A vehicle network data encryption system and an encrypted vehicle network chip

By introducing smart password keys and dominant chips into the in-vehicle network, combined with NMV storage components and multiple encryption algorithm modules, the problems of long hardware encryption development cycle, high cost and easy data loss are solved, and efficient and secure in-vehicle network data encryption is achieved.

CN115766150BActive Publication Date: 2025-09-23SOUTHWEST UNIV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211381220.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-06
Publication Date
2025-09-23
Estimated Expiration
2042-11-06

AI Technical Summary

Technical Problem

Existing in-vehicle chips require redesigning circuit boards and passing testing and verification when performing hardware encryption, which results in a long development cycle, high costs, and poor compatibility. The chip installed in the smart password key is prone to data loss, has a single function, and the network system can only perform simple storage and encryption.

Method used

An in-vehicle network data encryption system is designed, which includes an intelligent password key and a dominant chip, a built-in NMV storage element, an encryption processing unit and multiple algorithm modules. It supports the national secret algorithm and improves security through the SM2 algorithm module. The session key module temporarily generates and then destroys the session key to save storage space.

Benefits of technology

It realizes the secure storage and encryption of data, improves the security of the vehicle network, meets the requirements of national encryption algorithms, reduces development costs, has good compatibility, avoids data loss, and meets real-time encryption needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115766150B_ABST
    Figure CN115766150B_ABST
Patent Text Reader

Abstract

The present invention provides an in-vehicle network data encryption system and an encrypted in-vehicle network chip, which relate to the field of network information equipment. The system includes a smart password key and a dominant chip. The dominant chip is installed inside the smart password key, and an NMV storage element is provided inside the dominant chip. A device authentication module is electrically connected to the bottom of the smart password key near the dominant chip. An application management module is electrically connected to the bottom of the smart password key near the device authentication module. One end of the application management module is electrically connected to a container management module. The dominant chip in the present invention plans and modifies the internal overall system, solving the problems in existing equipment where many chips are installed in the smart password key, and data loss within the system may occur if the smart password key loses power, and the chip's network system can only perform simple data storage and encryption, with relatively single functions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network information equipment, and in particular to an in-vehicle network data encryption system and an encrypted in-vehicle network chip. Background Art

[0002] Patent No. CN 111291425 A discloses a chip protection method, device, storage medium and vehicle-mounted chip, which belongs to the field of chip security technology. The method includes: when the chip is started, obtaining stored historical attack information, the historical attack information at least includes the number of attacks and attack types before the chip is started; detecting whether the historical attack information meets the trigger of the first security mode.

[0003] If the trigger condition is met, the first security mode is used to limit some functions of the chip; if the historical attack information meets the trigger condition, the chip operates in the first security mode. In the embodiment of the present application, the first security mode limits some functions of the chip. Therefore, operating the chip in the first security mode can prevent information leakage in the chip. In addition, because the chip can operate in the first security mode, the time and cost of continuous large-scale attack attempts are greatly increased, the attack difficulty is increased, and thus the security of the chip is greatly improved.

[0004] The existing technology has protected the on-board chips to a certain extent, but it still has the following problems: 1. Many chips in existing devices are installed in smart password keys. If the smart password key loses power, the data within the system may be lost, and the chip's network system can only perform simple storage and encryption of data. It has relatively simple functions and cannot organize the data, which leads to relatively messy system data, so it needs to be planned; 2. Currently, most vehicle controllers are batch products of foreign manufacturers such as Bosch, Delphi, and Continental. The software is not open to Chinese automobile manufacturers, and it is difficult to modify the software. The use of software encryption requires modifying the underlying software of the controller. The encryption algorithm takes a long time to execute, and it is difficult to meet real-time requirements. If hardware encryption is used, there is a dedicated encryption chip, but it only processes digital signals. Hardware needs to be added between the controller and the communication transceiver, and the circuit board needs to be redesigned and verified through various tests. The development cycle is long, the cost is high, and the compatibility is poor. Summary of the Invention

[0005] In response to the shortcomings of the existing technology, the present invention provides an in-vehicle network data encryption system and an encrypted in-vehicle network chip, which solves the problem that when hardware encryption is used, there is a dedicated encryption chip, but it only processes digital signals, and hardware needs to be added between the controller and the communication transceiver. The circuit board needs to be redesigned and passed various tests and verifications, which results in a long development cycle, high cost and poor compatibility. At the same time, it solves the problem that many chips in existing equipment are installed in smart password keys, and if the smart password key loses power, the data within the system may be lost, and the chip's network system can only perform simple storage and encryption of data, and has relatively single functions.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: an in-vehicle network data encryption system and an encrypted in-vehicle network chip, including a smart password key and a dominant chip, the smart password key is equipped with a dominant chip, the dominant chip is provided with an NMV storage element, the smart password key is electrically connected to a device authentication module near the bottom of the dominant chip, the smart password key is electrically connected to an application management module near the bottom of the device authentication module, one end of the application management module is electrically connected to a container management module, the smart password key is provided with a file management module near the bottom of the container management module, one end of the container management module is electrically connected to an SM2 algorithm module and a session key module, the smart password key is provided with a cryptographic hash algorithm module near the top of the SM2 algorithm module, and one end of the session password module is electrically connected to an SM4 encryption / decryption module and a message authentication code module.

[0007] Preferably, the leading chip is provided with an encryption processing unit, the encryption processing unit is provided with an encryption authentication system, the leading chip is provided with an algorithm module, and the algorithm module includes an encryption algorithm repository and a private key repository.

[0008] Preferably, the encryption algorithm repository includes a hash algorithm, a symmetric algorithm, and an asymmetric algorithm, and the private key repository includes an intra-domain group key and an inter-domain session key.

[0009] Preferably, one end of the encryption processing unit is bidirectionally connected to the front-stage data cache unit, the other end of the encryption processing unit is bidirectionally connected to the back-stage data cache unit, and one end of the back-stage data cache unit is connected to the network adapter unit.

[0010] Preferably, the network adapter unit includes a 485 communication adapter, a K communication adapter is provided inside the network adapter unit near the bottom of the 485 communication adapter, a LIN communication adapter is provided inside the network adapter unit near the bottom of the K communication adapter, a FlexRax communication adapter is provided inside the network adapter unit near the bottom of the LIN communication adapter, and a 232 communication adapter is provided inside the network adapter unit near the bottom of the FIexRax communication adapter.

[0011] Preferably, the input terminal group of the front-stage data cache unit is connected to an external signal source, the communication terminal group of the network adapter unit is connected to an external bus, and an RX terminal and a TX terminal are provided on one side of the front-stage data cache unit.

[0012] Preferably, the front-stage data cache unit, the rear-stage data cache unit, the network adapter unit and the encryption processing unit are all provided with a power supply terminal VCC and a ground terminal GND, and one side of the network adapter unit is provided with a CANH terminal and a CANL terminal.

[0013] Preferably, the storage space of the NMV storage element is 96KB, and there are four containers in the NMV storage element.

[0014] Beneficial effects

[0015] The NMV storage element can ensure that internal stored data will not be lost. At the same time, the stored data files can be enumerated through the application management module to obtain the required files. The signature verification method of the SM2 algorithm module improves security. The internal data is grouped through the cryptographic hash algorithm module. At the same time, a session key can be temporarily generated through the session key module. After it is safely exported, the key will be automatically destroyed to delete the temporary session. There is no need to store these contents, saving storage space. The dominant chip in the present invention plans and modifies the internal overall system, solving the problem that many chips in existing devices are installed in smart password keys. If the smart password key loses power, it may cause data loss within the system and the chip's network system can only perform simple storage and encryption of data, with relatively simple functions. The present invention meets the requirements of the national secret algorithm and is a hybrid chip with a communication transceiver. The chip is pin-compatible, can meet standard encryption functions, has software encryption, and especially has the encryption technology foundation of the national secret algorithm, ensuring data confidentiality and driving safety of domestic vehicles. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 This is a diagram of the internal framework of the smart password key of the present invention;

[0017] Figure 2 This is a diagram of the internal connection framework of the smart password key of the present invention;

[0018] Figure 3 This is a framework diagram of the NMV storage process of the present invention;

[0019] Figure 4 It is a logic block diagram of the present invention;

[0020] Figure 5 is an equivalent circuit diagram of the 485 communication adapter of the present invention;

[0021] Figure 6 is an equivalent circuit diagram of the K communication adapter of the present invention;

[0022] Figure 7 is an equivalent circuit diagram of the LIN communication adapter of the present invention;

[0023] Figure 8 is an equivalent circuit diagram of the FlexRax communication adapter of the present invention;

[0024] Figure 9 The equivalent circuit diagram of the 232 communication adapter of the present invention;

[0025] Figure 10 This is a specific framework diagram of the network adapter unit of the present invention. DETAILED DESCRIPTION

[0026] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention. Specific embodiment one:

[0028] like Figure 1-3 As shown, an in-vehicle network data encryption system and an encrypted in-vehicle network chip include a smart password key and a dominant chip. The dominant chip is installed inside the smart password key, and an NMV storage element is provided inside the dominant chip. A device authentication module is electrically connected to the bottom of the dominant chip near the inside of the smart password key, an application management module is electrically connected to the bottom of the device authentication module near the inside of the smart password key, one end of the application management module is electrically connected to the container management module, a file management module is provided inside the smart password key near the bottom of the container management module, one end of the container management module is electrically connected to the SM2 algorithm module and a session key module, a cryptographic hash algorithm module is provided inside the smart password key near the top of the SM2 algorithm module, one end of the session password module is electrically connected to the SM4 encryption / decryption module and the message authentication code module, the storage space of the NMV storage element is 96KB, and there are four containers in the NMV storage element.

[0029] The dominant chip in the present invention can also be directly installed in the smart password key for use. The NMV storage element can be used to store user-defined information for a long time, such as the name of the application, the value of the stored signature key pair, etc. After the smart password key loses power, the information stored in this area will not be lost. The smart password key designed in this article can be divided into 8 modules according to its main functions. Each module contains several functional functions for the PC to interact with the smart password key.

[0030] The application management module application is a structure that contains a PIN code, container, and file in the smart password key. The function of this module includes creating applications, deleting applications, enumerating applications, opening applications, and closing applications.

[0031] The file management module is used to meet the needs of users to expand their business. Users can create and delete files within the application and read and write data to designated areas. The functions in this module include creating files, deleting files, enumerating files, obtaining file information, reading files, and writing files.

[0032] The container management module is a unique storage space in the smart key that stores secret keys. Functions in the container management module include: creating a container, deleting a container, opening a container, closing a container, enumerating containers, importing a digital certificate, and exporting a digital certificate.

[0033] The functional functions in the SM2 algorithm module include: SM2 key pair generation, SM2 signature, SM2 signature verification and public key export.

[0034] The functional functions in the cryptographic hash algorithm module include cryptographic hash initialization, single-group data cryptographic hash, multi-group data cryptographic hash and end cryptographic hash.

[0035] The session key module includes three functions of the SM2 key exchange protocol: random generation of session keys, secure derivation of session keys using external public keys, and destruction of session keys.

[0036] The functions in the SM4 encryption / decryption module include: encryption initialization, single-group data encryption, multiple-group data encryption, and end encryption; decryption initialization, single-group data decryption, multiple-group data decryption, and end decryption.

[0037] The functions in the message authentication code module include: MAC initialization, MAC calculation for a single set of data, MAC calculation for multiple sets of data, and MAC end.

[0038] The NMV storage element can ensure that internal stored data will not be lost. At the same time, the stored data files can be enumerated through the application management module to obtain the required files. The security is improved by the signature verification method of the SM2 algorithm module. The internal data is grouped through the cryptographic hash algorithm module. At the same time, a session key can be temporarily generated through the session key module. After the secure export, the key will be automatically destroyed to delete the temporary session. There is no need to store these contents, which saves storage space. The dominant chip in the present invention plans and changes the internal overall system. Specific embodiment two:

[0040] like Figure 4-10 As shown, an encryption processing unit is provided in the dominant chip, an encryption authentication system is provided in the encryption processing unit, an algorithm module is provided in the dominant chip, the algorithm module includes an encryption algorithm repository and a private key repository, the encryption processing unit interacts with the network adapter unit data, and the network adapter unit and the encryption processing unit constitute a topology architecture.

[0041] The encryption algorithm repository contains hash algorithms, symmetric algorithms, and asymmetric algorithms, and the private key repository contains intra-domain group keys and inter-domain session keys.

[0042] One end of the encryption processing unit is bidirectionally connected to the previous-stage data cache unit, and the other end of the encryption processing unit is bidirectionally connected to the next-stage data cache unit. One end of the next-stage data cache unit is connected to the network adapter unit. After the encryption function is implanted into the network adapter unit, the overall security of the vehicle circuit system can be improved without changing any circuit structure. The previous-stage data cache unit and the next-stage data cache unit are both cache topology structures. The input end group of the previous-stage data cache unit is used to connect to an external signal source. The previous-stage data cache unit is internally bidirectionally connected to the encryption processing unit, and the encryption processing unit is bidirectionally connected to the network adapter unit via the next-stage data cache unit. The communication end group of the network adapter unit is used to connect to an external bus.

[0043] The network adapter unit includes a 485 communication adapter. A K communication adapter is provided inside the network adapter unit near the bottom of the 485 communication adapter. A LIN communication adapter is provided inside the network adapter unit near the bottom of the K communication adapter. A FlexRax communication adapter is provided inside the network adapter unit near the bottom of the LIN communication adapter. A 232 communication adapter is provided inside the network adapter unit near the bottom of the FIexRax communication adapter.

[0044] The input terminal group of the front-stage data cache unit is connected to the external signal source, the communication terminal group of the network adapter unit is connected to the external bus, and an RX terminal and a TX terminal are provided on one side of the front-stage data cache unit.

[0045] The front-stage data cache unit, the rear-stage data cache unit, the network adapter unit and the encryption processing unit are all provided with a power supply terminal VCC and a ground terminal GND, and one side of the network adapter unit is provided with a CANH terminal and a CANL terminal.

[0046] After the encryption processing unit obtains the source data, the encryption authentication system identifies the data identity information based on the identity field in the source data. This identity information determines the legal identity of the specific on-board functional unit.

[0047] The algorithm module extracts the corresponding encryption algorithm from the encryption algorithm repository and the corresponding negotiated key from the key repository based on the legal identity of the on-board functional unit to encrypt the source data.

[0048] The network adapter unit transmits the encrypted source data to the vehicle network and receives the uploaded information from each vehicle functional unit in the vehicle network.

[0049] The algorithm module uses the corresponding encryption algorithm and negotiated key to decrypt the uploaded information and feed it back to the source.

[0050] Different units such as brakes, accelerators, vehicle speed, and water temperature use different encryption algorithms and keys to improve overall security.

[0051] The signal source in the overall vehicle bus is the vehicle controller. In the vehicle bus control system, there are a variety of different network adapters. In order not to affect the circuit structure of the original vehicle, the terminal characteristics of the newly developed vehicle network security chip must be consistent with the original vehicle products. Therefore, when integrating the data cache unit, encryption processing unit and network adapter unit, independent internal circuit connection relationships must be built for different network adapters to facilitate one-time quick replacement of chips to ensure that the original vehicle design is not affected. It should be noted that the enable end of the network adapter unit and the setting end of the encryption processing unit are connected in parallel before being connected to the outside world, and the dominant chip has its own transceiver.

Claims

1. A vehicle network data encryption system, comprising a smart password key and a master chip, characterized by: A dominant chip is installed inside the smart password key, and an NMV storage element is provided in the dominant chip. A device authentication module is electrically connected to the bottom of the dominant chip inside the smart password key. An application management module is electrically connected to the bottom of the device authentication module inside the smart password key. One end of the application management module is electrically connected to the container management module. A file management module is provided inside the smart password key near the bottom of the container management module. One end of the container management module is electrically connected to the SM2 algorithm module and the session key module. A cryptographic hash algorithm module is provided inside the smart password key near the top of the SM2 algorithm module. One end of the session key module is electrically connected to the SM4 encryption / decryption module and the message combined code module. A session key is temporarily generated by the session key module, and the key will be automatically destroyed immediately after it is safely exported to delete the temporary session. There is an encryption processing unit, which is equipped with an encryption authentication system. The dominant chip is equipped with an algorithm module, which includes an encryption algorithm repository and a private key repository. One end of the encryption processing unit is bidirectionally connected to a previous-level data cache unit, and the other end of the encryption processing unit is bidirectionally connected to a subsequent-level data cache unit. One end of the subsequent-level data cache unit is connected to a network adapter unit. The network adapter unit includes a 485 communication adapter. A K communication adapter is provided inside the network adapter unit near the bottom of the 485 communication adapter. A LIN communication adapter is provided inside the network adapter unit near the bottom of the K communication adapter. A FlexRax communication adapter is provided inside the network adapter unit near the bottom of the LIN communication adapter. A 232 communication adapter is provided inside the network adapter unit near the bottom of the FIexRax communication adapter.

2. The vehicle network data encryption system according to claim 1, characterized in that: The encryption algorithm repository includes hash algorithms, symmetric algorithms, and asymmetric algorithms, and the private key repository includes intra-domain group keys and inter-domain session keys.

3. The vehicle network data encryption system according to claim 2, characterized in that: The input terminal group of the front-stage data cache unit is connected to an external signal source, the communication terminal group of the network adapter unit is connected to an external bus, and one side of the front-stage data cache unit is provided with an RX terminal and a TX terminal.

4. The vehicle network data encryption system according to claim 3, characterized in that: The front-stage data cache unit, the rear-stage data cache unit, the network adapter unit and the encryption processing unit are all provided with a power supply terminal V DD and a ground terminal GND, and one side of the network adapter unit is provided with a CANH terminal and a CANL terminal.

5. The vehicle network data encryption system according to claim 4, characterized in that: The storage space of the NMV storage element is 96KB, and there are four containers in the NMV storage element.

Citation Information

Patent Citations

  • Chip protection method and device, storage medium and vehicle-mounted chip

    CN111291425A

  • Intelligent coded key of large-capacity data encrypt storage function and working method thereof

    CN101063994A

  • Vehicle lock remote security control system and method

    CN110239484A