A method and system for identifying tampering of program data

By obtaining the characteristic parameter values and distinction numbers in the ECU, and comparing them with the network-side device to identify whether the ECU data has been tampered, the problem of difficult to accurately identify the ECU program data tampering is solved, and a high-accuracy recognition effect is achieved.

CN113886896BActive Publication Date: 2025-07-18WEICHAI POWER CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111288020.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-02
Publication Date
2025-07-18
Estimated Expiration
2041-11-02

AI Technical Summary

Technical Problem

In the prior art, electronic control unit (ECU) programs and data tampering are difficult to accurately identify, resulting in the security of equipment use being affected, and there is a risk of missed inspection in manual verification.

Method used

By obtaining the characteristic parameter values and distinction numbers in the ECU, using the preset encryption algorithm to calculate and compare with the historical characteristic parameter values in the network side equipment, we can judge whether the ECU data has been tampered with, establish a correspondence between the distinction number and the characteristic parameter values, and avoid missed detection by manual interpretation.

Benefits of technology

It realizes accurate identification of ECU program data, improves recognition accuracy, avoids missed detection caused by manual interpretation, refines the type of tampering of the identification program data, and improves the accuracy of the identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113886896B_ABST
    Figure CN113886896B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a method and a system for identifying that program data has been tampered with. The method includes: when the electronic control unit is not in the after-sales upgrade mode, obtaining the characteristic parameter value and the difference number stored in the electronic control unit, searching in the network-side device for the latest characteristic parameter value corresponding to the difference number, determining whether the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit. If they are not consistent, then determining whether at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit. If any one of the other characteristic parameter values is not consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has been tampered with. The present invention realizes the accurate identification of whether the program data in the vehicle-mounted electronic control unit has been tampered with.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing, and in particular to a method and a system for identifying tampering of program data. Background Art

[0002] The programs and data in an Electronic Control Unit (ECU) are usually solidified and written according to the configuration requirements in the customer order when the ECU comes off the production line. During the operation of the device controlled by the ECU, the ECU will control the device according to the above programs and data to ensure the safe operation of the device.

[0003] However, currently, tampering with the programs and data in the ECU occurs frequently. For example, by changing the ECU program or data to increase the output power of the device and modify the system configuration of the device, etc. The occurrence of such situations causes the ECU to be unable to normally control the device, seriously affecting the use safety of the device. The prior art usually adopts the method of manual verification, and the staff reads and judges each item of the programs or data in the ECU one by one. Due to the large number of programs and data in the ECU, it is inevitable that missed inspections will occur during manual verification, and there are relatively large potential safety hazards. Therefore, how to accurately identify whether the program data in the ECU has been tampered with has become an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0004] The purpose of the embodiments of the present invention is to provide a method and a system for identifying tampering of program data to accurately identify whether the program data in the vehicle-mounted electronic control unit has been tampered with. The specific technical solutions are as follows:

[0005] A method for identifying tampering of program data, the method includes:

[0006] When the electronic control unit is not in the after-sales upgrade mode, obtain the characteristic parameter value and the difference number stored in the electronic control unit, where the characteristic parameter value is calculated by the electronic control unit using a preset encryption algorithm for target data, the characteristic parameter value is stored in the electronic control unit at a first moment, the difference number is the unique identifier of the control object of the electronic control unit, the characteristic parameter value and the difference number have a corresponding relationship, and the target data includes: the code data in the program code area of the electronic control unit and / or the data in the data area.

[0007] Search for the latest characteristic parameter value corresponding to the difference number in the network-side device, where the time when the latest characteristic parameter value is uploaded to the network-side device is later than the time when other characteristic parameter values corresponding to the difference number are uploaded to the network-side device, and the other characteristic parameter values are the characteristic parameter values corresponding to the difference number stored in the network-side device except the latest characteristic parameter value.

[0008] Determine whether the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit. If not, determine whether at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit. If none of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit, determine that the target data of the electronic control unit has been tampered with.

[0009] Optionally, the method further includes:

[0010] If the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit, determine that the target data of the electronic control unit has not been tampered with.

[0011] Optionally, the method further includes:

[0012] If at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit, determine that the target data of the electronic control unit is incorrect.

[0013] Optionally, the method further includes:

[0014] When the electronic control unit is in the offline mode, control the electronic control unit to calculate according to the target data by using the preset encryption algorithm to obtain the characteristic parameter value at the time when the electronic control unit is in the offline mode, establish the correspondence between the characteristic parameter value at the offline mode time and the difference number, and upload the difference number and the characteristic parameter value at the offline mode time to the network-side device for storage.

[0015] Optionally, the method further includes:

[0016] When the electronic control unit is in the after-sales upgrade mode, upgrade the target data in the electronic control unit. After the upgrade is completed, control the electronic control unit to use the preset encryption algorithm to calculate based on the upgraded target data to obtain an upgraded characteristic parameter value, establish a correspondence between the upgraded characteristic parameter value and the difference number, and upload the difference number and the upgraded characteristic parameter value to the network-side device for storage.

[0017] A system for identifying tampering of program data, the system comprising:

[0018] A first data acquisition module, configured to acquire a characteristic parameter value and a difference number stored in the electronic control unit when the electronic control unit is not in the after-sales upgrade mode, where the characteristic parameter value is obtained by the electronic control unit calculating target data using a preset encryption algorithm, the characteristic parameter value is stored in the electronic control unit at a first moment, the difference number is a unique identifier of a control object of the electronic control unit, the characteristic parameter value and the difference number have a correspondence, and the target data includes: code data in a program code area and / or data in a data area in the electronic control unit.

[0019] A data calling module, configured to search in the network-side device for the latest characteristic parameter value corresponding to the difference number, where the moment when the latest characteristic parameter value is uploaded to the network-side device is later than the moment when other characteristic parameter values corresponding to the difference number are uploaded to the network-side device, and the other characteristic parameter values are the characteristic parameter values stored in the network-side device corresponding to the difference number except the latest characteristic parameter value.

[0020] A data comparison module, configured to determine whether the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit. If not, determine whether at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit. If none of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit, determine that the target data of the electronic control unit has been tampered with.

[0021] Optionally, the data comparison module is further configured to:

[0022] If the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit, determine that the target data of the electronic control unit has not been tampered with.

[0023] Optionally, the data comparison module is further configured to:

[0024] If at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit is incorrect.

[0025] Optionally, the system further includes:

[0026] A data upgrade module, which is used to upgrade the target data in the electronic control unit when the electronic control unit is in the after-sales upgrade mode. After the upgrade is completed, it controls the electronic control unit to use the preset encryption algorithm to calculate based on the upgraded target data to obtain the upgraded characteristic parameter value, establish the corresponding relationship between the upgraded characteristic parameter value and the difference number, and upload the difference number and the upgraded characteristic parameter value to the network-side device for storage.

[0027] Optionally, the system further includes:

[0028] A second data acquisition module, which is used to control the electronic control unit to use the preset encryption algorithm to calculate based on the target data when the electronic control unit is in the offline mode, obtain the characteristic parameter value of the electronic control unit at the moment of the offline mode, establish the corresponding relationship between the characteristic parameter value at the moment of the offline mode and the difference number, and upload the difference number and the characteristic parameter value at the moment of the offline mode to the network-side device for storage.

[0029] A system for identifying that program data has been tampered with, the system includes: an electronic control unit, a first network-side device, and a service tool terminal,

[0030] When the electronic control unit is not in the after-sales upgrade mode, the service tool terminal acquires the characteristic parameter value and the difference number stored in the electronic control unit, and sends the characteristic parameter value and the difference number to the first network-side device.

[0031] The first network-side device acquires the difference number sent by the service tool terminal. The first network-side device searches for the latest characteristic parameter value corresponding to the difference number, where the time when the latest characteristic parameter value is uploaded to the first network-side device is later than the time when other characteristic parameter values corresponding to the difference number are uploaded to the first network-side device, and the other characteristic parameter values are the characteristic parameter values corresponding to the difference number stored in the first network-side device except the latest characteristic parameter value.

[0032] The first network-side device determines whether the latest feature parameter value is consistent with the feature parameter value stored in the electronic control unit. If not, it determines whether at least one of the other feature parameter values is consistent with the feature parameter value stored in the electronic control unit. If any of the other feature parameter values is not consistent with the feature parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has been tampered with.

[0033] Optionally, the system further includes: a second network-side device.

[0034] When the first network-side device determines that the target data of the electronic control unit has been tampered with, it sends the recognition result that the target data has been tampered with to the service tool terminal.

[0035] The service tool terminal sends the recognition result to the second network-side device. The second network-side device calls the disposal method matching the recognition result in the preset database according to the recognition result, and sends the disposal method to the service tool terminal.

[0036] Optionally, the first network-side device is further configured to:

[0037] When it is determined that the latest feature parameter value is consistent with the feature parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has not been tampered with.

[0038] Optionally, the first network-side device is further configured to:

[0039] When it is determined that at least one of the other feature parameter values is consistent with the feature parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit is incorrect.

[0040] Optionally, the service tool terminal is further configured to:

[0041] When the electronic control unit is in the offline mode, it controls the electronic control unit to use the preset encryption algorithm to calculate according to the target data, obtain the feature parameter value at the moment when the electronic control unit is in the offline mode, establish the corresponding relationship between the feature parameter value at the offline mode moment and the difference number, and upload the difference number and the feature parameter value at the offline mode moment to the network-side device for storage.

[0042] Optionally, the service tool terminal is further configured to:

[0043] When the electronic control unit is in the after-sales upgrade mode, upgrade the target data in the electronic control unit. After the upgrade is completed, control the electronic control unit to use the preset encryption algorithm to calculate based on the upgraded target data to obtain the upgraded characteristic parameter value, establish the corresponding relationship between the upgraded characteristic parameter value and the difference number, and upload the difference number and the upgraded characteristic parameter value to the network-side device for storage.

[0044] A method and system for identifying whether program data is tampered with provided by an embodiment of the present invention. The present invention introduces a characteristic parameter value to reflect whether the program data in the electronic control unit is tampered with. By comparing the characteristic parameter value stored in the electronic control unit at the current moment with the characteristic parameter value at the historical moment stored in the network-side device, it is determined whether the program data in the electronic control unit at the current moment is tampered with, so that the determination result of the present invention is more accurate compared with the manual line-by-line judgment of the prior art. The present invention also establishes the corresponding relationship between the difference number and the characteristic parameter value, so that during the identification process, by looking up the difference number, all the characteristic parameter values corresponding to the difference number can be obtained, avoiding the missed detection situation caused by manual judgment in the prior art and further improving the accuracy of identification. Finally, the present invention also compares the characteristic parameter value stored in the electronic control unit at the current moment with the characteristic parameter values at other historical moments stored in the preset cloud platform, further refining the possible types of situations that the program data may have and improving the accuracy of identification. It can be seen that the present invention realizes the accurate identification of whether the program in the vehicle-mounted electronic control unit is tampered with.

[0045] Of course, it is not necessary for any product or method implementing the present invention to achieve all the above-mentioned advantages at the same time. Description of the Drawings

[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0047] Figure 1 It is a flowchart of a method for identifying whether program data is tampered with provided by an embodiment of the present invention;

[0048] Figure 2 It is a flowchart of a method for identifying whether program data is tampered with provided by an optional embodiment of the present invention;

[0049] Figure 3Block diagram of a system for identifying tampering of program data provided by an alternative embodiment of the present invention;

[0050] Figure 4 Block diagram of a system for identifying tampering of program data provided by another alternative embodiment of the present invention. Detailed implementation manners

[0051] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0052] The embodiments of the present invention provide a method for identifying tampering of program data. As Figure 1 shown, the method may include:

[0053] S101. When the electronic control unit is not in the after-sales upgrade mode, obtain the characteristic parameter value and the identification number stored in the electronic control unit. The characteristic parameter value is calculated by the electronic control unit using a preset encryption algorithm for the target data, the characteristic parameter value is stored in the electronic control unit at the first moment, the identification number is the unique identifier of the control object of the electronic control unit, and there is a corresponding relationship between the characteristic parameter value and the identification number. The target data includes: the code data in the program code area and / or the data in the data area of the electronic control unit.

[0054] Optionally, the above-mentioned electronic control unit (ECU) is a device composed of integrated circuits for realizing data analysis and processing and controlling the device. The control objects of the above-mentioned electronic control unit include, but are not limited to, power output devices, system controllers, and electronic devices. The present invention does not impose excessive restrictions on the specific control objects of the above-mentioned electronic control unit.

[0055] Optionally, in an alternative embodiment of the present invention, the above-mentioned after-sales upgrade mode refers to the after-sales maintenance and program data upgrade services for the electronic control unit performed by the maintenance personnel of the manufacturer or the operator according to the regular operation and inspection process.

[0056] Optionally, the above-mentioned differentiation number is a unique identifier assigned by the manufacturer to the controlled object after the controlled object of the electronic control unit is off the production line. For example, both the engine number and the Vehicle Identification Number (VIN) are unique, and different differentiation numbers correspond to different characteristic parameter values. In practical applications, the electronic control unit will obtain this differentiation number after establishing a connection with the controlled object. Therefore, by introducing the differentiation number and establishing the corresponding relationship between the differentiation number and the characteristic parameter values, in the subsequent identification process, by searching for the differentiation number, all the characteristic parameter values corresponding to this differentiation number can be called out, avoiding errors and omissions while improving the accuracy of identification.

[0057] Optionally, in an alternative embodiment of the present invention, the above-mentioned characteristic parameter values are obtained by the electronic control unit using a preset encryption algorithm to calculate the code data in the program code area and the data in the data area. When the target data in the electronic control unit is tampered with, the code data in the above-mentioned program code area and / or the data in the data area will change, resulting in the change of the above-mentioned characteristic parameter values. Therefore, the above-mentioned characteristic parameter values can directly reflect whether the program data of the electronic control unit has been tampered with.

[0058] It should be noted that in practical applications, since the above-mentioned characteristic parameter values directly reflect whether the program data of the current electronic control unit has been tampered with, and when performing an identification operation on the electronic control unit, it is necessary to first use the characteristic parameter values stored on the electronic control unit for identification. Therefore, in other alternative embodiments of the present invention, it is set that the above-mentioned characteristic parameter values are not erased when the electronic control unit is powered off.

[0059] Optionally, the above-mentioned first moment refers to the moment after the above-mentioned characteristic parameter values are calculated, and the present invention will not elaborate on this too much.

[0060] Optionally, in an alternative embodiment of the present invention, there is also a corresponding relationship between the above-mentioned different differentiation numbers. For example, if a car privately replaces its engine, the vehicle identification number of the car does not change at this time, but the current engine number changes. During the identification process, since there is a difference in the engine number corresponding to the vehicle identification code of the car stored in the network-side device, an abnormal notification will be sent to inform the operation and maintenance personnel that there is a situation where the engine number of the car does not correspond, further improving the accuracy of identification.

[0061] In practical applications, the above-mentioned preset encryption algorithms include, but are not limited to: Message-Digest Algorithm 5 (MD5), Secure Hash Algorithm (SHA1), and Hash-based Message Authentication Code (HMAC). The specific encryption algorithm to be selected depends on the requirements of the actual application scenario, and the present invention does not impose excessive restrictions on this.

[0062] S102. Search for the latest characteristic parameter value corresponding to the differentiation number in the network-side device, where the time when the latest characteristic parameter value is uploaded to the network-side device is later than the time when other characteristic parameter values corresponding to the differentiation number are uploaded to the network-side device, and the other characteristic parameter values are the characteristic parameter values corresponding to the differentiation number stored in the network-side device except for the latest characteristic parameter value.

[0063] Optionally, in an alternative embodiment of the present invention, the types of the above-mentioned network-side devices include, but are not limited to: servers and databases. The specific network-side device to be selected depends on the purpose and specific application scenario in the present invention, and the present invention does not impose excessive restrictions on this.

[0064] Optionally, in another alternative embodiment of the present invention, a service tool terminal is used as the communication connection node between the electronic control unit and the network-side device. In practical applications, after the above-mentioned service tool terminal is connected to the above-mentioned electronic control unit by an operation and maintenance personnel, the service tool terminal will automatically establish a communication connection with the above-mentioned network-side device, and at the same time, the service tool terminal will automatically establish a communication connection with the after-sales service platform. The present invention does not impose excessive restrictions on the specific model and implementation method of the service tool terminal, and is subject to achieving the purpose of the present invention.

[0065] S103. Determine whether the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit. If not, determine whether at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit. If any of the other characteristic parameter values is not consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has been tampered with.

[0066] Optionally, in an alternative embodiment of the present invention, by comparing the latest characteristic parameter value stored in the network-side device with the characteristic parameter value stored in the current electronic control unit for consistency, it can be accurately determined whether the program data in the current electronic control unit has been tampered with after the last after-sales upgrade service.

[0067] Optionally, in another alternative embodiment of the present invention, by comparing the characteristic parameter values stored in the current electronic control unit with the other characteristic parameter values stored in the network-side device one by one, it can be determined whether the program data in the electronic control unit has been modified through the above after-sales upgrade service, thereby providing a reference for the operation and maintenance personnel to further troubleshoot other possible faults in the program data of the electronic control unit.

[0068] The present invention introduces characteristic parameter values as a measurement standard for reflecting whether the program data in the electronic control unit has been tampered with. By comparing the characteristic parameter values stored in the electronic control unit at the current moment with the characteristic parameter values at the historical moment stored in the network-side device, it is thus determined whether the program data in the electronic control unit at the current moment has been tampered with, making the determination result of the present invention more accurate compared with the manual item-by-item reading in the prior art. The present invention also establishes a correspondence relationship between the difference numbers and the characteristic parameter values, such that during the identification process, by searching for the difference number, all the characteristic parameter values corresponding to the difference number can be obtained, avoiding the missed detection situation caused by manual reading in the prior art and further improving the accuracy of identification. Finally, the present invention further refines the types of situations that the program data may present by comparing the characteristic parameter values stored in the electronic control unit at the current moment with the characteristic parameter values at other historical moments stored in the network-side device, enhancing the accuracy of identification. It can be seen that the present invention realizes the accurate identification of whether the program in the vehicle-mounted electronic control unit has been tampered with.

[0069] Optionally, the above method further includes:

[0070] If the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has not been tampered with.

[0071] Optionally, the above method further includes:

[0072] If at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit is incorrect.

[0073] Among them, in the actual application scenario, the types of the above incorrect target data include but are not limited to: the characteristic parameter value stored in the current electronic control unit is consistent with at least one of the other characteristic parameter values, and the service tool terminal cannot read the characteristic parameter value stored in the current electronic control unit, etc.

[0074] Optionally, in an alternative embodiment of the present invention, the program data in the current electronic control unit is the program data flashed through an after-sales upgrade service. However, when the program data stored in the current electronic control unit does not match the flashing record of the latest after-sales upgrade service stored in the network-side device, the operation and maintenance personnel can further detect the electronic control unit based on the recognition result of the target data error.

[0075] Optionally, the above method further includes:

[0076] When the electronic control unit is in the offline mode, control the electronic control unit to calculate according to the target data using a preset encryption algorithm to obtain the characteristic parameter value at the moment when the electronic control unit is in the offline mode, establish the corresponding relationship between the characteristic parameter value at the offline mode moment and the difference number, and upload the difference number and the characteristic parameter value at the offline mode moment to the network-side device for storage.

[0077] The present invention realizes the acquisition of basic data by verifying whether the electronic control unit is in the above offline mode, and for the electronic control unit in the offline mode, controlling it to generate the characteristic parameter value in the current state, and after establishing the corresponding relationship between the characteristic parameter value and the difference number, uploading the above characteristic parameter value and the difference number to the network-side device for storage, thereby realizing the coherence of the recognition process.

[0078] Optionally, the above method further includes:

[0079] When the electronic control unit is in the after-sales upgrade mode, upgrade the target data in the electronic control unit. After the upgrade is completed, control the electronic control unit to calculate according to the upgraded target data using a preset encryption algorithm to obtain the upgraded characteristic parameter value, establish the corresponding relationship between the upgraded characteristic parameter value and the difference number, and upload the difference number and the upgraded characteristic parameter value to the network-side device for storage.

[0080] Optionally, in an alternative embodiment of the present invention, after completing the upgrade and storage operations of the target data in the above electronic control unit, the service tool terminal uploads the content of the current upgrade and storage operations to the after-sales service platform for storage. Among them, the types of the above after-sales service platform include but are not limited to: servers and databases. The specific choice of the after-sales service platform depends on the purpose and specific application scenario in the present invention, and the present invention does not impose too many restrictions on this. The content stored in the after-sales service platform includes but is not limited to: upgrade object, specific upgrade content, upgrade supervisor information, upgrade location, etc.

[0081] Those skilled in the art can understand that after determining that the current electronic control unit is in the after-sales upgrade mode, it is also possible to first identify whether the target data stored in the electronic control unit has been tampered with, and then perform subsequent upgrade operations on the target data after passing the identification. The present invention does not impose too many restrictions on this.

[0082] For the convenience of understanding the method for identifying the tampering of the above-mentioned identification program data, the following will be combined with Figure 2 to illustrate another optional embodiment of the present invention:

[0083] As Figure 2 shown, identify whether the target data of the electronic control unit of a certain vehicle has been tampered with. Among them, the control objects of the electronic control unit of this vehicle include the engine and the vehicle controller, and hereinafter the electronic control unit is replaced by ECU.

[0084] Step S201, the operation and maintenance personnel connect the service tool terminal to the ECU and trigger step S202.

[0085] Among them, after the service tool terminal establishes a communication connection with the ECU, the service tool terminal will automatically establish a communication connection with the network-side device.

[0086] Step S202, determine whether the first ECU controlling the engine is in the offline mode. If so, trigger step S203. If not, trigger step S204.

[0087] Step S203, control the first ECU to calculate the characteristic parameter value when the engine is in the offline mode, establish the corresponding relationship between the characteristic parameter value and the engine number, and upload the characteristic parameter value and the corresponding engine number to the network-side device for storage, and end the process.

[0088] Step S204, determine whether the second ECU controlling the vehicle controller is in the offline mode. If so, trigger step S205. If not, trigger step S206.

[0089] Step S205, control the second ECU to calculate the characteristic parameter value when the vehicle controller is in the offline mode, establish the corresponding relationship between the characteristic parameter value and the vehicle identification number, and upload the characteristic parameter value and the corresponding vehicle identification number to the network-side device for storage, and end the process.

[0090] Step S206, respectively determine whether the above two ECUs are in the after-sales upgrade mode. If so, trigger step S207. If not, trigger step S208.

[0091] It should be noted that the steps after step S206 are the same in terms of the execution content for the above two ECUs. For the sake of convenience in description, the steps after step S206 will no longer distinguish between the first ECU and the second ECU, and their corresponding parameter names.

[0092] Step S207: Upgrade the target data of the above ECU. After the upgrade is completed, establish the relationship between the difference number and the characteristic parameter value, and upload the difference number and the characteristic parameter value to the network-side device for storage, and end the process.

[0093] Step S208: Read the characteristic parameter value and the difference number currently stored in the ECU, and compare them with the characteristic parameter value corresponding to the difference number stored in the network-side device, and trigger step S209.

[0094] Step S209: Determine whether the current characteristic parameter value is consistent with the latest characteristic parameter value stored on the network-side device. If so, trigger step S210; if not, trigger step S211.

[0095] Step S210: Output the recognition result that the target data has not been tampered with, and end the process.

[0096] Step S211: Determine whether the current characteristic parameter value is inconsistent with all other characteristic parameter values on the network-side device except the latest characteristic parameter value. If so, trigger step S212; if not, trigger step S213.

[0097] Step S212: Output the recognition result that the target data has been tampered with, and end the process.

[0098] Step S213: Output the recognition result that the target data is incorrect, and output the characteristic parameter value and the difference number that are consistent with the current characteristic parameter value among the other characteristic parameter values stored on the network-side device, and end the process.

[0099] Among them, step S208 is Figure 1 a specific implementation manner of step S101 shown, and steps S209, S211, and S212 are Figure 1 a specific implementation manner of step S103 shown.

[0100] The present invention introduces characteristic parameter values as a measure to reflect whether the program data in the electronic control unit has been tampered with. By comparing the characteristic parameter values stored in the electronic control unit at the current moment with the characteristic parameter values of the historical moments stored in the network side device, it is determined whether the program data in the electronic control unit at the current moment has been tampered with, so that the present invention is more accurate than the manual interpretation of the prior art. The present invention also establishes a corresponding relationship between the difference number and the characteristic parameter value, so that in the identification process, by searching the difference number, all the characteristic parameter values corresponding to the difference number can be obtained, avoiding the missed detection caused by manual interpretation in the prior art, and further improving the accuracy of identification. Finally, the present invention also further refines the types of situations that may occur in the program data by comparing the characteristic parameter values stored in the electronic control unit at the current moment with the characteristic parameter values of other historical moments stored in the network side device, and improves the accuracy of identification. It can be seen that the present invention realizes the accurate identification of whether the program in the vehicle-mounted electronic control unit has been tampered with.

[0101] Corresponding to the above-mentioned embodiment of the method for identifying that program data has been tampered with, the present invention also provides a system for identifying that program data has been tampered with, such as Figure 3 As shown, the system for identifying that program data has been tampered with includes:

[0102] The first data acquisition module 301 is used to obtain the characteristic parameter value and the distinguishing number stored in the electronic control unit when the electronic control unit is not in the after-sales upgrade mode, wherein the characteristic parameter value is obtained by the electronic control unit by calculating the target data using a preset encryption algorithm, and the characteristic parameter value is stored in the electronic control unit at the first moment, the distinguishing number is a unique identifier of the control object of the electronic control unit, and the characteristic parameter value and the distinguishing number have a corresponding relationship, and the target data includes: code data in the program code area and / or data in the data area in the electronic control unit.

[0103] The data calling module 302 is used to search for the latest characteristic parameter value corresponding to the distinguishing number in the network side device, wherein the time when the latest characteristic parameter value is uploaded to the network side device is later than the time when other characteristic parameter values corresponding to the distinguishing number are uploaded to the network side device, wherein the other characteristic parameter values are the characteristic parameter values corresponding to the distinguishing number stored in the network side device except the latest characteristic parameter value.

[0104] A data comparison module 303 is used to determine whether the latest feature parameter value is consistent with the feature parameter value stored in the electronic control unit. If not, it determines whether at least one of the other feature parameter values is consistent with the feature parameter value stored in the electronic control unit. If none of the other feature parameter values is consistent with the feature parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has been tampered with.

[0105] Optionally, the above-mentioned data comparison module 303 is further configured to:

[0106] When the latest feature parameter value is consistent with the feature parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has not been tampered with.

[0107] Optionally, the above-mentioned data comparison module 303 is further configured to:

[0108] When at least one of the other feature parameters is consistent with the feature parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit is incorrect.

[0109] Optionally, the above-mentioned system further includes:

[0110] A second data acquisition module is used to control the electronic control unit to calculate according to the target data by using a preset encryption algorithm when the electronic control unit is in the offline mode, obtain the feature parameter value at the moment when the electronic control unit is in the offline mode, establish the corresponding relationship between the feature parameter value at the offline mode moment and the difference number, and upload the difference number and the feature parameter value at the offline mode moment to the network-side device for storage.

[0111] Optionally, the above-mentioned system further includes:

[0112] A data upgrade module is used to upgrade the target data in the electronic control unit when the electronic control unit is in the after-sales upgrade mode. After the upgrade is completed, it controls the electronic control unit to calculate according to the upgraded target data by using a preset encryption algorithm, obtain the upgraded feature parameter value, establish the corresponding relationship between the upgraded feature parameter value and the difference number, and upload the difference number and the upgraded feature parameter value to the network-side device for storage.

[0113] The present invention also provides a system for identifying that program data has been tampered with. The system includes: an electronic control unit, a first network-side device, and a service tool terminal.

[0114] The service tool terminal acquires the feature parameter value and the difference number stored in the electronic control unit and sends the feature parameter value and the difference number to the first network-side device when the electronic control unit is not in the after-sales upgrade mode.

[0115] The first network-side device obtains the difference number sent by the service tool terminal, and the first network-side device searches for the latest characteristic parameter value corresponding to the difference number, where the time when the latest characteristic parameter value is uploaded to the first network-side device is later than the time when other characteristic parameter values corresponding to the difference number are uploaded to the first network-side device, and the other characteristic parameter values are the characteristic parameter values corresponding to the difference number stored in the first network-side device except the latest characteristic parameter value.

[0116] The first network-side device determines whether the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit. If not, it determines whether at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit. If any of the other characteristic parameter values is not consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has been tampered with.

[0117] Optionally, the system further includes: a second network-side device,

[0118] When the first network-side device determines that the target data of the electronic control unit has been tampered with, it sends the identification result that the target data has been tampered with to the service tool terminal.

[0119] The service tool terminal sends the identification result to the second network-side device. The second network-side device calls the disposal method matching the identification result in the preset database according to the identification result, and sends the disposal method to the service tool terminal.

[0120] Optionally, the first network-side device is further configured to:

[0121] When it is determined that the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has not been tampered with.

[0122] Optionally, the first network-side device is further configured to:

[0123] When it is determined that at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit is incorrect.

[0124] Optionally, the service tool terminal is further configured to:

[0125] When the electronic control unit is in the offline mode, control the electronic control unit to calculate according to the target data by using a preset encryption algorithm to obtain the characteristic parameter value at the moment when the electronic control unit is in the offline mode, establish the corresponding relationship between the characteristic parameter value at the offline mode moment and the difference number, and upload the difference number and the characteristic parameter value at the offline mode moment to the network-side device for storage.

[0126] Optionally, the service tool terminal is further configured to:

[0127] When the electronic control unit is in the after-sales upgrade mode, upgrade the target data in the electronic control unit. After the upgrade is completed, control the electronic control unit to calculate according to the upgraded target data by using a preset encryption algorithm to obtain an upgraded characteristic parameter value, establish a correspondence between the upgraded characteristic parameter value and the difference number, and upload the difference number and the upgraded characteristic parameter value to the network-side device for storage.

[0128] Optionally, in an alternative embodiment of the present invention, the above system for identifying tampering of program data is as Figure 4 shown, and includes a first network-side device 401, a service tool terminal 402, an electronic control unit 403, a controlled object 404, and a second network-side device 405. Among them, the network-side device 401 is communicatively connected to the service tool terminal 402, the service tool terminal 402 is communicatively connected to the electronic control unit 403, the electronic control unit 403 is communicatively connected to the controlled object 404, and the service tool terminal 402 is communicatively connected to the second network-side device 405. Among them, the above second network-side device may be the above after-sales service platform, and the types of the second network-side device include, but are not limited to: servers and databases.

[0129] Optionally, the above first network-side device may be used to store information such as electronic control unit information, controlled object information, target key values, etc., and is used to send instructions to the service tool terminal or the second network-side device. The above service tool terminal may be used to interact with the electronic control unit, diagnose the status of the electronic control unit, perform operations such as flashing the electronic control unit, and transmit instructions and information. The above second network-side device may be used to receive the identification result sent by the service tool terminal or the first network-side device, and send the disposal method matching the identification result in the preset database to the service tool terminal or the first network-side device.

[0130] Optionally, the above electronic control unit may be used to respond to the instructions of the service tool terminal, calculate the above characteristic parameter value, and may send the characteristic parameter value and the difference number to the service tool terminal or the first network-side device.

[0131] The memory may include non-permanent memory in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one memory chip. The memory is an example of a computer-readable medium.

[0132] A computer-readable medium includes both permanent and non-permanent, removable and non-removable media and can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information accessible by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media such as modulated data signals and carrier waves.

[0133] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0134] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, commodity or device including the element.

[0135] Each embodiment in this specification is described in a related manner. The same or similar parts between the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.

[0136] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A method for identifying tampering of program data, characterized in that, The method includes: When the electronic control unit is not in the after-sales upgrade mode, obtaining the characteristic parameter value and the difference number stored in the electronic control unit, where the characteristic parameter value is obtained by the electronic control unit calculating target data using a preset encryption algorithm, the characteristic parameter value is stored in the electronic control unit at a first moment, the difference number is the unique identifier of the control object of the electronic control unit, the characteristic parameter value and the difference number have a corresponding relationship, and the target data includes: the code data in the program code area of the electronic control unit and / or the data in the data area; Searching in the network-side device for the latest characteristic parameter value corresponding to the difference number, where the moment when the latest characteristic parameter value is uploaded to the network-side device is later than the moment when other characteristic parameter values corresponding to the difference number are uploaded to the network-side device, and the other characteristic parameter values are the characteristic parameter values corresponding to the difference number stored in the network-side device except the latest characteristic parameter value; Judging whether the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit. If not, judging whether at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit. If any of the other characteristic parameter values is not consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has been tampered with.

2. The method according to claim 1, wherein The method further includes: If the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has not been tampered with.

3. The method according to claim 1, wherein The method further includes: If at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit is incorrect.

4. The method according to claim 1, wherein The method further includes: When the electronic control unit is in the offline mode, controlling the electronic control unit to calculate according to the target data using the preset encryption algorithm to obtain the characteristic parameter value at the moment when the electronic control unit is in the offline mode, establishing the corresponding relationship between the characteristic parameter value at the offline mode moment and the difference number, and uploading the difference number and the characteristic parameter value at the offline mode moment to the network-side device for storage.

5. The method according to claim 1, characterized in that, The method further includes: When the electronic control unit is in the after-sales upgrade mode, upgrading the target data in the electronic control unit. After the upgrade is completed, controlling the electronic control unit to calculate according to the upgraded target data using the preset encryption algorithm to obtain the upgraded characteristic parameter value, establishing the corresponding relationship between the upgraded characteristic parameter value and the difference number, and uploading the difference number and the upgraded characteristic parameter value to the network-side device for storage.

6. A system for identifying the tampering of program data, characterized in that, The system includes: A first data acquisition module, configured to obtain the characteristic parameter value and the identification number stored in the electronic control unit when the electronic control unit is not in the after-sales upgrade mode, where the characteristic parameter value is obtained by the electronic control unit calculating target data using a preset encryption algorithm, the characteristic parameter value is stored in the electronic control unit at a first moment, the identification number is the unique identifier of the control object of the electronic control unit, the characteristic parameter value and the identification number have a corresponding relationship, and the target data includes: code data in the program code area of the electronic control unit and / or data in the data area; A data call module, configured to search in the network-side device for the latest characteristic parameter value corresponding to the identification number, where the moment when the latest characteristic parameter value is uploaded to the network-side device is later than the moment when other characteristic parameter values corresponding to the identification number are uploaded to the network-side device, and the other characteristic parameter values are the characteristic parameter values corresponding to the identification number stored in the network-side device except for the latest characteristic parameter value; A data comparison module, configured to determine whether the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit. If not, determine whether at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit. If none of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit, determine that the target data of the electronic control unit has been tampered with.

7. The system according to claim 6, wherein The system further includes: A data upgrade module, configured to upgrade the target data in the electronic control unit when the electronic control unit is in the after-sales upgrade mode. After the upgrade is completed, control the electronic control unit to calculate according to the upgraded target data using the preset encryption algorithm to obtain an upgraded characteristic parameter value, establish a corresponding relationship between the upgraded characteristic parameter value and the identification number, and upload the identification number and the upgraded characteristic parameter value to the network-side device for storage.

8. The system according to claim 6, wherein The system further includes: A second data acquisition module, configured to control the electronic control unit to calculate according to the target data using the preset encryption algorithm to obtain the characteristic parameter value at the moment when the electronic control unit is in the offline mode when the electronic control unit is in the offline mode, establish a corresponding relationship between the characteristic parameter value at the offline mode moment and the identification number, and upload the identification number and the characteristic parameter value at the offline mode moment to the network-side device for storage.

9. A system for identifying tampering of program data, characterized in that, The system includes: an electronic control unit, a first network-side device, and a service tool terminal. When the electronic control unit is not in the after-sales upgrade mode, the service tool terminal obtains the characteristic parameter values and the identification number stored in the electronic control unit, and sends the characteristic parameter values and the identification number to the first network-side device. The characteristic parameter values are obtained by the electronic control unit calculating target data using a preset encryption algorithm. The characteristic parameter values are stored in the electronic control unit at a first moment. The identification number is the unique identifier of the control object of the electronic control unit. There is a corresponding relationship between the characteristic parameter values and the identification number. The target data includes: code data in the program code area and / or data in the data area of the electronic control unit; The first network-side device obtains the identification number sent by the service tool terminal. The first network-side device searches for the latest characteristic parameter value corresponding to the identification number. Among them, the moment when the latest characteristic parameter value is uploaded to the first network-side device is later than the moment when other characteristic parameter values corresponding to the identification number are uploaded to the first network-side device. The other characteristic parameter values are the characteristic parameter values corresponding to the identification number stored in the first network-side device except the latest characteristic parameter value; The first network-side device determines whether the latest characteristic parameter value is consistent with the characteristic parameter value stored in the electronic control unit. If not, it determines whether at least one of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit. If none of the other characteristic parameter values is consistent with the characteristic parameter value stored in the electronic control unit, it is determined that the target data of the electronic control unit has been tampered with.

10. The system according to claim 9, wherein The system further includes: a second network-side device, When the first network-side device determines that the target data of the electronic control unit has been tampered with, it sends the identification result that the target data has been tampered with to the service tool terminal; The service tool terminal sends the identification result to the second network-side device. The second network-side device calls the disposal method matching the identification result in the preset database according to the identification result, and sends the disposal method to the service tool terminal.

Citation Information

Patent Citations

  • Electronic data storage system, history verifying device, electronic data storing method and recording medium

    JP2001337600A

  • Apparatus, license management system, license management method, and license managing program

    JP2013037705A