A method and system for a post-installation device to safely access a vehicle electronic system

The unique security certificate and cloud certificate management system verification are generated through the Guose algorithm, which solves the security problem of the rear-installed equipment being connected to the vehicle electronic system, realizes identity authentication and permission management of the rear-installed equipment, and improves communication security and system stability.

CN114815762BActive Publication Date: 2025-07-22GUANGZHOU AUTOMOBILE GROUP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110061309.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-18
Publication Date
2025-07-22
Estimated Expiration
2041-01-18

AI Technical Summary

Technical Problem

The existing method of connecting the rear-installation equipment to the vehicle electronic system is insufficient security, and it is impossible to effectively manage the identity authentication and permissions of third-party rear-installation equipment, resulting in an increase in the risk of car failure or data leakage.

Method used

The National Secret algorithm is used to generate a unique security certificate, and the identity verification and permission management of the rear-installed equipment is carried out through the cloud certificate management system. The vehicle gateway determines access permissions based on the verification results, and uses the National Secret algorithm to encrypt communications to achieve secure access between the equipment and the vehicle electronic system.

Benefits of technology

It improves the communication security between the rear-mounted equipment and the vehicle electronic system, ensures that equipment that has not passed the review cannot be accessed, provides permission level management, reduces safety risks, and improves system stability and controllability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114815762B_ABST
    Figure CN114815762B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for aftermarket equipment to securely access a vehicle electronic system, comprising: step S10, after the aftermarket equipment is connected to the OBD interface, the encrypted information containing the device ID and its pre-stored security certificate is sent to the vehicle gateway; step S11, the vehicle gateway initiates an authentication request to the cloud certificate management system according to the received encrypted content; step S12, after the cloud certificate management system receives the authentication request, it decrypts the device ID and security certificate carried therein; step S13, the cloud certificate management system verifies the legitimacy and validity of the device ID and security certificate, and responds to the vehicle gateway; step S14, the vehicle gateway processes the access request of the aftermarket equipment accordingly according to the response result. The present invention also discloses a corresponding system. The implementation of the present invention can improve the security of communication between aftermarket equipment and vehicle electronic systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security of vehicle electronic systems, and particularly to a method and system for securely accessing a vehicle electronic system by a retrofit device. Background Art

[0002] Automobile retrofit devices are usually developed and sold by third-party product development companies and are connected to the electronic system of an automobile through a standard interface provided by the automobile. On the one hand, they can provide users with customized functions beyond those designed by automobile manufacturers; on the other hand, they can monitor and collect automobile operation data to achieve their own required application purposes. Although these retrofit devices provide convenience for users and others, the quality of retrofit devices varies, making it difficult to monitor and supervise them, and they are prone to causing automobile failures or leakage of key data of the automobile and users.

[0003] Especially when accessing a vehicle through an OBD interface (On Board Diagnostics), identity verification is required. The existing implementation schemes mainly have three forms: 1. Through a set of pre-agreed password exchange methods, the diagnostic device and relevant in-vehicle controllers mutually confirm identity information to prevent unrecognized devices from accessing; 2. Use a public key infrastructure (PKI) to issue valid certificates to the diagnostic device. When the diagnostic device connects to the in-vehicle network, the relevant in-vehicle controllers verify the validity of the device's certificate to confirm the identity of the diagnostic device; 3. Add a communication protection component between the in-vehicle controller network and the OBD, including several modules such as key distribution, encryption and decryption, and identity authentication. By using the same encryption and decryption algorithm for each external device, a one-time random number sent by the encryption and decryption module is transformed into a function as a response and encrypted using the belonging key and sent to the identity authentication center, thereby completing the identity authentication of the external device.

[0004] However, the existing methods also have some deficiencies:

[0005] First of all, almost all of the existing technical solutions are used for diagnostic devices and do not consider the usage scenarios of other third-party retrofit devices.

[0006] In addition, the first solution has poor security because the password may be leaked. Once the password is obtained, anyone can develop a device that can access the vehicle. The second solution does not use national cryptographic algorithms, and the core module has poor self-control. The third solution cannot divide the permission levels of access devices and cannot restrict the permissions of access devices. Since the decryption method used for the identity authentication module in the third solution is built into the external device and the same set of decryption algorithms is shared by any external device, once it is cracked, it will pose a great security threat. Summary of the Invention

[0007] The technical problem to be solved by the present invention is to provide a method and system for securely accessing a vehicle electronic system by a retrofit device, which can improve the security of communication between the retrofit device and the vehicle electronic system.

[0008] To solve the above technical problem, as one aspect of the present invention, there is provided a method for securely accessing a vehicle electronic system by a retrofit device, which includes the following steps:

[0009] Step S10, after the retrofit device accesses the OBD interface, the encrypted information containing the device ID and its pre-stored security certificate is sent to the vehicle-mounted gateway via the OBD interface, wherein the encryption uses the national cryptographic algorithm;

[0010] Step S11, the vehicle-mounted gateway initiates an authentication request to the cloud certificate management system according to the received encrypted content, and the authentication request contains the encrypted information from the retrofit device;

[0011] Step S12, after receiving the authentication request, the cloud certificate management system decrypts the device ID and the security certificate carried therein;

[0012] Step S13, the cloud certificate management system performs legality and validity verification processing on the device ID and the security certificate. If the authentication result is a legal certificate and the certificate is within the valid lifetime, it is determined that the verification is successful, and the vehicle-mounted gateway is notified, and at the same time, the permission level of the current retrofit device is informed; otherwise, it is determined that the verification fails and the vehicle-mounted gateway is notified;

[0013] Step S14, after receiving the verification success notification, the vehicle-mounted gateway performs corresponding processing on the access request of the retrofit device according to the permission level; the corresponding processing includes: executing the message of the access device, forwarding the message of the access device, or rejecting the message of the access device; after receiving the verification failure notification, the vehicle-mounted gateway rejects the retrofit device from accessing the OBD interface.

[0014] Among them, it further includes:

[0015] Each retrofit device applies to the cloud certificate management system for a security certificate;

[0016] The cloud certificate management system verifies the retrofit device and issues a security certificate, which is generated by the national cryptographic algorithm and at least includes an identity identifier, key information, and validity period information; the national cryptographic algorithm is SM2 and SM3;

[0017] The retrofit device receives the initial security certificate and stores it;

[0018] The cloud certificate management system establishes the corresponding relationship between each device ID, the corresponding security certificate, and the permission level.

[0019] Among them, further include:

[0020] Each after-installed device periodically or before use initiates a request to the cloud certificate management system to verify and update the certificate. The cloud certificate management system manages the certificates of all after-installed devices, including verification, update, and revocation.

[0021] Among them, further include:

[0022] In the vehicle gateway, the execution operation scope corresponding to each permission level, the devices and network segments / network ports that can be accessed corresponding to each permission level are pre-determined, and the corresponding relationship table of "device / certificate / authority level" is recorded.

[0023] Among them, the messages between the vehicle-mounted terminal and the cloud certificate management system are encrypted using one of the national encryption algorithms SM1, SM2, and SM3.

[0024] Accordingly, another aspect of the present invention further provides a system for securely accessing a post-installed device to a vehicle electronic system, comprising:

[0025] The after-installed device is used to send the encrypted information including the device ID and its pre-stored security certificate to the vehicle gateway via the OBD interface after accessing the OBD interface, wherein the encryption adopts the national secret algorithm;

[0026] The vehicle-mounted gateway is arranged in the vehicle, and is used to receive the encrypted content from the after-installed device through the OBD interface, and initiate an authentication request to the cloud certificate management system, wherein the authentication request includes the encrypted information from the after-installed device; and is used to process the access request of the after-installed device accordingly according to the permission level after receiving the verification success notification; the corresponding processing includes: executing the message of accessing the device, forwarding the message of accessing the device, or refusing the message of accessing the device; and is used to refuse the after-installed device to access the OBD interface after receiving the verification failure notification;

[0027] The cloud certificate management system is used to decrypt the device ID and security certificate carried in the authentication request after receiving it; verify the legitimacy and validity of the device ID and security certificate. If the authentication result is a legal certificate and the certificate is within the valid life cycle, the verification is determined to be successful, and the vehicle gateway is notified, and the permission level of the current after-installed device is informed; otherwise, the verification is determined to have failed and the vehicle gateway is notified.

[0028] Wherein, the aftermarket equipment further comprises:

[0029] A security certificate application unit, used to apply for a security certificate from a cloud certificate management system;

[0030] A storage unit, used to receive and store the initial security certificate;

[0031] The verification and update unit is used to initiate a request to verify and update the certificate to the cloud certificate management system periodically or before use.

[0032] Wherein, the cloud certificate management system further includes:

[0033] A security certificate generation unit, used to verify the post-installed device and issue a security certificate, wherein the security certificate is generated by a national secret algorithm and includes at least an identity identifier, key information, and validity period information; the national secret algorithm is SM2 and SM3;

[0034] The corresponding relationship establishing unit is used to establish the corresponding relationship between each device ID, the corresponding security certificate and the authority level.

[0035] The security certificate management unit is used to manage the certificates of all after-installed devices, including verification, update and revocation.

[0036] Wherein, the vehicle gateway further includes:

[0037] The recording storage unit is used to predetermine the execution operation scope corresponding to each permission level, the devices and network segments / network ports that can be accessed corresponding to each permission level in the vehicle gateway, and record the corresponding relationship table of "device / certificate / authority level".

[0038] Among them, the messages between the vehicle-mounted terminal and the cloud certificate management system are encrypted using one of the national encryption algorithms SM1, SM2, and SM3.

[0039] The implementation of the embodiments of the present invention has the following beneficial effects:

[0040] The present invention provides a method and system for securely accessing a vehicle electronic system with an aftermarket device. By setting up a cloud certificate management system, it is ensured that each legitimate access device has a built-in unique security certificate, so that each aftermarket device authentication is independent, and unauthorized devices that have not passed the review cannot be used to access the vehicle, thereby better maintaining the communication security between the aftermarket device and the controller in the vehicle.

[0041] At the same time, the present invention implements a certificate life management mechanism for all pre-set certificates, and re-authorizes them at regular intervals, which can effectively protect the timeliness and security of the certificates;

[0042] In addition, permission level management is provided for different after-market devices, and the functional permissions of different after-market devices can be restricted to avoid security risks caused by after-market devices arbitrarily accessing all in-vehicle controller resources after successfully connecting to the vehicle, thereby improving safety and stability.

[0043] Moreover, the present invention uses the national cryptographic algorithm to generate the certificate used for device authentication, improving the controllability of the module. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, obtaining other drawings based on these drawings still belongs to the scope of the present invention.

[0045] Figure 1 It is a schematic diagram of the main process of an embodiment of a method for a retrofit device to securely access a vehicle electronic system provided by the present invention;

[0046] Figure 2 It is a schematic diagram of the structure of an embodiment of a system for a retrofit device to securely access a vehicle electronic system provided by the present invention;

[0047] Figure 3 For Figure 2 It is a schematic diagram of the structure of the retrofit device in

[0048] Figure 4 For Figure 2 It is a schematic diagram of the structure of the cloud certificate management system in

[0049] Figure 5 For Figure 2 It is a schematic diagram of the structure of the in-vehicle gateway in DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the drawings.

[0051] As Figure 1 shown, it shows a schematic diagram of the main process of an embodiment of a method for a retrofit device to securely access a vehicle electronic system provided by the present invention. In this embodiment, the method for a retrofit device to securely access a vehicle electronic system includes the following steps:

[0052] Step S10, after the retrofit device accesses the OBD interface, it sends the encrypted information containing the device ID and its pre-stored security certificate to the in-vehicle gateway via the OBD interface. Among them, the encryption uses the national cryptographic algorithm, and the OBD interface establishes a dedicated line connection with the in-vehicle gateway; the retrofit device cannot access other electronic control units (ECUs) except the in-vehicle gateway; it can be understood that in the present invention, the retrofit device can also be a diagnostic device.

[0053] It should be understood that the security certificate pre-stored in the after-sales device is pre-applied from the cloud certificate management system. For example, in one example, the following steps are further included before step S10:

[0054] Each aftermarket device applies for a security certificate from the cloud certificate management system, where the cloud certificate management system is generally established and maintained by the vehicle manufacturer;

[0055] The cloud certificate management system verifies the after-sales device and issues a security certificate. The security certificate is generated by a national secret algorithm and includes at least identity identification, key information, and validity period information. The national secret algorithm is SM2 and SM3. Each security certificate has a one-to-one correspondence with each after-sales device, that is, the certificate of each after-sales device is unique. For example, a correspondence table of device ID / security certificate / authority level can be stored in the cloud certificate management system. This setting can ensure the relative independence of the authentication of each after-sales device. Even if a security certificate is leaked, the impact is very limited, so it can effectively reduce the negative impact of the loss of the security certificate.

[0056] The after-sales device receives and stores the initial security certificate;

[0057] The cloud certificate management system establishes a correspondence between each device ID, the corresponding security certificate, and the permission level, and also records the validity period of each security certificate.

[0058] Step S11, the vehicle-mounted gateway initiates an authentication request to the cloud-based certificate management system based on the received encrypted content, and the authentication request includes the encrypted information from the after-sales device; it is understandable that the authentication request also uses an encrypted message, and the encryption uses a national encryption algorithm, such as one of the national encryption algorithms SM1, SM2, and SM3. The specific national encryption algorithm to be used needs to be determined in advance by the cloud-based certificate management system and the vehicle-mounted gateway;

[0059] Step S12, after receiving the authentication request, the cloud certificate management system decrypts the device ID and security certificate carried therein; specifically, the encrypted information from the after-installed device may be first decrypted, and then the encrypted information may be decrypted again to obtain the device ID and security certificate in the encrypted information;

[0060] Step S13, the cloud certificate management system verifies the legitimacy and validity of the device ID and security certificate. If the authentication result is a legal certificate and the certificate is within the valid life cycle, the verification is determined to be successful, and the vehicle gateway is notified, and the permission level of the current after-installed device is informed; otherwise, the verification is determined to be failed and the vehicle gateway is notified;

[0061] Step S14: After receiving the verification success notification, the vehicle-mounted gateway processes the access request of the retrofit device according to the permission level. The corresponding processing includes: executing the message of the access device, forwarding the message of the access device, or rejecting the message of the access device. After receiving the verification failure notification, the vehicle-mounted gateway rejects the retrofit device from accessing the OBD interface.

[0062] It can be understood that in the vehicle-mounted gateway, the execution operation range corresponding to each permission level, the devices, network segments / network ports that can be accessed corresponding to each permission level are determined in advance, and the corresponding relationship table of "device / certificate / permission level" is recorded. For different vehicle models and platforms, the above form or the content corresponding to the permission level may be different.

[0063] Therefore, after receiving the verification success notification, the vehicle-mounted gateway can process the access request or the message sent by the retrofit device according to the permission level corresponding to the device ID.

[0064] It can be understood that in order to ensure that the certificates in each retrofit device are valid or up-to-date, the following steps are further included:

[0065] Each retrofit device periodically or before use sends a request to the cloud certificate management system to verify and update the certificate. The cloud certificate management system manages the certificates of all retrofit devices. The management includes: verification, update, and revocation. For example, in some cases, the retrofit device can initiate verification and update in the following two ways: First, actively query whether the certificate is within the validity period at regular intervals (such as every month) and update it in time; Second, verify the certificate validity status before use and update it in time.

[0066] As Figure 2 shown, a schematic structural diagram of an embodiment of a system for safely accessing a retrofit device to a vehicle electronic system according to the present invention is shown. In combination with Figures 3 to 5 shown, in the embodiment, the system includes:

[0067] The retrofit device 1 is used to send the encrypted information containing the device ID and its pre-stored security certificate to the vehicle-mounted gateway via the OBD interface after accessing the OBD interface, where the encryption uses the national cryptography algorithm.

[0068] The vehicle-mounted gateway 2 is installed in a vehicle and is used to receive encrypted content from a retrofit device through an OBD interface and initiate an authentication request to a cloud certificate management system. The authentication request contains encrypted information from the retrofit device. It is also used to, after receiving a verification success notification, perform corresponding processing on the access request of the retrofit device according to the permission level. The corresponding processing includes: executing messages of the access device, forwarding messages of the access device, or rejecting messages of the access device. And it is used to, after receiving a verification failure notification, reject the retrofit device from accessing the OBD interface.

[0069] The cloud certificate management system 3 is used to, after receiving an authentication request, decrypt the device ID and security certificate carried therein, perform legality and validity verification processing on the device ID and security certificate. If the authentication result is a legal certificate and the certificate is within the valid life period, it determines that the verification is successful, notifies the vehicle-mounted gateway, and at the same time informs the permission level of the current retrofit device. Otherwise, it determines that the verification fails and notifies the vehicle-mounted gateway.

[0070] Among them, the retrofit device 1 further includes:

[0071] A security certificate application unit 10 is used to apply for a security certificate to the cloud certificate management system.

[0072] A storage unit 11 is used to receive the initial security certificate and store it.

[0073] A verification and update unit 12 is used to periodically or before use initiate a request to the cloud certificate management system to verify and update the certificate.

[0074] An access unit 13 is used to, after accessing the OBD interface, send encrypted information containing the device ID and its pre-stored security certificate to the vehicle-mounted gateway via the OBD interface.

[0075] Among them, the cloud certificate management system 3 further includes:

[0076] A security certificate generation unit 30 is used to verify the retrofit device and issue a security certificate. The security certificate is generated by a national cryptography algorithm, and it at least includes an identity identifier, key information, and validity period information. The national cryptography algorithms are SM2 and SM3.

[0077] A corresponding relationship establishment unit 31 is used to establish the corresponding relationship between each device ID, the corresponding security certificate, and the permission level.

[0078] A security certificate management unit 32 is used to manage the certificates of all retrofit devices. The management includes: verification, update, and revocation.

[0079] The verification processing unit 33 is configured to, after receiving an authentication request, decrypt the device ID and security certificate carried therein; perform legality and validity verification processing on the device ID and security certificate. If the authentication result is a legal certificate and the certificate is within the valid lifetime, it is determined that the verification is successful, and the vehicle-mounted gateway is notified, and at the same time, the permission level of the current retrofit device is informed; otherwise, it is determined that the verification fails and the vehicle-mounted gateway is notified.

[0080] Wherein, the vehicle-mounted gateway 2 further includes:

[0081] The record storage unit 20 is configured to pre-determine the execution operation range corresponding to each permission level, the devices and network segments / network ports that can be accessed corresponding to each permission level in the vehicle-mounted gateway, and record the correspondence table of "device / certificate / permission level";

[0082] The authentication request unit 21 is configured to receive the encrypted content from the retrofit device through the OBD interface and initiate an authentication request to the cloud certificate management system, and the authentication request includes the encrypted information from the retrofit device;

[0083] The post-authentication processing unit 22 is configured to, after receiving the verification success notification, and according to the permission level, perform corresponding processing on the access request of the retrofit device; the corresponding processing includes: executing the message of the access device, forwarding the message of the access device, or rejecting the message of the access device; and is configured to, after receiving the verification failure notification, reject the retrofit device from accessing the OBD interface.

[0084] Wherein, the message between the vehicle-mounted terminal and the cloud certificate management system is encrypted using one of the national cryptography algorithms SM1, SM2, and SM3.

[0085] For more details, reference can be made to the foregoing description of Figure 1 and details will not be elaborated herein.

[0086] Implementing the embodiments of the present invention has the following beneficial effects:

[0087] The present invention provides a method and system for secure access of retrofit devices to a vehicle electronic system; by setting up a cloud certificate management system, it is ensured that each legitimate access device has a unique security certificate built-in, making the authentication of each retrofit device independent. Devices that fail to pass the review and are not authorized cannot be used when accessing the vehicle, thereby being able to better maintain the communication security between the retrofit device and the in-vehicle controller;

[0088] At the same time, the present invention implements a certificate life management mechanism for all pre-set certificates, and re-authorization will be performed every once in a while, which can effectively protect the timeliness and security of the certificates;

[0089] In addition, permission level management is provided for different after-installation devices, which can limit the functional permissions of different after-installation devices, avoid potential safety hazards caused by the arbitrary access of all in-vehicle controller resources by the after-installation devices after they are successfully connected to the vehicle, and improve safety and stability.

[0090] Moreover, the present invention uses a national cryptographic algorithm to generate the certificate used for device authentication, improving the controllability of the module.

[0091] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a device, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0092] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one or more flows or multiple flows and / or blocks Figure 1 one or more blocks or multiple blocks.

[0093] The above-disclosed is only a preferred embodiment of the present invention, and of course, it cannot be used to limit the scope of the rights of the present invention. Therefore, equivalent changes made according to the claims of the present invention still fall within the scope covered by the present invention.

Claims

1. A method for a post-installation device to safely access a vehicle electronic system, characterized in that, The steps include: Step S10, after the after-installed device is connected to the OBD interface, the encrypted information including the device ID and the pre-stored security certificate is sent to the vehicle gateway via the OBD interface, wherein the encryption adopts the national encryption algorithm; Step S11, the vehicle gateway initiates an authentication request to the cloud certificate management system according to the received encrypted content, wherein the authentication request includes the encrypted information from the after-sales device; Step S12: After receiving the authentication request, the cloud certificate management system decrypts the device ID and security certificate carried therein; Step S13, the cloud certificate management system verifies the legitimacy and validity of the device ID and security certificate. If the authentication result is a legal certificate and the certificate is within the valid life cycle, the verification is determined to be successful, and the vehicle gateway is notified, and the permission level of the current after-installed device is notified; otherwise, the verification is determined to be failed and the vehicle gateway is notified; Step S14, after receiving the verification success notification, the vehicle gateway processes the access request of the after-market device accordingly according to the permission level; the corresponding processing includes: executing the message of accessing the device, forwarding the message of accessing the device, or rejecting the message of accessing the device; after receiving the verification failure notification, the vehicle gateway rejects the after-market device from accessing the OBD interface.

2. The method according to claim 1, characterized in that Further including: Each after-installed device applies for a security certificate from the cloud certificate management system; The cloud certificate management system verifies the post-installed device and issues a security certificate. The security certificate is generated by a national secret algorithm and includes at least an identity identifier, key information, and validity period information. The national secret algorithm is SM2 and SM3. The after-installation device receives and stores the initial security certificate; A correspondence between each device ID, the corresponding security certificate, and the permission level is established in the cloud certificate management system.

3. The method according to claim 2, wherein Further including: Each after-installed device periodically or before use initiates a request to the cloud certificate management system to verify and update the certificate. The cloud certificate management system manages the certificates of all after-installed devices, including verification, update, and revocation.

4. The method of claim 3, further comprising: In the vehicle gateway, the execution operation scope corresponding to each permission level, the devices and network segments / network ports that can be accessed corresponding to each permission level are pre-determined, and the corresponding relationship table of "device / certificate / authority level" is recorded.

5. The method according to claim 4, wherein The messages between the vehicle terminal and the cloud certificate management system are encrypted using one of the national encryption algorithms SM1, SM2, and SM3.

6. A system for securely connecting a post-installation device to a vehicle electronic system, characterized in that, include: The after-installed device is used to send the encrypted information including the device ID and the pre-stored security certificate to the vehicle gateway via the OBD interface after accessing the OBD interface, wherein the encryption adopts the national secret algorithm; The in-vehicle gateway is set in a vehicle and is used to receive encrypted content from a retrofit device through an OBD interface and initiate an authentication request to the cloud certificate management system. The authentication request contains encrypted information from the retrofit device. It is also used to, after receiving a verification success notification, perform corresponding processing on the access request of the retrofit device according to the permission level. The corresponding processing includes: executing the message of the access device, forwarding the message of the access device, or rejecting the message of the access device. And it is used to, after receiving a verification failure notification, reject the retrofit device from accessing the OBD interface. The cloud certificate management system is used to, after receiving the authentication request, decrypt the device ID and security certificate carried therein, perform legality and validity verification processing on the device ID and security certificate. If the authentication result is a legal certificate and the certificate is within the valid life period, it determines that the verification is successful, notifies the in-vehicle gateway, and at the same time informs the permission level of the current retrofit device. Otherwise, it determines that the verification fails and notifies the in-vehicle gateway.

7. The system according to claim 6, characterized in that, The retrofit device further includes: A security certificate application unit for applying for a security certificate to the cloud certificate management system. A storage unit for receiving and storing the initial security certificate. A verification and update unit for periodically or before use initiating a request to the cloud certificate management system to verify and update the certificate.

8. The system according to claim 7, wherein The cloud certificate management system further includes: A security certificate generation unit for verifying the retrofit device and issuing a security certificate. The security certificate is generated by a national cryptography algorithm, and at least includes an identity identifier, key information, and validity period information. The national cryptography algorithms are SM2 and SM3. A correspondence relationship establishment unit for establishing the correspondence relationship between each device ID, the corresponding security certificate, and the permission level. A security certificate management unit for managing the certificates of all retrofit devices. The management includes: verification, update, and revocation.

9. The system according to claim 8, wherein the in-vehicle gateway further includes: A record storage unit for pre-determining in the in-vehicle gateway the execution operation scope corresponding to each permission level, the devices and network segments / network ports that can be accessed corresponding to each permission level, and recording the correspondence table of "device / certificate / permission level".

10. The system according to claim 9, characterized in that The message between the in-vehicle terminal and the cloud certificate management system is encrypted using one of the national cryptography algorithms SM1, SM2, and SM3.

Citation Information

Patent Citations

  • Equipment certification method and vehicle-mounted equipment

    CN109159758A