmable logic device may be a complex programmable logic device, an array of field-programmable logic gates, a generic array logic, or any combination thereof.
[186] The first memory 20 stores executable instructions by at least one first processor 10, so that at least one processor 10 implements the method illustrated in the embodiment described above.
[187] The first memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and Petition 870250084323, dated 09 / 18 / 2025, page 75 / 100 61 / 64 application programs required by at least one function; and the data storage area may store data created in accordance with the use of a computer device and the like. In addition, the first memory 20 may include high-speed random access memory and may also include non-transient memory, such as at least one magnetic disk storage device, flash memory device, or other non-transient solid-state storage device. In some optional implementations, the first memory 20 optionally includes memories supplied remotely from the first processor 10, and these remote memories may be connected to the computer device via a network. Examples of the aforementioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[188] The first memory 20 may include volatile memory, such as random access memory; or the memory may include non-volatile memory, such as flash memory, a hard disk or a solid state drive; or the first memory 20 may include a combination of the memory types mentioned above.
[189] The computer device additionally includes input medium 30 and output medium 40. The first processor 10, the first memory 20, the input medium 30 and the output medium 40 can be connected by means of a bus or by other means. Connection via a bus is used in Fig. 9 as an example.
[190] Input media 30 can receive numeric or character input information and generate key signal inputs related to user settings and functional control of the computer device, such as a touch screen, numeric keypad, mouse, trackpad, touchpad, Petition 870250084323, dated 09 / 18 / 2025, page 76 / 100 62 / 64 pointing device, one or more mouse buttons, trackball, joystick and the like. The emission medium 40 may include a display device, an auxiliary lighting device (e.g., an LED) and a tactile feedback device (e.g., a vibration motor) and the like. The aforementioned display device includes, but is not limited to, a liquid crystal display, a light-emitting diode display and a plasma display. In some optional implementations, the display device may be a touch screen.
[191] The embodiments of the present disclosure further provide a vehicle. Referring to Fig. 10, which is a schematic structural diagram of a vehicle according to an optional embodiment of the present application, as shown in Fig. 10, the vehicle includes: one or more second processors 50, a second memory 60, and interfaces for connecting various components, including a high-speed interface and a low-speed interface. The vehicle further includes a second input medium 70 and a second output medium 80. The second processor 50, the second memory 60, the second input medium 70, and the second output medium 80 can be connected via a bus or by other means. Connection via a bus is used in Fig. 10 as an example.Regarding the communication process between the second processor 50, the second memory 60, the second input medium 70, and the second output medium 80 in the vehicle, reference can be made to the description of the computer device above, and it will not be repeated here.
[192] Embodiments of the present application further provide a computer storage medium. The method described above, according to the embodiments of the present application, may be implemented in hardware or firmware, or implemented as computer code that may be Petition 870250084323, dated 09 / 18 / 2025, page 77 / 100 63 / 64 recorded on a storage medium, or implemented as computer code that is downloaded over a network and originally stored on a remote storage medium or non-transient machine-readable storage medium, and which must be stored on a local storage medium, so that the method described herein can be processed by such software stored on a storage medium that uses a general-purpose computer, a dedicated processor, or dedicated or programmable hardware. The storage medium may be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, solid-state drive, or the like. Optionally, the storage medium may also include a combination of the memory types mentioned above.It can be understood that the computer, processor, microprocessor, controller, or programmable hardware includes a storage component that can store or receive software or computer code, and when the software or computer code is accessed and executed by the computer, processor, or hardware, the method illustrated in the embodiment above is implemented.
[193] Part of the present application may be applied as a computer program product, such as computer program instructions, which, when executed by a computer, may invoke or provide the method and / or technical solution according to the present application through the operation of the computer. Those skilled in the art should understand that the forms of computer program instructions in a computer-readable medium include, but are not limited to, a source file, an executable file, an installer package and the like, and consequently, the ways in which computer program instructions are executed by the computer include, but are not limited to: the computer executing Petition 870250084323, dated 09 / 18 / 2025, page 78 / 100 64 / 64 directly the instructions, or the computer compiling the instructions and then executing a corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing a corresponding installed program. Here, the computer-readable medium can be any computer-readable storage medium or communication medium accessible to a computer.
[194] Although the embodiments of the present application are described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present application, and such modifications and variations are all included within the scope defined by the appended claims. Petition 870250084323, dated 09 / 18 / 2025, page 79 / 100
Claims
1 / 13 CLAIMS 1. Over-the-air enhancement method, characterized in that the method is applied to one network side, the method comprising: generating a software enhancement key and sending the software enhancement key to a vehicle side; upon receiving a software enhancement task sent by the vehicle side, updating a first software enhancement count and detecting whether the software enhancement task is a lower version software enhancement task to obtain a software enhancement rollback flag; encrypting enhancement information comprising the first software enhancement count using the software enhancement key to generate encrypted enhancement information; and sending the enhancement information, the encrypted enhancement information,The software enhancement rollback flag and a software enhancement package corresponding to the software enhancement task for the vehicle side, wherein: the vehicle side, upon determining, based on the software enhancement rollback flag, to upgrade to a lower version software, decrypts the encrypted enhancement information based on the software enhancement key to obtain new enhancement information and the first software enhancement count, and upon determining that the over-the-air (OTA) enhancement is legitimate based on a magnitude ratio between the first software enhancement count and a second software enhancement count stored on the vehicle side, as well as a corresponding ratio between the new enhancement information and the enhancement information, enhances Petition 870250084323, dated 09 / 18 / 2025,pg. 80 / 100 2 / 13 for the lower version software using the software enhancement package.
2. A method according to claim 1, characterized in that the software enhancement key comprises a software enhancement master key; the enhancement information further comprises software information and certification information for enhancement certification, and the encrypted enhancement information comprises encrypted certification information; and encrypting enhancement information comprising the first software enhancement count using the software enhancement key to generate encrypted enhancement information comprises: generating the certification information based on the software enhancement count;Perform symmetric encryption on software information using the software enhancement master key to obtain a rollback service key, wherein the software information is generated based on a software enhancement version corresponding to the software enhancement task, a current software version, and the software enhancement rollback flag; and perform symmetric encryption on certification information using the rollback service key to obtain the encrypted certification information.
3. Method according to claim 2, characterized in that sending the enhancement information, the encrypted enhancement information, the software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task to the vehicle side comprises: sending the software information, the certification information, the encrypted certification information, the software enhancement rollback flag, and the software enhancement package corresponding to the software enhancement task to the vehicle side, wherein the vehicle side, upon determining, based on the software enhancement rollback flag, to upgrade to the lower version software,It decrypts the encrypted certification information based on the software enhancement master key and software information, and extracts the first software enhancement count based on the new certification information obtained through decryption. Upon determining that the OTA enhancement is legitimate based on the magnitude ratio between the first software enhancement count and the second software enhancement count stored on the vehicle side, as well as the corresponding ratio between the new certification information and the certification information, it upgrades to the lower version software using the software enhancement package.
4. Method, according to claim 2, characterized in that generating a software enhancement key and sending the software enhancement key to a vehicle side comprises: upon receiving a public key sent by the vehicle side, generating the software enhancement master key and a transmission protection key; performing asymmetric cryptography on the transmission protection key using the public key to obtain a ciphertext transmission protection key and performing symmetric cryptography on the software enhancement master key based on the ciphertext transmission protection key for Petition 870250084323, dated 09 / 18 / 2025, p.82 / 100 4 / 13 obtain a ciphertext software enhancement master key; and send the ciphertext software enhancement master key and the ciphertext transmission protection key to the vehicle side, so that the vehicle side decrypts the ciphertext transmission protection key using a private key corresponding to the public key to obtain the transmission protection key and decrypts the ciphertext software enhancement master key based on the transmission protection key to obtain the software enhancement master key.
5. A method according to claim 1, characterized in that the software enhancement key comprises an asymmetric key pair consisting of a public software enhancement key and a private software enhancement key; the enhancement information further comprises certification information for enhancement certification and build certification information, and the encrypted enhancement information comprises signature certification information; and encrypting enhancement information comprising the first software enhancement count using the software enhancement key to generate encrypted enhancement information comprises: generating the certification information based on the software enhancement count;and perform a compilation operation on the certification information to obtain the compilation certification information and perform asymmetric encryption on the compilation certification information using the software enhancement private key to obtain the signing certification information. Petition 870250084323, dated 09 / 18 / 2025, p. 83 / 100 5 / 13; 6. Method according to claim 5, characterized in that sending the enhancement information, the encrypted enhancement information, the software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task to the vehicle side comprises: sending the certification information, the signature certification information, the software enhancement rollback flag, and the software enhancement package corresponding to the software enhancement task to the vehicle side, wherein the vehicle side, upon determining, based on the software enhancement rollback flag, to upgrade to the lower version software, = decrypts the signature certification information based on the software enhancement public key to obtain the build certification information,Performs a compilation operation on the certification information to obtain new compilation certification information and extracts the first software enhancement count from the certification information and, upon determining that the OTA enhancement is legitimate based on the magnitude ratio between the first software enhancement count and the second software enhancement count stored on the vehicle side, as well as the corresponding ratio between the new compilation certification information and the compilation certification information, enhances to the lower version software using the software enhancement package.
7. Method, according to claim 1, characterized in that, upon receiving a software enhancement task sent from the vehicle side, it updates an initial software enhancement count and detects whether the software enhancement task is a Petition 870250084323 task, dated 09 / 18 / 2025, p.84 / 100 6 / 13 Software enhancement of a lower version to obtain a software enhancement rollback flag comprise: upon receiving the software enhancement task, increment the first software enhancement count by one and obtain a software enhancement version and a current software version based on the software enhancement task; if it is detected that the software enhancement version is not higher than the current software version, determine that the software enhancement task is a lower version software enhancement task and set the software enhancement rollback flag to one; and if it is detected that the software enhancement version is not higher than the current software version, determine that the software enhancement task is not a lower version software enhancement task and set the software enhancement rollback flag to zero.
8. Over-the-air enhancement method, characterized in that the method is applied to a vehicle side, the method comprising: receiving a software enhancement key sent by a network side; sending a software enhancement task to the network side and receiving enhancement information, encrypted enhancement information, a software enhancement rollback flag and a software enhancement packet corresponding to the software enhancement task, which are returned by the network side, wherein the encrypted enhancement information is obtained by encrypting the enhancement information comprising a first software enhancement count by the network side using the software enhancement key;The first software enhancement count of Petition 870250084323, dated 09 / 18 / 2025, page 85 / 100 7 / 13 is obtained by updating a current software enhancement count from the network side after receiving the software enhancement task; and the software enhancement rollback flag is obtained by detecting whether the software enhancement task is a lower version software enhancement task from the network side; when determining, based on the software enhancement rollback flag, to upgrade to a lower version software, decrypt the encrypted enhancement information based on the software enhancement key to obtain new enhancement information and the first software enhancement count stored on the network side;and in determining that the over-the-air (OTA) upgrade is legitimate based on a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding ratio between the new upgrade information and the upgrade information, upgrading to the lower version software using the software upgrade package.
9. Method according to claim 8, characterized in that the software enhancement key comprises a software enhancement master key; the enhancement information further comprises software information and certification information for enhancement certification, and the encrypted enhancement information comprises encrypted certification information;to receive enhancement information, encrypted enhancement information, a software enhancement rollback flag, and a software enhancement package corresponding to the task of Petition 870250084323, dated 09 / 18 / 2025, page 86 / 100 8 / 13 software enhancement, which are returned by the network side, comprises: receiving the software information, the certification information, the encrypted certification information, the software enhancement rollback flag, and the software enhancement package corresponding to the software enhancement task, which are returned by the network side;and decrypt the encrypted enhancement information based on the software enhancement key to obtain new enhancement information and the first software enhancement count stored on the network side comprises: performing symmetric encryption on the software information based on the software enhancement master key to obtain a rollback service key; and decrypting the encrypted certification information using the rollback service key to obtain new decrypted certification information and extracting the first software enhancement count stored on the network side from the new certification information.
10. Method according to claim 9, characterized in that before upgrading to the lower version software using the software enhancement package, the method further comprises: if the first software enhancement count is detected as greater than the second software enhancement count, determining whether the new certification information is consistent with the certification information; if the new certification information is detected as consistent with the certification information, determining that Petition 870250084323, dated 09 / 18 / 2025, p.87 / 100 9 / 13 OTA enhancement is legitimate, assign the value of the first software enhancement count to the second software enhancement count and perform an enhancement step for the lower version software using the software enhancement package; and if it is detected that the new certification information is inconsistent with the certification information, or if it is detected that the first software enhancement count is not greater than the second software enhancement count, stop the enhancement.
11. A method according to claim 10, characterized in that after receiving the software enhancement key sent by the network side, the method further comprises: obtaining a software enhancement version and a current software version and comparing the software enhancement version and the current software version to obtain the software enhancement rollback flag used to indicate whether the software enhancement task is a lower-version software enhancement task;when determining, based on the software enhancement rollback flag, to upgrade to a lower version, perform symmetric encryption on the software enhancement version, the current software version, and the software enhancement rollback flag to obtain the rollback service key and receive the certification information for the enhancement certification, the encrypted certification information, and the software enhancement package, which are entered offline by a user, where the certification information, the encrypted certification information, and the software enhancement package are obtained by the user from the network side; and perform a decryption step of the encrypted certification information using the rollback service key to obtain new decrypted certification information and subsequent steps.
12. Method, according to claim 8, characterized in that the software enhancement key comprises an asymmetric key pair consisting of a public software enhancement key and a private software enhancement key; the enhancement information further comprises certification information for enhancement certification and compilation certification information, and the encrypted enhancement information comprises signature certification information;Receiving enhancement information, encrypted enhancement information, a software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task, which are returned by the network side, comprises: receiving certification information, signature certification information, the software enhancement rollback flag, and the software enhancement package corresponding to the software enhancement task, which are returned by the network side;and decrypting the encrypted enhancement information based on the software enhancement key to obtain new enhancement information and the first software enhancement count stored on the network side comprises: decrypting the signature certification information based on the public software enhancement key sent by the network side to obtain the build certification information, performing a build operation on the certification information to obtain new build certification information, and extracting the first software enhancement count from the certification information.
13. Method according to claim 12, characterized in that before upgrading to the lower version software using the software enhancement package, the method further comprises: if the new build certification information is detected as consistent with the build certification information, determining whether the first software enhancement count is greater than the second software enhancement count; if the first software enhancement count is detected as being greater than the second software enhancement count, determining that the OTA enhancement is legitimate, assigning the value of the first software enhancement count to the second software enhancement count, and performing an upgrade step to the lower version software using the software enhancement package;If the first software enhancement count is detected as no greater than the second software enhancement count, or if the new build certification information is detected as inconsistent with the build certification information, stop the enhancement.
14. Method, according to claim 13, characterized in that after receiving the software enhancement public key sent by the network side, the method further comprises: obtaining a software enhancement version and a current software version and comparing the software enhancement version and the current software version to obtain the software enhancement rollback flag used to indicate whether the software enhancement task is a Petition 870250084323, dated 09 / 18 / 2025, p.90 / 100 12 / 13 software upgrade from a lower version; and when determining, based on the software upgrade rollback flag, to upgrade to a lower version, receive the certification information for upgrade certification, the signature certification information, and the software upgrade package, which are entered offline by a user, and perform a step to decrypt the signature certification information based on the software upgrade public key sent by the network side to obtain the build certification information, and subsequent steps, in which the certification information, the signature certification information, and the software upgrade package are obtained by the user from the network side.
15. Over-the-air enhancement system, characterized in that the system comprises a network side and a vehicle side; the network side is configured to generate a software enhancement key and send the software enhancement key to the vehicle side; upon receiving a software enhancement task sent by the vehicle side, update a first software enhancement count and detect if the software enhancement task is a lower version software enhancement task to obtain a software enhancement rollback flag; encrypt enhancement information comprising the first software enhancement count using the software enhancement key to generate encrypted enhancement information;and send the enhancement information, the encrypted enhancement information, the software enhancement rollback flag, and a software enhancement package corresponding to the software enhancement task to the vehicle side;and Petition 870250084323, dated 09 / 18 / 2025, page 91 / 100 13 / 13 the vehicle side is configured to, upon determining, based on the software upgrade rollback flag, to upgrade to a lower version software, decrypt the encrypted upgrade information based on the software upgrade key to obtain new upgrade information and the first software upgrade count and, upon determining that the over-the-air (OTA) upgrade is legitimate based on a magnitude ratio between the first software upgrade count and a second software upgrade count stored on the vehicle side, as well as a corresponding ratio between the new upgrade information and the upgrade information, to upgrade to the lower version software using the software upgrade package.
16. Computer device, characterized in that it comprises: a first memory and a first processor communicatively connected to each other, wherein the first memory stores first computer instructions, which are executed by the first processor to perform the OTA enhancement method defined in any one of claims 1 to 7.
17. Vehicle, characterized in that it comprises: a second memory and a second processor communicatively connected to each other, wherein the second memory stores second computer instructions, which are executed by the second processor to perform the OTA enhancement method defined in any one of claims 8 to 14. Petition 870250084323, dated 09 / 18 / 2025, pp. 92 / 100