Automobile electronic control unit key management method and device, vehicle and storage medium

By identifying and managing the types of keys for automotive electronic control units, and covering management actions throughout their entire lifecycle, the problem of incomplete key management in existing technologies is solved, thereby improving vehicle safety and management efficiency.

CN120934743APending Publication Date: 2025-11-11DEEPAL AUTOMOBILE NANJING RESEARCH INSTITUTE CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202410568322.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-09
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing technologies fail to comprehensively manage the entire lifecycle of automotive electronic control unit keys, resulting in lower vehicle security.

Method used

A method for managing keys in automotive electronic control units is provided, which identifies key types and manages them according to target key management actions within their lifecycle, including stages such as key generation, distribution, storage, import and export, use, update, backup and recovery, archiving, revocation and destruction, and is applicable to different types of keys.

Benefits of technology

It enables secure and proper management of the key throughout its entire lifecycle, improves vehicle security and key management efficiency, ensures that keys are not leaked under abnormal circumstances, and supports the traceability of key operation records.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934743A_ABST
    Figure CN120934743A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of automobile electronics, in particular to an automobile electronic control unit key management method and device, a vehicle and a storage medium, and the method comprises the steps: recognizing the key type of a target key of an automobile electronic control unit; a target key management action of the target key in the life cycle is determined according to the key type, and the target key management action comprises multiple stages of key generation, key distribution, key storage, key import and export, key use, key update, key backup and recovery, key archiving, key revocation and key destruction; and managing the target key in the life cycle based on the target key management action. Therefore, the problems that in the related technology, management of the full life cycle of the secret key cannot be achieved, the aspects involved in management are not comprehensive, and consequently the safety of an automobile is low are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automotive electronics technology, and more specifically to a method, device, vehicle, and storage medium for managing keys of automotive electronic control units. Background Technology

[0002] In the automotive industry, as vehicle functions become increasingly complex, the number of electronic control units (ECUs) and the number of keys required for ECUs are both increasing. Key management is closely related to processes such as ECU product development, mass production, vehicle operation, and vehicle scrapping.

[0003] Key management is a security strategy that guides technical issues related to the entire lifecycle of a key to defend against various potential threats, including key leakage, key invalidation, and unauthorized abuse. Key management involves multiple considerations, typically relying on hardware to provide acceleration and isolation, and employing a combination of software strategies.

[0004] Related technology 1, “CN107113167A”, discloses a key management device installed in a car, including encrypting a key using an encryption processing unit to generate an encryption key, generating a key using a key generation unit, storing the generated key using a key storage unit, and sending the encryption key to an on-board computer installed in the vehicle using a communication unit; Related technology 2, “CN112953939A”, discloses a key management method that uses an on-board gateway function module to distribute and update keys to an on-board electronic control unit, and the session key is saved for multiple uses after generation, or destroyed after the distribution or update of the key to the electronic control unit is completed; Related technology 3, “CN117725593A”, discloses a method for managing the secure boot key of an on-board ECU (Electronic Control Unit), which uses a hardware security module to derive a secure boot key through a preset algorithm and stores the secure boot key in an internal secure memory to calculate and verify the secure boot credential of the ECU security firmware.

[0005] However, the above methods only involve how to generate and use keys, but do not manage the entire lifecycle of keys. The management is not comprehensive, resulting in lower vehicle security. Summary of the Invention

[0006] One objective of this invention is to provide a key management method for automotive electronic control units, thereby solving the problem that related technologies cannot achieve full lifecycle management of keys, and the management is not comprehensive, resulting in low vehicle security. A second objective is to provide a key management device for automotive electronic control units. A third objective is to provide a vehicle. A fourth objective is to provide a computer-readable storage medium.

[0007] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0008] A method for managing keys in an automotive electronic control unit includes the following steps: identifying the key type of a target key for the automotive electronic control unit; determining the target key management actions within the lifecycle of the target key based on the key type, wherein the target key management actions include multiple stages such as key generation, key distribution, key storage, key import and export, key use, key update, key backup and recovery, key archiving, key revocation, and key destruction; and managing the target key within its lifecycle based on the target key management actions.

[0009] Based on the above technical means, the embodiments of the present invention can determine how to manage the target key throughout its life cycle according to the key type of the target key in the vehicle electronic control unit, and determine the corresponding key management action according to the key type. This can be applied to different keys in different electronic control units, realize secure and proper management of the key throughout its entire life cycle, improve the efficiency of key management, and further improve the security of the vehicle.

[0010] Furthermore, if the target key is no longer used or is attacked by the target threat, the target key will be revoked or destroyed.

[0011] Based on the above technical means, the embodiments of the present invention revoke or destroy the target key when the target key is no longer used or is attacked by the target threat, so as to ensure that the key will not be leaked and improve the security of the car.

[0012] Furthermore, key operation records can be traced based on key archiving.

[0013] Based on the above technical means, the embodiments of the present invention can trace key operation records based on key archiving, so that it is convenient for managers to query key operation records when they have query needs.

[0014] Furthermore, the key type includes at least one of master key, key encryption key, and business key. The target key management actions within the lifecycle of the target key are determined based on the key type, including: if the key type is a master key, the target key management actions include key generation, key distribution, key storage, key usage, key archiving, and key destruction; if the key type is a key encryption key, the target key management actions include key generation, key distribution, key storage, key import and export, key usage, key update, key backup and recovery, key archiving, key revocation, and key destruction; if the key type is a business key, the target key management actions include key generation, key distribution, key storage, key import and export, key usage, key update, key revocation, and key destruction.

[0015] Based on the above technical means, embodiments of the present invention can determine key management actions according to the type of key, so as to achieve targeted management of different types of keys.

[0016] Furthermore, if the key type is a master key, the target key is managed throughout its lifecycle based on target key management actions, including: in the key generation stage, using a physical noise source to generate a truly random sequence as the master key; in the key distribution stage, distributing the key to the target product; in the key storage stage, storing the plaintext of the master key in the target memory; in the key usage stage, using the master key stored in the target memory in an indexed manner; and in the key destruction stage, physically destroying the target memory.

[0017] Based on the above technical means, the embodiments of the present invention can manage the generation, distribution, storage, use and destruction stages of the key when the key type is the primary key.

[0018] Furthermore, if the key type is a key encryption key, the target key is managed throughout its lifecycle based on target key management actions, including: in the key generation stage, using a random number generator to generate a random number sequence as the key encryption key; in the key distribution stage, using the master key to encrypt the key encryption key and then publicly releasing it; in the key storage stage, storing the encrypted key encryption key in the target storage; in the key import and export stage, importing and exporting the key in key component form; in the key usage stage, using the encrypted key encryption key stored in the target storage in an indexed manner; in the key update stage, updating the encrypted key encryption key at preset intervals; in the key backup and recovery stage, backing up using multiple key component forms, with each key component backed up to a different storage area, and recovering the key after authorization verification; and in the key revocation and key destruction stage, overwriting the corresponding area of ​​the target storage where the encrypted key encryption key is stored.

[0019] Based on the above technical means, the embodiments of the present invention can manage the generation, distribution, storage, use, update, backup and recovery, revocation and destruction of keys when the key type is a key encryption key.

[0020] Furthermore, if the key type is a business key, the target key is managed throughout its lifecycle based on target key management actions, including: in the key generation stage, the business key is obtained by encrypting it with a random number from the master key; in the key distribution stage, the business key is encrypted with a key encryption key and then publicly released; in the key storage stage, the encrypted business key is stored in plaintext in the target storage; in the key import and export stage, the key is imported and exported in ciphertext; in the key usage stage, the encrypted business key stored in the target storage is used in an indexed manner; in the key update stage, the encrypted business key is updated at preset intervals; and in the key revocation and key destruction stage, the corresponding area of ​​the target storage where the encrypted business key is stored is overwritten.

[0021] Based on the above technical means, this embodiment of the invention manages the generation, distribution, storage, import and export, use, update, revocation and destruction of keys when the key type is a business key.

[0022] A key management device for an automotive electronic control unit includes: an identification module for identifying the key type of a target key for the automotive electronic control unit; a determination module for determining the target key management actions within the lifecycle of the target key based on the key type, wherein the target key management actions include multiple stages such as key generation, key distribution, key storage, key import and export, key use, key update, key backup and recovery, key archiving, key revocation, and key destruction; and a management module for managing the target key within its lifecycle based on the target key management actions.

[0023] Furthermore, if the target key is no longer used or is attacked by the target threat, the target key will be revoked or destroyed.

[0024] Furthermore, key operation records can be traced based on key archiving.

[0025] Furthermore, the key type includes at least one of a master key, a key encryption key, and a business key. The determining module is further configured to: if the key type is a master key, then the target key management actions include key generation, key distribution, key storage, key usage, key archiving, and key destruction; if the key type is a key encryption key, then the target key management actions include key generation, key distribution, key storage, key import and export, key usage, key update, key backup and recovery, key archiving, key revocation, and key destruction; if the key type is a business key, then the target key management actions include key generation, key distribution, key storage, key import and export, key usage, key update, key revocation, and key destruction.

[0026] Furthermore, if the key type is a master key, the management module is further used to: generate a true random sequence using a physical noise source as the master key during the key generation stage; distribute the key to the target product during the key distribution stage; store the plaintext of the master key in the target memory during the key storage stage; use the master key stored in the target memory in an indexed manner during the key usage stage; and physically destroy the target memory during the key destruction stage.

[0027] Furthermore, if the key type is a key encryption key, the management module is further used for: in the key generation stage, using a random number generator to generate a random number sequence as the key encryption key; in the key distribution stage, using the master key to encrypt the key encryption key and then publicly releasing it; in the key storage stage, storing the encrypted key encryption key in the target storage; in the key import and export stage, importing and exporting keys in key component form; in the key usage stage, using the encrypted key encryption key stored in the target storage in an indexed manner; in the key update stage, updating the encrypted key encryption key at preset intervals; in the key backup and recovery stage, backing up using multiple key component forms, with each key component backed up to a different storage area, and recovering the key after authorization verification; and in the key revocation and key destruction stage, overwriting the corresponding area of ​​the target storage where the encrypted key encryption key is stored.

[0028] Furthermore, if the key type is a business key, the management module is further used for: obtaining the business key by encrypting it with a random number of the master key during the key generation stage; publicly releasing the business key after encrypting it with a key encryption key during the key distribution stage; storing the encrypted business key in plaintext form in the target storage during the key storage stage; importing and exporting the key in ciphertext form during the key import and export stage; using the encrypted business key stored in the target storage in an indexed manner during the key usage stage; updating the encrypted business key at preset intervals during the key update stage; and overwriting the corresponding area of ​​the target storage where the encrypted business key is stored during the key revocation and key destruction stage.

[0029] A vehicle includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the automotive electronic control unit key management method as described in the above embodiments.

[0030] A computer-readable storage medium having a computer program stored thereon, which is executed by a processor to implement the automotive electronic control unit key management method as described in the above embodiments.

[0031] The beneficial effects of this invention are:

[0032] (1) The embodiments of the present invention can determine how to manage the target key during its life cycle based on the key type of the target key in the vehicle electronic control unit, and determine the corresponding key management action according to the key type. This can be applied to different keys of different electronic control units, realize secure and proper management of the key throughout its life cycle, improve the efficiency of key management, and further improve the safety of the vehicle.

[0033] (2) In this embodiment of the invention, when the target key is no longer used or is attacked by the target threat, the target key is revoked or destroyed to ensure that the key is not leaked and improve the security of the car.

[0034] (3) The embodiments of the present invention can trace key operation records based on key archiving so that key operation records can be easily queried when managers have query needs.

[0035] (4) The embodiments of the present invention can determine the key management action according to the key type, so as to achieve targeted management of different types of keys.

[0036] (5) In this embodiment of the invention, when the key type is the main key, the generation, distribution, storage, use and destruction of the key can be managed.

[0037] (6) In this embodiment of the invention, when the key type is a key encryption key, the key can be managed in stages of generation, distribution, storage, use, update, backup and recovery, revocation and destruction.

[0038] (7) In this embodiment of the invention, when the key type is a business key, the key is managed in stages of generation, distribution, storage, import and export, use, update, revocation and destruction.

[0039] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description

[0040] Figure 1 This is a flowchart of the automotive electronic control unit key management method of the present invention;

[0041] Figure 2 This is a schematic diagram illustrating the lifecycle of the key management system for the automotive electronic control unit according to the present invention.

[0042] Figure 3 This is a schematic diagram of the master key management method of the present invention;

[0043] Figure 4 This is a schematic diagram of the key encryption key management method of the present invention;

[0044] Figure 5This is a schematic diagram of the business key management method of the present invention;

[0045] Figure 6 This is a schematic diagram of the automotive electronic control unit key management device of the present invention;

[0046] Figure 7 This is a schematic diagram of the vehicle structure of the present invention. Detailed Implementation

[0047] The embodiments of the present invention will be described below with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the scope of protection of the present invention.

[0048] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0049] With the rapid development and application of intelligent connected vehicles, the possibility and scenarios of vehicle, or more specifically, ECU, being attacked by hackers are increasing daily. Without constraints and requirements for automotive information security, the shadow of hacking will constantly loom over drivers and passengers, posing potential threats to their privacy, data security, and even their lives. To prevent and mitigate malicious attacks on vehicles, the use of cryptography to protect sensitive data has received increasing attention and importance. For example, in the widely used Automotive Open System Architecture (AUTOSAR), the SecOC module (Secure Onboard Communication) is designed for secure communication between in-vehicle electronic control units. Drawing on mature technologies from the IT (Information Technology) field, the MKA module (MACsec Key Agreement protocol) is used to protect data at the Ethernet MAC (Medium Access Control) layer, and so on.

[0050] The aforementioned security mechanisms all originate from cryptographic algorithms. However, as is well known, cryptographic algorithms are public. The security of the entire cryptographic system does not depend on the protection of the cryptographic algorithm or the encryption device, but rather on the security of the key. This is because, with the exception of some hash algorithms, most cryptographic computations rely on the key. When using public algorithms, the key is a variable part of the cryptographic system. If a user chooses to develop their own cryptographic algorithm, the difficulty is obviously much greater than using a mature public algorithm combined with different keys. Moreover, the difficulty of finding a new path outside of these numerous public algorithms is self-evident. Therefore, the security of a cryptographic mechanism depends more on the secure protection and management of the key; key management provides a crucial foundation for cryptographic technology.

[0051] On the other hand, there are generally two methods to attack cryptographic mechanisms: one is to directly crack the cryptographic algorithm through decryption; the other is to steal the key. The cost, or difficulty, of stealing the key is far lower than that of cracking the cryptographic algorithm. It can be obtained by planting a Trojan horse or backdoor in the target system, or by using social engineering attacks.

[0052] Therefore, it can be said that cryptographic mechanisms are based on the confidentiality of keys; all secrets reside within the keys. In the automotive industry, as vehicle functions become increasingly complex, the number of electronic control units (ECUs) and the number of keys required for these ECUs are both increasing. Key management is closely related to ECU product development, mass production, vehicle operation, and vehicle scrapping. In conclusion, secure, efficient, and flexible management of a vast number of keys is essential.

[0053] In addition to the related technologies 1-3 mentioned in the background technology above, related technologies 4 and 5 also provide key security management methods. Related technology 4 "CN113613214A" discloses an in-vehicle message authentication key management method, which is a key management method between electronic control units in the vehicle that need to send and receive message authentication messages. This method configures two-level keys: a master key and a communication key. The master key is securely written with the same content before the electronic control unit goes offline, so that the master node can generate the communication key and the slave node can verify the communication key to complete the pairing. Related technology 5 "CN109728899A" discloses a secure management method for authentication keys between the vehicle controller and the request controller, which only involves the generation, transmission and storage of keys.

[0054] However, the problem with related technical solutions is that they do not consider the entire lifecycle management of keys. They only address the questions of "where the key comes from" or "how it is used during normal operation," without further comprehensively addressing issues such as "what happens if the key is damaged," "whether the operation records are traceable," and "where it ultimately goes." Because automobiles are high-value, durable goods, drivers and passengers have close and continuous interactions and connections with them during actual driving. Therefore, key management of the vehicle's "brain," the electronic control unit, must be comprehensively planned and implemented from beginning to end. Therefore, this invention provides a more comprehensive and practical key management method to help improve vehicle security.

[0055] Specifically, Figure 1 This is a flowchart illustrating a method for managing keys in an automotive electronic control unit, as provided in an embodiment of this application.

[0056] like Figure 1 As shown, the automotive electronic control unit key management method includes the following steps:

[0057] In step S101, the key type of the target key of the vehicle electronic control unit is identified.

[0058] The key type includes at least one of a master key, a key encryption key, and a business key.

[0059] The master key is the root of trust in a key management system. Applications include secure vehicle startup and security upgrades. It has the highest level of security and the longest lifespan. Besides being used for cryptographic algorithm calculations on plaintext data, it is also used to encrypt and protect other keys. The encryption key, also known as a secondary key, secondary master key, or auxiliary key, is used to encrypt and decrypt business keys. It can be used to build a secure channel for business key exchange and distribution, as seen in applications such as generating authentication keys for secure communication messages. The business key, also known as a session key, working key, or data encryption key, is used to encrypt actual plaintext data, as seen in applications such as authentication keys for secure vehicle communication messages.

[0060] It is understood that embodiments of the present invention can identify the key type of the target key of the automotive electronic control unit so as to determine how to manage the key based on the key type.

[0061] In step S102, the target key management action within the lifecycle of the target key is determined according to the key type.

[0062] The target key management actions include multiple stages such as key generation, key distribution, key storage, key import and export, key usage, key update, key backup and recovery, key archiving, key revocation, and key destruction.

[0063] It is understood that since the lifecycle management of different keys is different, the embodiments of the present invention can determine the target key management action within the lifecycle of the key according to the key type, so as to achieve precise management of the target key.

[0064] It should be noted that the management of the target key is essentially the management of the key's lifecycle. This embodiment of the invention covers the entire lifecycle of the key. After generation, the key can be distributed to other electronic control units as needed, and then stored in secure areas for later use. It can also be exported as needed. When the security of a key still in use is threatened, or when the key is no longer needed, it is revoked or destroyed. Figure 2 As shown.

[0065] Specifically, key generation: keys can be generated directly by random numbers or indirectly, such as by deriving from passwords, deriving from key derivation functions, and so on.

[0066] Key distribution: Keys can be distributed automatically online or offline manually, by dedicated key distribution personnel and properly installed by dedicated installation personnel, etc.

[0067] Key storage: Keys can be stored using various storage devices such as cryptographic products or external media. The storage format can be plaintext, ciphertext, or component form. Plaintext means the key is stored in plaintext form; ciphertext means the key is stored after encryption; and component form means the key is stored in components. That is, key components are not the key itself, but rather partial parameters used to generate the key. The true key can only be generated when all key components work together; if only one or some components are known, the other components and the true key cannot be derived.

[0068] Key Import and Export: Keys can be imported or exported in ciphertext or component form, etc. Ciphertext and component forms are described in the previous sections and will not be repeated here.

[0069] Key usage: Key usage refers to the use of a key to execute cryptographic algorithms in a secure environment. This can be done in a Hardware Security Module (HSM), or by creating other secure zones in an electronic control unit, etc.

[0070] Key revocation and key destruction: Key revocation or destruction refers to erasing all storage forms and related information of the key, making it impossible to recover and reuse the key. Proper methods should be used to clear the memory, such as writing values ​​to overwrite the corresponding area, or physically destroying it, etc.

[0071] Key Update: When a key's expiration date arrives, or if a key leak is suspected, or if a communication member requests a key update, the key is updated, and the original key is no longer used. It's understandable that even with strong cryptographic algorithms, the likelihood of a key being cracked increases as an attacker intercepts enough ciphertext; therefore, key updates are meaningful.

[0072] Key backup: Backing up keys further ensures the security of keys and encrypted data. If a key is destroyed, the backup key can be used to recover the original key or encrypted data, preventing loss. This is especially important for critical data, as key loss can have catastrophic consequences. Key backups can be performed by yourself, by a third party, or by a key escrow service provider in the form of key components, etc.

[0073] Key archiving: When a key is no longer in use and the protected object is within its validity period, the key can be archived so that it can be retrieved and used under certain special circumstances. These special circumstances may include when it is necessary to decrypt and preserve historical content and data, or when it is necessary to conduct key-related security audits (audit content may include the personnel, time, and content of key management and operation), and so on.

[0074] In this embodiment of the invention, if the target key is no longer used or is attacked by a target threat, the target key is revoked or destroyed.

[0075] Revoking or destroying a target key means clearing all storage formats and related information of the target key, making it impossible to recover and reuse the key.

[0076] Understandably, since keys can prevent malicious attackers from using them to deceive or leak information by intercepting or tampering with information, this embodiment of the invention will revoke or destroy the target key when it is no longer in use or is under attack by a target threat, in order to prevent incomplete revocation or destruction from affecting vehicle safety.

[0077] In this embodiment of the invention, key operation records are traced based on key archiving.

[0078] It is understood that embodiments of the present invention can trace key operation records based on key archiving so that key-related security audits can be carried out subsequently (audit content may include the personnel, time, and content of key management and operation).

[0079] In this embodiment of the invention, the target key management actions within the lifecycle of the target key are determined according to the key type, including: if the key type is a primary key, the target key management actions include key generation, key distribution, key storage, key usage, key archiving, and key destruction; if the key type is a key encryption key, the target key management actions include key generation, key distribution, key storage, key import and export, key usage, key update, key backup and recovery, key archiving, key revocation, and key destruction; if the key type is a business key, the target key management actions include key generation, key distribution, key storage, key import and export, key usage, key update, key revocation, and key destruction.

[0080] It is understandable that different types of keys require different key management actions throughout their lifecycle, as follows:

[0081] If the key type is the primary key, then the target key management actions include: key generation, key distribution, key storage, key usage, key archiving, and key destruction.

[0082] If the key type is a key encryption key, then the target key management actions include: key generation, key distribution, key storage, key import and export, key usage, key update, key backup and recovery, key archiving, key revocation, and key destruction.

[0083] If the key type is a business key, the target key management actions include: key generation, key distribution, key storage, key import and export, key usage, key update, key revocation, and key destruction.

[0084] In step S103, the target key is managed throughout its lifecycle based on the target key management action.

[0085] It is understood that embodiments of the present invention can manage the target key throughout its lifecycle based on the target key management action, so as to achieve secure and proper management of the key and realize full lifecycle management of the key, thereby improving the safety of the vehicle.

[0086] In this embodiment of the invention, if the key type is a master key, the target key is managed within its lifecycle based on target key management actions, including: in the key generation stage, using a physical noise source to generate a truly random sequence as the master key; in the key distribution stage, distributing the key to the target product; in the key storage stage, storing the plaintext of the master key in the target memory; in the key usage stage, using the master key stored in the target memory in an indexed manner; and in the key destruction stage, physically destroying the target memory.

[0087] The target memory can be an HSM memory, and there are no specific restrictions on it.

[0088] It is understood that, in embodiments of the present invention, when the key type is the primary key, the target key is managed throughout its lifecycle. Figure 3 The management method shown is as follows:

[0089] 1. During the key generation phase, a truly random sequence generated using physical noise sources is chosen as the master key;

[0090] 2. During the key distribution phase, choose to distribute the keys to other products manually;

[0091] 3. During the key storage phase, since the master key is the highest level key and there is no higher level key to encrypt and store it, the master key can only be stored in plaintext. At the same time, a highly secure physical and logical storage device, HSM, is selected for storage.

[0092] 4. During the key usage phase, only the type of key required for cryptographic algorithm computation and its index in the HSM are provided. The actual computation is performed in the HSM, and the plaintext of the key is not visible to the outside world.

[0093] 5. During the key destruction phase, the memory is physically destroyed after the vehicle is scrapped.

[0094] In this embodiment of the invention, if the key type is a key encryption key, the target key is managed throughout its lifecycle based on target key management actions, including: in the key generation stage, using a random number generator to generate a random number sequence as the key encryption key; in the key distribution stage, using the master key to encrypt the key encryption key and then publicly releasing it; in the key storage stage, storing the encrypted key encryption key in the target memory; in the key import and export stage, importing and exporting the key in key component form; in the key usage stage, using the encrypted key encryption key stored in the target memory in an indexed manner; in the key update stage, updating the encrypted key encryption key at preset intervals; in the key backup and recovery stage, backing up using multiple key component forms, with each key component backed up to a different storage area, and recovering the key after authorization verification; and in the key revocation and key destruction stage, covering the corresponding area of ​​the target memory where the encrypted key encryption key is stored.

[0095] The preset duration can be set according to specific circumstances, such as 180 days or 200 days, without any specific limitation.

[0096] It is understood that, in embodiments of the present invention, when the key type is a key encryption key, the target key is managed throughout its lifecycle, in order to... Figure 4 The management method shown is as follows:

[0097] 1. During the key generation phase, a random number generator is selected to generate a random number sequence;

[0098] 2. During the key distribution phase, the master key is used to encrypt and protect the key, and then it is distributed using a public channel.

[0099] 3. During the key storage phase, the master key is selected to encrypt and protect it, and it is stored in the HSM in ciphertext form;

[0100] 4. During the key usage phase, only the type of key required for cryptographic algorithm computation and its index in the HSM are provided. The actual computation is performed in the HSM, and the plaintext of the key is not visible to the outside world.

[0101] 5. During the key update phase, select to set the validity period to 180 days. The security requirements for reinstallation are the same as for the initial installation, and the business keys protected by it are also updated.

[0102] 6. During the key backup and recovery phase, use multiple key components for backup. Each key component is backed up to a different storage area, and key recovery requires authorized verification.

[0103] 7. During the key revocation and destruction phase, choose to overwrite the corresponding area with a written value.

[0104] In this embodiment of the invention, if the key type is a business key, the target key is managed throughout its lifecycle based on target key management actions, including: in the key generation stage, the business key is obtained by encrypting it with a master key random number; in the key distribution stage, the business key is publicly released after being encrypted with a key encryption key; in the key storage stage, the encrypted business key is stored in the target memory in plaintext form; in the key import and export stage, the key is imported and exported in ciphertext form; in the key usage stage, the encrypted business key stored in the target memory is used in an indexed manner; in the key update stage, the encrypted business key is updated at preset intervals; and in the key revocation and key destruction stage, the corresponding area of ​​the target memory storing the encrypted business key is overwritten.

[0105] It is understood that, in embodiments of the present invention, when the key type is a business key, the target key is managed throughout its lifecycle, in order to... Figure 5 The management method shown is as follows:

[0106] 1. During the generation phase, a string of random numbers is encrypted using the aforementioned master key;

[0107] 2. During the distribution phase, select to encrypt and protect it using a key encryption key, and then distribute it using a public channel;

[0108] 3. During the storage phase, choose to store the data in plaintext format in the HSM;

[0109] 4. During the import and export stages, the data is processed in encrypted form;

[0110] 5. During the usage phase, only the type of key required for cryptographic algorithm calculation and its index in the HSM are provided. The actual calculation is performed in the HSM, and the plaintext of the key is not visible to the outside world.

[0111] 6. During the update phase, choose to set a validity period of 30 days or adopt the "one-time password" method according to the specific application business. The security requirements for reinstallation are the same as those for the initial installation.

[0112] 7. During the undo and destroy phase, select to write overwrite values ​​to the corresponding area.

[0113] In summary, this invention provides a management method covering the entire lifecycle of keys, including generation, distribution, storage, import and export, use, update, backup and recovery, archiving, revocation, and destruction, thus achieving effective key management. This method not only addresses the widely discussed questions of "where do keys come from" and "how are they used during normal operation" through key generation, distribution, storage, import and export, use, and update, but also solves the problem of "what to do if keys are damaged" through key backup and recovery, the problem of "whether key operation records are traceable" through key archiving, and the problem of "where do keys ultimately go" through key revocation and destruction. This ensures the key usage needs of vehicles and cryptographic algorithms in abnormal situations while guaranteeing the traceability of key management and operations, significantly improving the security, reliability, and stability of vehicles and cryptographic algorithms. Furthermore, the method can be appropriately tailored to specific application scenarios and security requirements, simplifying key management logic and enabling efficient management of different keys for different electronic control units, balancing security and convenience, and improving work efficiency.

[0114] The automotive electronic control unit key management method proposed in this embodiment of the invention can determine how to manage the target key throughout its lifecycle based on the key type of the target key in the automotive electronic control unit, and determine the corresponding key management action according to the key type. It can be applied to different keys of different electronic control units, realize secure and proper management of the key throughout its entire lifecycle, improve the efficiency of key management, and further improve the security of the vehicle.

[0115] Next, the key management device for automotive electronic control units according to an embodiment of the present invention is described with reference to the accompanying drawings.

[0116] Figure 6 This is a block diagram of the key management device for the automotive electronic control unit according to an embodiment of the present invention.

[0117] like Figure 6 As shown, the automotive electronic control unit key management device 10 includes: an identification module 100, a determination module 200, and a management module 300.

[0118] The identification module 100 is used to identify the key type of the target key of the automotive electronic control unit; the determination module 200 is used to determine the target key management actions within the life cycle of the target key based on the key type, wherein the target key management actions include multiple stages such as key generation, key distribution, key storage, key import and export, key use, key update, key backup and recovery, key archiving, key revocation and key destruction; and the management module 300 is used to manage the target key within its life cycle based on the target key management actions.

[0119] In this embodiment of the invention, if the target key is no longer used or is attacked by a target threat, the target key is revoked or destroyed.

[0120] In this embodiment of the invention, key operation records are traced based on key archiving.

[0121] In this embodiment of the invention, the key type includes at least one of a master key, a key encryption key, and a business key. The determining module 200 is further configured to: if the key type is a master key, then the target key management actions include key generation, key distribution, key storage, key usage, key archiving, and key destruction; if the key type is a key encryption key, then the target key management actions include key generation, key distribution, key storage, key import and export, key usage, key update, key backup and recovery, key archiving, key revocation, and key destruction; if the key type is a business key, then the target key management actions include key generation, key distribution, key storage, key import and export, key usage, key update, key revocation, and key destruction.

[0122] In this embodiment of the invention, if the key type is a master key, the management module 300 is further configured to: generate a true random sequence using a physical noise source as the master key during the key generation stage; distribute the key to the target product during the key distribution stage; store the plaintext of the master key in the target memory during the key storage stage; use the master key stored in the target memory in an indexed manner during the key usage stage; and physically destroy the target memory during the key destruction stage.

[0123] In this embodiment of the invention, if the key type is a key encryption key, the management module 300 is further configured to: in the key generation stage, use a random number generator to generate a random number sequence as the key encryption key; in the key distribution stage, use the master key to encrypt the key encryption key and then publicly release it; in the key storage stage, store the encrypted key encryption key in the target memory; in the key import and export stage, import and export the key in key component form; in the key usage stage, use the encrypted key encryption key stored in the target memory in an indexed manner; in the key update stage, update the encrypted key encryption key at preset intervals; in the key backup and recovery stage, back up the key using multiple key component forms, with each key component backed up to a different storage area, and recover the key after authorization verification; in the key revocation and key destruction stage, cover the corresponding area of ​​the target memory where the encrypted key encryption key is stored.

[0124] In this embodiment of the invention, if the key type is a business key, the management module 300 is further configured to: in the key generation stage, encrypt the business key using a master key random number to obtain the business key; in the key distribution stage, encrypt the business key using a key encryption key and then publicly release it; in the key storage stage, store the encrypted business key in plaintext form in the target memory; in the key import and export stage, import and export the key in ciphertext form; in the key usage stage, use the encrypted business key stored in the target memory in an indexed manner; in the key update stage, update the encrypted business key at preset intervals; and in the key revocation and key destruction stage, cover the corresponding area of ​​the target memory where the encrypted business key is stored.

[0125] It should be noted that the foregoing explanation of the embodiment of the automotive electronic control unit key management method also applies to the automotive electronic control unit key management device of this embodiment, and will not be repeated here.

[0126] The automotive electronic control unit key management device proposed in this embodiment of the invention can determine how to manage the target key throughout its lifecycle based on the key type of the target key in the automotive electronic control unit, and determine the corresponding key management action based on the key type. It can be applied to different keys of different electronic control units, realize secure and proper management of the key throughout its entire lifecycle, improve the efficiency of key management, and further improve the security of the vehicle.

[0127] Figure 7 This is a schematic diagram of a vehicle provided in an embodiment of the present invention. The vehicle may include:

[0128] The memory 701, the processor 702, and the computer program stored on the memory 701 and executable on the processor 702.

[0129] When the processor 702 executes the program, it implements the automotive electronic control unit key management method provided in the above embodiments.

[0130] Furthermore, the vehicle also includes:

[0131] Communication interface 703 is used for communication between memory 701 and processor 702.

[0132] The memory 701 is used to store computer programs that can run on the processor 702.

[0133] The memory 701 may include high-speed RAM (Random Access Memory) memory, and may also include non-volatile memory, such as at least one disk storage.

[0134] If the memory 701, processor 702, and communication interface 703 are implemented independently, then the communication interface 703, memory 701, and processor 702 can be interconnected via a bus to complete communication between them. The bus can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 7 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0135] Optionally, in a specific implementation, if the memory 701, processor 702, and communication interface 703 are integrated on a single chip, then the memory 701, processor 702, and communication interface 703 can communicate with each other through an internal interface.

[0136] The processor 702 may be a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement embodiments of the present invention.

[0137] This invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described automotive electronic control unit key management method.

[0138] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0139] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "N" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0140] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or N executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.

[0141] It should be understood that the various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, the N steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (FPGAs), field-programmable gate arrays (FPGAs), etc.

[0142] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0143] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.

Claims

1. A method for key management of an automotive electronic control unit, characterized in that, Includes the following steps: The key type for identifying the target key of an automotive electronic control unit; The target key management actions for the target key during its lifecycle are determined based on the key type. The target key management actions include multiple stages such as key generation, key distribution, key storage, key import and export, key usage, key update, key backup and recovery, key archiving, key revocation, and key destruction. The target key is managed throughout its lifecycle based on the target key management action.

2. The method for managing the key of an automotive electronic control unit according to claim 1, characterized in that, If the target key is no longer used or is attacked by a target threat, the target key shall be revoked or destroyed.

3. The method for managing automotive electronic control unit keys according to claim 1, characterized in that, Based on the key archive, traceable key operation records are maintained.

4. The method for managing the key of an automotive electronic control unit according to claim 1, characterized in that, The key type includes at least one of a master key, a key encryption key, and a business key. The step of determining the target key management action within its lifecycle based on the key type includes: If the key type is the master key, then the target key management actions include key generation, key distribution, key storage, key usage, key archiving, and key destruction. If the key type is the key encryption key, then the target key management actions include key generation, key distribution, key storage, key import and export, key usage, key update, key backup and recovery, key archiving, key revocation and key destruction; If the key type is the business key, then the target key management actions include key generation, key distribution, key storage, key import and export, key usage, key update, key revocation, and key destruction.

5. The method for managing the key of an automotive electronic control unit according to claim 4, characterized in that, If the key type is the master key, the management of the target key throughout its lifecycle based on the target key management action includes: During the key generation phase, a truly random sequence is generated using physical noise sources as the master key; During the key distribution phase, the key is distributed to the target product; During the key storage phase, the plaintext of the master key is stored in the target memory; During the key usage phase, the master key stored in the target memory is used in an indexed manner; During the key destruction phase, the target memory is physically destroyed.

6. The method for managing the key of an automotive electronic control unit according to claim 4, characterized in that, If the key type is the key encryption key, the management of the target key throughout its lifecycle based on the target key management action includes: During the key generation phase, a random number generator is used to generate a random number sequence as the encryption key. During the key distribution phase, the key encryption key is encrypted using the master key and then publicly released. During the key storage phase, the encrypted key is stored in the target memory. During the key import and export phase, keys are imported and exported in the form of key components. During the key usage phase, the encrypted key stored in the target memory is used in an indexed manner to encrypt the key; During the key update phase, the encrypted key is updated at preset intervals. During the key backup and recovery phase, multiple key components are used for backup, with each key component backed up to a different storage area, and the key is recovered after authorization verification. During the key revocation and key destruction phase, the corresponding area of ​​the target memory storing the encrypted key is covered.

7. The method for managing the key of an automotive electronic control unit according to claim 4, characterized in that, If the key type is the business key, the management of the target key throughout its lifecycle based on the target key management action includes: During the key generation phase, the business key is obtained by encrypting the random number of the master key. During the key distribution phase, the business key is encrypted using the key encryption key and then publicly released. During the key storage phase, the encrypted business key is stored in plaintext form in the target memory. During the key import and export phase, the key is imported and exported in encrypted form. During the key usage phase, the encrypted business key stored in the target memory is used in an indexed manner; During the key update phase, the encrypted business key is updated at preset intervals. During the key revocation and key destruction phase, the corresponding area of ​​the target memory storing the encrypted business key is covered.

8. A key management device for an automotive electronic control unit, characterized in that, include: The identification module is used to identify the key type of the target key of the automotive electronic control unit; The determination module is used to determine the target key management actions of the target key during its lifecycle based on the key type. The target key management actions include multiple stages such as key generation, key distribution, key storage, key import and export, key usage, key update, key backup and recovery, key archiving, key revocation, and key destruction. The management module is used to manage the target key throughout its lifecycle based on the target key management actions.

9. A vehicle, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, the processor executing the program to implement the automotive electronic control unit key management method as described in any one of claims 1-6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, The program is executed by the processor to implement the automotive electronic control unit key management method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Management device, key generating device, vehicle, maintenance tool, management system, management method, and computer program

    CN107113167A

  • A pure electric vehicle authentication key security management method and system

    CN109728899A

  • Secret key management method

    CN112953939A

  • In-vehicle message authentication key management method and readable storage medium

    CN113613214A

  • Management method and device of vehicle-mounted ECU (Electronic Control Unit) safe start-up key and electronic equipment

    CN117725593A