Vehicle-side firmware upgrade method, device, equipment and medium for digital key system
By implementing real-time interaction between the TSM component and the security chip locally on the vehicle side, the delay problem of security chip upgrade in poor signal environment is solved, ensuring the stable upgrade of the digital key system and the real-time update of the security strategy.
Patent Information
- Application Number
- CN202210796889.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-06
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2042-07-06
AI Technical Summary
Existing digital key systems cannot achieve real-time upgrades of security chips in environments with poor signals, resulting in delays or failures in the upgrade process.
The TSM components required for the upgrade are deployed locally on the vehicle side, and real-time interaction is carried out with the security chip through the vehicle-side gateway and local TSM components to establish a secure channel and identify upgrade conditions, ensuring a stable software upgrade process for the security chip.
It reduces the number of interactions between the cloud and the security chip, avoids delays during the upgrade process, ensures the stability and integrity of the security chip upgrade, and realizes real-time updates of vehicle-side security policies.
Smart Images

Figure CN115220762B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of digital key technology, and in particular to a vehicle-side firmware upgrade method, device, equipment, and medium for a digital key system. Background Art
[0002] In recent years, with the rapid development of Internet of Things and Internet of Vehicles technologies, the application scenarios of digital keys have become more and more numerous.
[0003] Digital keys are a business function built on an integrated security system that integrates the vehicle, mobile phone, and cloud. As business functions evolve in line with domestic and international standards, the security system needs to be continuously updated to ensure that the digital key business remains secure and effective. The vehicle's security policies are encapsulated in a security chip and exist in the form of security applications. Updating the security system means that the security software on the vehicle, mobile phone, and cloud need to be updated simultaneously. Existing technologies generally use online upgrades of security chips to update security applications for vehicle-side security policies, so that the security policies of the vehicle-side devices are updated as a whole following the version iterations of the mobile phone and cloud. This method allows vehicles already in the hands of users to enjoy the latest security protection in real time, ensuring the consistency and integrity of the digital key business.
[0004] However, in the existing upgrade and update methods, the digital key main module cannot guarantee real-time Internet access. For example, in an underground garage or tunnel with poor transmission signals, upgrading the security chip through the cloud trust management system (TSM) will cause a delay, resulting in the inability to complete the digital key security upgrade. Summary of the Invention
[0005] The present invention provides a vehicle-side firmware upgrade method, device, equipment and medium for a digital key system, which sinks the TSM components required for the upgrade to the local vehicle-side firmware to achieve real-time interaction between the local TSM components in the vehicle-side firmware and the security chip, ensuring that the upgrade of the vehicle-side security chip can be implemented stably.
[0006] In a first aspect, an embodiment of the present invention provides a method for upgrading vehicle-side firmware of a digital key system, wherein the vehicle-side firmware includes a vehicle-side gateway and a digital key main module, wherein the digital key main module includes a local TSM component and a security chip; the method includes:
[0007] The vehicle-side gateway downloads the upgrade software and authentication key from the upgrade platform;
[0008] The digital key main module receives the upgrade software and the authentication key;
[0009] The local TSM component determines whether the security chip enters the upgrade mode;
[0010] If so, establishing a secure channel between the local TSM component and the security chip;
[0011] Identifying whether the space of the security chip meets the upgrade conditions;
[0012] If so, the software of the security chip is upgraded through the secure channel.
[0013] Optionally, before the vehicle-side gateway downloads the upgrade software and authentication key from the upgrade platform, it also includes: a security chip upgrade preparation stage.
[0014] Optionally, the upgrade platform includes an over-the-air (OTA) platform and a digital key (DK) service platform; and the security chip upgrade preparation phase includes:
[0015] When the vehicle is powered on, the OTA platform reads the security element serial number SEID and software version number of the security chip through the vehicle-side gateway;
[0016] The vehicle-side gateway sends the SEID and software version number of the security chip to the OTA platform. The OTA platform maintains the software version of the digital key security chip and the version number information of each vehicle, and outputs whether there is an upgrade request through comparison;
[0017] If yes, the OTA platform sends the upgrade request to the vehicle gateway and notifies the user through the in-vehicle infotainment system (IVI);
[0018] If the IVI receives an update instruction from the user, it forwards the update request to the OTA platform through the vehicle-side gateway;
[0019] After receiving the updated software license, the OTA platform applies for an authentication key from the digital key DK business platform through the SEID. The authentication key is used for mutual authentication between the local TSM component and the security chip before establishing a secure channel to transmit the upgraded software.
[0020] Optionally, after the software upgrade of the security chip is completed, it also includes: the digital key main module returns the upgrade result to the vehicle-side gateway, and returns it to the OTA platform through the vehicle-side gateway, and the OTA platform synchronizes the SEID and software version in the upgraded vehicle to the digital key DK business platform.
[0021] Optionally, after the software upgrade of the security chip is completed, the method further includes: writing another authentication key into the security chip for use in establishing a secure channel when the security chip is upgraded next time.
[0022] Optionally, after the local TSM component determines whether the security chip enters the upgrade mode, the method further includes: if not, exiting the upgrade process.
[0023] Optionally, after identifying whether the space of the security chip meets the upgrade conditions, it also includes: if not, exiting the upgrade process and feeding back error information to the upgrade platform through the vehicle-side gateway.
[0024] In a second aspect, an embodiment of the present invention further provides a vehicle-side firmware upgrade device for a digital key system, wherein the vehicle-side firmware includes a vehicle-side gateway and a digital key main module, wherein the digital key main module includes a local TSM component and a security chip; the vehicle-side gateway is used to download upgrade software and an authentication key from an upgrade platform, the digital key main module is used to receive the upgrade software and the authentication key, and the local TSM component is used to determine whether the security chip enters an upgrade mode; the vehicle-side firmware upgrade device for the digital key system further includes:
[0025] a secure channel establishing unit, configured to establish a secure channel between the local TSM component and the security chip when the local TSM component determines that the security chip enters the upgrade mode;
[0026] an identification unit, configured to identify whether the space of the security chip meets an upgrade condition;
[0027] An upgrading unit is configured to upgrade the software of the security chip through the secure channel when the identifying unit identifies that the space of the security chip meets an upgrading condition.
[0028] In the third aspect, an embodiment of the present invention also provides a vehicle-side firmware upgrade device for a digital key system, comprising: one or more processors; a memory for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the vehicle-side firmware upgrade method for the digital key system as described in the first aspect.
[0029] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored, which, when executed by a processor, implements the vehicle-side firmware upgrade method of the digital key system as described in the first aspect.
[0030] The technical solution of the embodiment of the present invention is to download the upgrade software and authentication key from the upgrade platform through the vehicle-side gateway, the digital key main module receives the upgrade software and authentication key, and the local TSM component determines whether the security chip has entered the upgrade mode. If so, a secure channel is established between the local TSM component and the security chip, and whether the space of the security chip meets the upgrade conditions is identified. If so, the software of the security chip is upgraded through the secure channel. By sinking the TSM components required for the upgrade to the local vehicle-side, the local TSM components on the vehicle side interact with the security chip in real time, reducing the number of interactions between the cloud and the security chip, ensuring the smooth progress of the upgrade process, and avoiding the situation where the digital key main module upgrades the security chip through the cloud TSM, resulting in a delay that makes the upgrade incomplete. The entire process of the security chip upgrade can be monitored to ensure that the upgrade of the vehicle-side security chip can be implemented stably. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 A flowchart of a vehicle-side firmware upgrade method for a digital key system provided by an embodiment of the present invention;
[0032] Figure 2 A flowchart of a vehicle-side firmware upgrade method for a digital key system provided by an embodiment of the present invention;
[0033] Figure 3 A detailed flowchart of a vehicle-side firmware upgrade method for a digital key system provided by an embodiment of the present invention;
[0034] Figure 4 A structural block diagram of a vehicle-side firmware upgrade device for a digital key system provided by an embodiment of the present invention;
[0035] Figure 5 A schematic diagram of the hardware structure of a device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0036] The present invention will be further described in detail below with reference to the accompanying drawings and examples. It will be understood that the specific embodiments described herein are intended only to illustrate the present invention and are not intended to limit the present invention. It should also be noted that, for ease of description, the accompanying drawings only illustrate portions relevant to the present invention, not all structures.
[0037] Example 1
[0038] Figure 1This is a flowchart of a method for upgrading vehicle-side firmware for a digital key system, provided in an embodiment of the present invention. This embodiment is applicable to updating vehicle-side security applications in a digital key system. This method can be performed by a vehicle-side firmware upgrade device for the digital key system, which can be implemented using software and / or hardware. This device can be deployed in a terminal device, server, or vehicle controller.
[0039] Among them, the vehicle-side firmware includes the vehicle-side gateway and the digital key main module, and the digital key main module includes the local TSM component and the security chip.
[0040] like Figure 1 As shown, a vehicle-side firmware upgrade method for a digital key system provided in Embodiment 1 of the present invention includes the following steps:
[0041] S110. The vehicle-side gateway downloads the upgrade software and authentication key from the upgrade platform.
[0042] The vehicle-side gateway is the core control device of the automotive network system, responsible for coordinating protocol conversion, data exchange, and fault diagnosis between bus networks and data networks with different structures and characteristics. The upgrade platform can be understood as a service download platform that integrates multiple security and business application software to provide secure and stable system firmware and application upgrade services for vehicle-side devices. For example, when upgrading the vehicle-side firmware of the digital key system, the vehicle-side gateway downloads the updated upgrade software and the authentication keys required for data encryption and decryption from the upgrade platform. It should be noted that, based on current technological development capabilities, the TSM component in the embodiments of the present invention includes, to a certain extent, a local TSM component located on the vehicle side and a cloud-based TSM component embedded in the digital key platform. The authentication key is generated with the assistance of a cloud-based trust management system (i.e., the cloud-based TSM component) embedded in the digital key platform and supporting the security chip. However, this does not affect the technical purpose of the present invention to reduce the number of interactions between the cloud and the security chip.
[0043] S120: The digital key main module receives the upgrade software and authentication key.
[0044] The Digital Key Master Module, installed in the vehicle, is the communication unit that enables wireless data transmission between the vehicle and the terminal device. For example, the Digital Key Master Module in the vehicle-side firmware uses wireless communication technology to receive the upgrade software and authentication key downloaded from the vehicle-side gateway.
[0045] S130: The local TSM component determines whether the security chip has entered the upgrade mode; if so, a secure channel is established between the local TSM component and the security chip.
[0046] Among them, the local TSM component is a trust management system installed on the vehicle side; and the security chip is equivalent to a trusted platform, which encapsulates the vehicle-side security policies in the security chip and exists in the form of security applications. By iteratively updating the security applications in the security chip according to the cloud version, it ensures that the vehicles in the hands of users can enjoy the latest security protection in real time.
[0047] In this embodiment, when the digital key main module receives the upgrade software and authentication key, it will judge the status of the security chip through the local TSM component to determine whether the security chip has entered the upgrade mode. When it is determined that it has entered the upgrade mode, a secure channel between the local TSM component and the security chip will be established based on the authentication key to enable the local TSM component to interact with the security chip in real time.
[0048] Based on the above embodiment, after the local TSM component determines whether the security chip enters the upgrade mode, the following further includes: if not, exiting the upgrade process.
[0049] It can be understood that when the digital key main module receives the upgrade software and authentication key, it will judge the status of the security chip through the local TSM component to determine whether the security chip has entered the upgrade mode. If it is determined that the security chip has not entered the upgrade mode, it will exit the upgrade process.
[0050] S140: Identify whether the space of the security chip meets the upgrade conditions; if so, upgrade the software of the security chip through a secure channel.
[0051] In this embodiment, after the security channel is established, the storage space of the security chip is identified to determine whether the storage space of the security chip meets the conditions required for upgrading the software. If the preset conditions for the upgrade are met, the software of the security chip is systematically upgraded through the established security channel, ensuring that the upgrade of the vehicle-side security chip can be implemented stably.
[0052] Based on the above embodiment, after identifying whether the space of the security chip meets the upgrade conditions, it also includes: if not, exiting the upgrade process and feeding back error information to the upgrade platform through the vehicle-side gateway.
[0053] For example, after the security channel is established, the storage space of the security chip will be identified to determine whether the storage space of the security chip meets the conditions required for upgrading the software. If it does not meet the preset storage space conditions required for the upgrade, the upgrade process will be exited and an error message will be issued. The error message will be returned to the vehicle-side gateway through the digital key main module, and finally the error message will be fed back to the upgrade platform through the vehicle-side gateway to avoid the failure of the security chip software upgrade due to insufficient memory problems, further ensuring the reliability of the vehicle-side security chip upgrade.
[0054] The technical solution of this embodiment downloads the upgrade software and authentication key from the upgrade platform through the vehicle-side gateway. The digital key main module receives the upgrade software and authentication key. The local TSM component determines whether the security chip has entered upgrade mode. If so, it establishes a secure channel between the local TSM component and the security chip, and determines whether the security chip's space meets the upgrade conditions. If so, the security chip software is upgraded through the secure channel. By sinking the TSM components required for the upgrade to the local vehicle-side, the local vehicle-side TSM components and the security chip interact in real time, reducing the number of interactions between the cloud and the security chip, ensuring the smooth progress of the upgrade process, and avoiding the situation where the digital key main module upgrades the security chip through the cloud TSM, which may cause the upgrade to fail. The entire security chip upgrade process can also be monitored to ensure that the upgrade of the vehicle-side security chip can be implemented stably.
[0055] Example 2
[0056] Figure 2 This is a flowchart of a method for upgrading vehicle-side firmware of a digital key system provided by an embodiment of the present invention. This embodiment further refines the above-mentioned technical solution and is applicable to updating vehicle-side security applications of a digital key system. This method can be executed by a vehicle-side firmware upgrade device of a digital key system.
[0057] On the basis of the above embodiment, before the vehicle-side gateway downloads the upgrade software and the authentication key from the upgrade platform, it also includes: a security chip upgrade preparation stage.
[0058] like Figure 2 As shown, a vehicle-side firmware upgrade method for a digital key system provided in the second embodiment of the present invention includes the following steps:
[0059] Specifically, the upgrade platform includes the over-the-air download technology OTA platform and the digital key DK business platform.
[0060] S210: When the vehicle is powered on, the OTA platform reads the security element serial number SEID and software version number of the security chip through the vehicle-side gateway.
[0061] The DK can be understood as a digital key, and vehicle power-on can be understood as a state in which the vehicle's low-voltage main switch is closed and there is no fault indication on the instrument panel. The secure element serial number (SEID) is equivalent to an identification code and is used to authenticate each secure element. The software version number refers to the method used to set the software version number. The software version number naming format is generally GNU-style version number naming format, Windows-style version number naming format, and Net Framework-style version number naming format. This embodiment does not specifically limit the software version number naming format of the security chip.
[0062] In this embodiment, when the vehicle is fully powered on, the over-the-air download technology OTA platform will read the security element serial number and software version number of the security chip through the vehicle network system to determine the basic information of the security chip. Finally, the local TSM component in the digital key main module will establish communication with the security chip, integrate the information, and transmit it back to the vehicle-side gateway through the network, so as to make accurate judgments on the upgrade of the security chip.
[0063] S220. The vehicle-side gateway sends the SEID and software version number of the security chip to the OTA platform. The OTA platform maintains the software version of the digital key security chip and the version number information of each vehicle, and outputs whether there is an upgrade request through comparison.
[0064] It is understandable that the vehicle-side gateway can send the SEID and software version number of the security chip to the OTA platform through the 4G channel. Of course, the information can also be transmitted through other methods. This embodiment does not specifically limit the specific transmission method.
[0065] S230: If yes, the OTA platform sends the upgrade request to the vehicle gateway and notifies the user through the in-vehicle infotainment system (IVI).
[0066] In this embodiment, the OTA platform will maintain the integrated information of the read security chip and the version signal corresponding to each vehicle, and check whether there is an upgrade request by comparison. If there is an upgrade request, the OTA platform will send this request to the vehicle-side gateway and issue a prompt to the user through the in-vehicle infotainment system IVI. The prompt method can be a voice prompt, a pop-up prompt on the central control display, etc.
[0067] S240: If the IVI receives the user's update instruction, it forwards the update request to the OTA platform through the vehicle-side gateway.
[0068] The in-vehicle infotainment system IVI may receive the user's update command through user voice communication, touch feedback, or gesture commands. In this embodiment, the method for the IVI to receive the user's update command is not specifically limited.
[0069] After S250 and OTA platforms receive the update software license, they apply for an authentication key from the digital key DK business platform through SEID. The authentication key is used for mutual authentication between the local TSM component and the security chip before establishing a secure channel to transmit the upgraded software.
[0070] It is understandable that the above steps S210 to S250 belong to the security chip upgrade preparation stage. Figure 2 The second embodiment of the present invention provides a method for upgrading vehicle-side firmware of a digital key system, further comprising the following steps:
[0071] S260 and the vehicle-side gateway download the upgrade software and authentication key from the upgrade platform.
[0072] S270: The digital key main module receives the upgrade software and authentication key.
[0073] S280: The local TSM component determines whether the security chip has entered the upgrade mode; if so, a secure channel is established between the local TSM component and the security chip.
[0074] S290: Identify whether the space of the security chip meets the upgrade conditions; if so, upgrade the software of the security chip through the secure channel.
[0075] The technical solution of this embodiment is to set a security chip upgrade preparation stage in the vehicle-side firmware upgrade method of the digital key system. When the entire vehicle is powered on, the OTA platform reads the security element serial number SEID and software version number of the security chip through the vehicle-side gateway to determine the basic information of the security chip. Finally, the local TSM component located in the digital key main module will establish communication with the security chip, integrate the information, and then transmit it back to the vehicle-side gateway through the network. Based on the OTA platform, the integrated information of the read security chip and the corresponding version signal of each vehicle are compared to confirm whether there is an upgrade request. If there is an upgrade request, the request content will be prompted to the user through the IVI system. After receiving the user's update instruction, the update request will be forwarded to the OTA platform, and the authentication key will be applied for from the digital key DK business platform through SEID to ensure the effectiveness of the security chip upgrade. Subsequently, the OTA platform obtains the authentication key and downloads it together with the upgrade software to the vehicle-side gateway. The vehicle-side gateway is connected to the digital key main module through the vehicle bus. The digital key main module receives the upgrade software and authentication key. When the local TSM component determines that the security chip enters the upgrade mode, it establishes a secure channel between the local TSM component and the security chip through standard instructions and authentication of the authentication key, and upgrades the application of the security chip through the secure channel. By sinking the TSM components required for the upgrade to the local vehicle, the local TSM components on the vehicle side interact with the security chip in real time, reducing the number of interactions between the cloud and the security chip, ensuring the smooth progress of the upgrade process, and avoiding the situation where the digital key main module cannot complete the upgrade due to delays when upgrading the security chip through the cloud TSM.
[0076] Based on the above embodiment, after the software upgrade of the security chip is completed, it also includes: the digital key main module returns the upgrade result to the vehicle-side gateway, and returns it to the OTA platform through the vehicle-side gateway. The OTA platform synchronizes the SEID and software version in the upgraded vehicle to the digital key DK business platform.
[0077] In this embodiment, after the security chip upgrade is completed, the digital key will feed back the upgrade results to the vehicle-side gateway and return them to the OTA platform through the gateway, so that data interoperability can be achieved. Finally, the OTA platform will synchronize the security element serial number SEID and software version number corresponding to the upgraded vehicle's security chip to the digital key DK business platform, so that the security software on the vehicle, terminal and cloud can be updated synchronously. The vehicle in the hands of the user can enjoy the latest security protection in real time, ensuring the consistency and integrity of the digital key business.
[0078] Based on the above embodiment, after the software upgrade of the security chip is completed, the method further includes: writing another authentication key into the security chip for use in establishing a secure channel when the security chip is upgraded next time.
[0079] In this embodiment, after the software upgrade of the security chip is completed, another authentication key is written into the security chip to be used to establish a secure channel for the next upgrade. During the next update, there is no need to send the update request to the OTA platform through the vehicle-side gateway, and then apply for the authentication key from the digital key DK business platform through the element serial number SEID of the security element. This can improve the efficiency of the next update of the security chip and save time for users.
[0080] Figure 3 The detailed flow chart of the vehicle-side firmware upgrade method of a digital key system provided by the embodiment of the present invention is a further detailed description of this embodiment. Figure 3 As shown in the figure, the vehicle-side firmware upgrade process of the digital key system can be divided into the preparation stage, the security channel establishment stage and the application installation stage.
[0081] Phase 1: Preparation
[0082] For example, when the vehicle is powered on, the OTA platform reads the security chip's secure element serial number (SEID) and software version number through the vehicle-side gateway. Communication is established between the digital key main module and the security chip, and the SEID and software version number information are integrated and fed back to the vehicle-side gateway. The vehicle-side gateway sends the security chip's SEID and software version number to the OTA platform through a designated channel, such as a 4G channel. The OTA platform maintains the software version of the digital key security chip and the version number information for each vehicle, and compares and checks whether there is an upgrade request. If no request is received, a "no request" message is returned to the vehicle-side gateway. If a request is received, an upgrade request is returned to the vehicle-side gateway, and the user is prompted to select the update application through the IVI.
[0083] After the user chooses to update the application, the update request is forwarded to the OTA platform through the vehicle-side gateway. After receiving the update software license, the OTA platform applies for the corresponding authentication key from the digital key DK business platform through the SEID of the security chip. The key is used by the local TSM component in the vehicle-side digital key main module and the security chip to establish a secure channel for mutual authentication before transmitting the upgraded software. After obtaining the authentication key, the OTA platform downloads it along with the application upgrade software to the vehicle-side gateway. The vehicle-side gateway transmits the upgraded software to the digital key main module using the long message strategy. After receiving it, the digital key main module forwards it to the local TSM component for application storage and provides the vehicle's parking status to the local TSM component. The local TSM component determines the actual conditions and notifies the security chip to enter the upgrade mode.
[0084] At this point, the preparation phase for the security chip upgrade has been completed.
[0085] Phase 2: Establishing a secure channel
[0086] For example, if the authentication key is successfully authenticated, a secure channel can be established between the local TSM component and the security chip using instructions from the All-Digital Services and Devices Standard Platform (GP) specification. Other specifications and standards can also be used to establish a secure channel, which is not specifically limited in this embodiment. After the secure channel is established, the system checks whether the storage space within the security chip meets the upgrade requirements. If so, the application installation process continues. If not, a message indicating insufficient storage space is displayed, and an error message is returned to the vehicle gateway through the Digital Key main module, and ultimately to the OTA platform.
[0087] Phase 3: Application installation phase
[0088] For example, the local TSM component and the security chip can complete application installation via GP standard instructions, and upgrade applications one by one based on the number of upgrade applications included in the downloaded upgrade software. The upgrade process can generate application download instructions, send multiple application instructions to the security chip, and then send multiple instruction feedback to the digital key main module. Based on the instruction feedback, the application file is loaded into the security chip, and the security chip then feeds the secure application file back to the digital key main module. After all applications are upgraded, another authentication key is written to the security chip to establish a secure channel for use during the next security chip upgrade.
[0089] After the security chip upgrade is completed, the digital key main module needs to return the upgrade results to the vehicle-side gateway, and then return them to the OTA platform through the vehicle-side gateway. The OTA platform needs to synchronize the SEID and software version in the upgraded vehicle to the digital key DK business platform to ensure the consistency and integrity of the digital key business. At this point, the vehicle-side firmware upgrade process for the digital key system has been completed.
[0090] In this embodiment, by setting three stages corresponding to the preparation stage, the security channel establishment stage and the application installation stage in the vehicle-side firmware upgrade process of the digital key system, real-time interaction between the local TSM components on the vehicle side and the security chip is achieved, and the TSM components required for the upgrade are sunk to the local vehicle side, reducing the number of interactions between the cloud and the security chip, ensuring the smooth progress of the upgrade process, and avoiding the situation where the digital key main module cannot complete the upgrade due to delays when upgrading the security chip through the cloud TSM.
[0091] Example 3
[0092] Figure 4 A structural schematic diagram of a vehicle-side firmware upgrade device for a digital key system provided in an embodiment of the present invention. The vehicle-side firmware upgrade device for a digital key system can be applicable to situations where a terminal device upgrades the vehicle-side firmware of a digital key system, wherein the device can be implemented by software and / or hardware and is generally integrated on the terminal device.
[0093] like Figure 4 As shown, the device includes: a secure channel establishing unit 31, an identifying unit 32 and an upgrading unit 33;
[0094] The secure channel establishing unit 31 is configured to establish a secure channel between the local TSM component and the security chip when the local TSM component determines that the security chip enters the upgrade mode;
[0095] An identification unit 32 is used to identify whether the space of the security chip meets the upgrade conditions;
[0096] The upgrading unit 33 is configured to upgrade the software of the security chip through a secure channel when the identifying unit identifies that the space of the security chip meets the upgrading condition.
[0097] The technical solution of this embodiment establishes a secure channel between the local TSM component and the security chip when the local TSM component determines that the security chip has entered upgrade mode, and identifies whether the space in the security chip meets the upgrade conditions. When the identification unit identifies that the space in the security chip meets the upgrade conditions, the security chip software is upgraded through the secure channel. By enabling real-time interaction between the local TSM component on the vehicle side and the security chip, the TSM components required for the upgrade are localized on the vehicle side, reducing the number of interactions between the cloud and the security chip, ensuring the smooth progress of the upgrade process, and avoiding the situation where the digital key main module upgrades the security chip through the cloud TSM, resulting in a delay that prevents the upgrade from being completed. The entire process of the security chip upgrade can also be monitored to ensure that the upgrade of the vehicle-side security chip can be implemented stably.
[0098] Based on the above embodiment, it further includes: an upgrade preparation unit.
[0099] Upgrade preparation unit, including:
[0100] The reading unit is used to read the security element serial number (SEID) and software version number of the security chip through the vehicle gateway when the vehicle is powered on.
[0101] The comparison unit is used to send the SEID and software version number of the security chip to the OTA platform after the vehicle-side gateway sends the OTA platform. The OTA platform maintains the software version of the digital key security chip and the version number information of each vehicle, and outputs whether there is an upgrade request through comparison;
[0102] The prompt unit is used to send the upgrade request to the vehicle gateway when the OTA platform determines that there is an upgrade request, and to prompt the user through the in-vehicle infotainment system (IVI);
[0103] The request forwarding unit is used to forward the update request to the OTA platform through the vehicle-side gateway when the IVI receives the user's update instruction;
[0104] The key application unit is used to apply for an authentication key from the digital key DK business platform through SEID after the OTA platform receives the updated software license. The authentication key is specifically used for mutual authentication between the local TSM component and the security chip before establishing a secure channel to transmit the upgraded software.
[0105] On the basis of the above embodiment, after the upgrading unit 33, the following is further included:
[0106] The synchronization unit is used for the digital key main module to return the upgrade results to the vehicle-side gateway, and then return them to the OTA platform through the vehicle-side gateway. The OTA platform synchronizes the SEID and software version in the upgraded vehicle to the digital key DK business platform.
[0107] On the basis of the above embodiment, after the upgrading unit 33, the following is further included:
[0108] The writing unit is used to write another authentication key into the security chip for use in establishing a secure channel when the security chip is upgraded next time.
[0109] On the basis of the above embodiment, before the secure channel establishing unit 31, the following further comprises:
[0110] The exit process unit is used to exit the upgrade process when the local TSM component determines that the security chip has not entered the upgrade mode.
[0111] On the basis of the above embodiment, after the identification unit 32, the following further comprises:
[0112] The feedback unit is used to exit the upgrade process and feedback error information to the upgrade platform through the vehicle-side gateway when the identification unit 32 identifies that the space of the security chip does not meet the upgrade conditions.
[0113] The vehicle-side firmware upgrade device of the digital key system provided in an embodiment of the present invention can execute the vehicle-side firmware upgrade method of the digital key system provided in any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution method.
[0114] Example 4
[0115] Figure 5 This is a schematic diagram of the hardware structure of a device provided in the fourth embodiment of the present invention. Figure 5 As shown, the terminal device provided by the fourth embodiment of the present invention includes: one or more processors 41 and a storage device 42; the processor 41 in the terminal device can be one or more, Figure 5 Take a processor 41 as an example; the storage device 42 is used to store one or more programs; the one or more programs are executed by one or more processors 41, so that one or more processors 41 implement the vehicle-side firmware upgrade method of the digital key system as any one of the embodiments of the present invention.
[0116] The terminal device may further include: an input device 43 and an output device 44 .
[0117] The processor 41, storage device 42, input device 43 and output device 44 in the terminal device can be connected via a bus or other means. Figure 5 The bus connection is taken as an example.
[0118] The storage device 42 in the terminal device is a computer-readable storage medium that can be used to store one or more programs. The program can be a software program, a computer executable program, and a module, such as the program instructions / modules corresponding to the vehicle-side firmware upgrade method of the digital key system provided in the first embodiment of the present invention (for example, the attached Figure 3 The modules in the vehicle-side firmware upgrade device for the digital key system shown include: a secure channel establishment unit 31, an identification unit 32, and an upgrade unit 33. A processor 41 executes the software programs, instructions, and modules stored in a storage device 42 to execute various functional applications and data processing of the terminal device, thereby implementing the vehicle-side firmware upgrade method for the digital key system in the above-mentioned method embodiment.
[0119] The storage device 42 may include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function; the data storage area may store data created based on the use of the terminal device, etc. Furthermore, the storage device 42 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state memory device. In some instances, the storage device 42 may further include a memory remotely located relative to the processor 41, and such remote memory may be connected to the device via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0120] The input device 43 may be used to receive input digital or character information and generate key signal input related to user settings and function control of the terminal device. The output device 44 may include a display device such as a display screen.
[0121] Furthermore, when one or more programs included in the terminal device are executed by one or more processors 41, the programs perform the following operations:
[0122] When the local TSM component determines that the security chip enters the upgrade mode, a secure channel is established between the local TSM component and the security chip; whether the space of the security chip meets the upgrade conditions is identified; when the identification unit identifies that the space of the security chip meets the upgrade conditions, the software of the security chip is upgraded through the secure channel.
[0123] Example 5
[0124] A fifth embodiment of the present invention further provides a storage medium containing computer-executable instructions. When the computer-executable instructions are executed by a computer processor, the computer-executable instructions are used to perform a method for upgrading vehicle-side firmware of a digital key system. The method includes:
[0125] The vehicle-side gateway downloads the upgrade software and authentication key from the upgrade platform;
[0126] The digital key main module receives the upgraded software and authentication key;
[0127] The local TSM component determines whether the security chip has entered upgrade mode;
[0128] If so, a secure channel between the local TSM component and the security chip is established;
[0129] Identify whether the space of the security chip meets the upgrade conditions;
[0130] If so, the software of the security chip is upgraded through a secure channel.
[0131] Of course, the computer-executable instructions provided in the storage medium of the embodiment of the present invention are not limited to the above-described method operations, but can also perform the related operations of the vehicle-side firmware upgrade method of the digital key system provided in any embodiment of the present invention.
[0132] Through the above description of the embodiments, those skilled in the art will clearly understand that the present invention can be implemented using software and necessary general-purpose hardware. Of course, it can also be implemented using hardware, but in many cases the former is a more preferred embodiment. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk, or optical disk, and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods of various embodiments of the present invention.
[0133] It is worth noting that in the embodiment of the above-mentioned search device, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.
[0134] Note that the above are only preferred embodiments of the present invention and the technical principles employed. Those skilled in the art will appreciate that the present invention is not limited to the specific embodiments herein, and that various obvious changes, readjustments, and substitutions are possible for those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments and may include many other equivalent embodiments without departing from the scope of the present invention. The scope of the present invention is determined by the scope of the appended claims.
Claims
1. A vehicle-side firmware upgrade method for a digital key system, characterized in that: The vehicle-side firmware includes a vehicle-side gateway and a digital key main module, and the digital key main module includes a local TSM component and a security chip; The vehicle-side firmware upgrade method of the digital key system includes: The vehicle-side gateway downloads the upgrade software and authentication key from the upgrade platform. The authentication key is used for mutual authentication between the local TSM component in the vehicle-side digital key main module and the security chip before establishing a secure channel to transmit the upgrade software; The digital key master module receives the upgrade software and the authentication key, and after receiving the upgrade software and the authentication key, the digital key master module forwards the upgrade software and the authentication key to the local TSM component for application storage, and provides the parking status of the vehicle to the local TSM component; the local TSM component determines whether the security chip enters the upgrade mode; If so, establishing a secure channel between the local TSM component and the security chip; Identifying whether the space of the security chip meets the upgrade conditions; If so, the software of the security chip is upgraded through the secure channel.
2. The vehicle-side firmware upgrade method of the digital key system according to claim 1, characterized in that: Before the vehicle-side gateway downloads the upgrade software and the authentication key from the upgrade platform, the method further includes: Security chip upgrade preparation stage.
3. The vehicle-side firmware upgrade method of the digital key system according to claim 2, characterized in that: The upgrade platform includes an over-the-air (OTA) platform and a digital key (DK) service platform. The security chip upgrade preparation phase includes: When the vehicle is powered on, the OTA platform reads the security element serial number SEID and software version number of the security chip through the vehicle-side gateway; The vehicle-side gateway sends the SEID and software version number of the security chip to the OTA platform. The OTA platform maintains the software version of the digital key security chip and the version number information of each vehicle, and outputs whether there is an upgrade request through comparison; If yes, the OTA platform sends the upgrade request to the vehicle gateway and notifies the user through the in-vehicle infotainment system (IVI); If the IVI receives an update instruction from the user, it forwards the update request to the OTA platform through the vehicle-side gateway; After receiving the updated software license, the OTA platform applies for an authentication key from the digital key DK business platform through the SEID. The authentication key is used for mutual authentication between the local TSM component and the security chip before establishing a secure channel to transmit the upgraded software.
4. The vehicle-side firmware upgrade method of the digital key system according to claim 3, characterized in that: After the software upgrade of the security chip is completed, the method further includes: The digital key main module returns the upgrade result to the vehicle-side gateway, and returns it to the OTA platform through the vehicle-side gateway. The OTA platform synchronizes the SEID and software version in the upgraded vehicle to the digital key DK business platform.
5. The vehicle-side firmware upgrade method of the digital key system according to claim 1, characterized in that: After the software upgrade of the security chip is completed, the method further includes: Another authentication key is written into the security chip for use in establishing a secure channel when the security chip is upgraded next time.
6. The vehicle-side firmware upgrade method of the digital key system according to claim 1, characterized in that: After the local TSM component determines whether the security chip enters the upgrade mode, the method further includes: If not, exit the upgrade process.
7. The vehicle-side firmware upgrade method of the digital key system according to claim 1, characterized in that: After identifying whether the space of the security chip meets the upgrade condition, the method further includes: If not, exit the upgrade process and feedback error information to the upgrade platform through the vehicle-side gateway.
8. A vehicle-side firmware upgrade device for a digital key system, characterized in that: The vehicle-side firmware includes a vehicle-side gateway and a digital key main module, and the digital key main module includes a local TSM component and a security chip; the vehicle-side gateway is used to download upgrade software and authentication keys from the upgrade platform, and the authentication key is used for mutual authentication between the local TSM component in the vehicle-side digital key main module and the security chip before establishing a secure channel to transmit the upgrade software. The digital key main module is used to receive the upgrade software and the authentication key. After receiving the upgrade software and the authentication key, the digital key main module forwards them to the local TSM component for application storage and provides the vehicle's parking status to the local TSM component. The local TSM component is used to determine whether the security chip has entered the upgrade mode; The vehicle-side firmware upgrade device of the digital key system further includes: a secure channel establishing unit, configured to establish a secure channel between the local TSM component and the security chip when the local TSM component determines that the security chip enters the upgrade mode; an identification unit, configured to identify whether the space of the security chip meets an upgrade condition; An upgrading unit is configured to upgrade the software of the security chip through the secure channel when the identifying unit identifies that the space of the security chip meets an upgrading condition.
9. A vehicle-side firmware upgrade device for a digital key system, characterized in that: include: one or more processors; a memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the vehicle-side firmware upgrade method of the digital key system as described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the vehicle-side firmware upgrade method of the digital key system as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Security chip firmware updating method and device
CN110688648A
Security authentication method and electronic equipment
CN113821787A