A method, apparatus, system, and storage medium for processing mirror image data
By introducing master-slave mirror partition structure and public-key private key verification into the mirror data packet, the problem of mirror data being tampered with during transmission is solved, data integrity and security is ensured, and the secure writing of mirror data on the on-board chip is realized.
Patent Information
- Application Number
- CN202211352885.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-01
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2042-11-01
AI Technical Summary
During the transmission of mirror data, mirror data may be intercepted and tampered by attackers, resulting in the chip being unavailable or security problems, and it is difficult for the prior art to effectively verify the integrity and security of the data.
By introducing the structure of the main mirror partition and the slave mirror partition into the mirror data packet, the main mirror partition stores the digest signature of the slave mirror partition, and verifies the digest signature using the public and private keys to ensure the integrity and security of the data.
Improve the security of mirrored data on the on-board chip, ensure that data is written to the chip without being tampered with, reduce the chance of attackers tampering and improve the availability and security of data.
Smart Images

Figure CN115842652B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of automobiles, and more specifically, to a method, device, system and storage medium for processing mirror image data in the field of automobiles. Background Art
[0002] When any chip on a device fails, the mirror image data to be burned on the chip can be retrieved again from the server side and burned again onto the chip, so that the user can continue to use the chip.
[0003] In the related art, during the process of sending the mirror image data to the device, the mirror image data may be intercepted by an attacker, and thus the mirror image data is tampered with. If the tampered mirror image data is burned onto the chip, this will cause the chip to be unusable or there will be various security problems with the chip, etc. Therefore, the device needs to determine whether the mirror image data is tampered with so as to burn the mirror image data onto the chip when the mirror image data is not tampered with. Summary of the Invention
[0004] The present application provides a method, device, system and storage medium for processing mirror image data, and this method can improve the security of the data burned onto the vehicle-mounted chip.
[0005] In a first aspect, a method for processing mirror image data is provided. This method is executed by a controller of a vehicle-mounted chip, and the method includes: receiving a mirror image data packet sent by a server, the mirror image data packet including each piece of mirror image data to be burned onto the vehicle-mounted chip, the mirror image data packet including a main mirror image partition and at least one secondary mirror image partition, the secondary mirror image partition including a header and corresponding mirror image data; when it is determined that the signature of the digest of the mirror image data stored in the header of the secondary mirror image partition is trustworthy according to the signature of the digest of the secondary mirror image partition stored in the main mirror image partition, determining whether the mirror image data is tampered with according to the signature of the digest of the mirror image data and the mirror image data; and when the mirror image data is not tampered with, burning the mirror image data onto the vehicle-mounted chip.
[0006] In the above technical solution, since the signature of the digest of the mirror data is stored at the head of the slave mirror partition, and the signature of the digest of the slave mirror partition is stored in the master mirror partition (the digest of the slave mirror partition is the digest of the information at the head of the slave mirror partition), after the controller of the in-vehicle chip receives the mirror data packet, the controller can determine whether the information at the head of the slave mirror partition is trustworthy based on the signature of the digest of the slave mirror partition stored in the master mirror partition. Since the signatures of the digests of the respective mirror data are stored at the head of the slave mirror partition, when the signature of the digest of the mirror data is trustworthy, the signature of the digest of the mirror data can be used to verify whether the mirror data actually received by the controller of the in-vehicle chip has been tampered with. In this way, it can be determined whether the received mirror data packet is available. When the mirror data has not been tampered with, the respective mirror data is burned onto the in-vehicle chip, which can improve the security of the data burned onto the in-vehicle chip.
[0007] In combination with the first aspect, in some possible implementation manners, the process of judging the trustworthiness of the signature of the digest of the mirror data includes: decrypting the signature of the digest of the slave mirror partition by using a preset public key to obtain the digest of the slave mirror partition; calculating the digest of the slave mirror partition by using a preset second digest algorithm to obtain the information at the head of the slave mirror partition; and determining whether the signature of the digest of the mirror data is trustworthy according to the information at the head of the slave mirror partition and the signature of the digest of the mirror data.
[0008] In the above technical solution, it is a process of verifying whether the signature of the digest of the mirror data in the slave mirror partition is trustworthy according to the signature of the digest of the slave mirror partition stored in the master mirror partition (the digest of the slave mirror partition is the digest of the information at the head of the slave mirror partition). Since the signature of the digest of the information at the head of the slave mirror partition is stored in the master mirror partition, and the signatures of the digests of the mirror data are stored at the head of the slave mirror partition. Therefore, the signature of the digest of the slave mirror partition can be decrypted by using the public key to obtain the digest of the slave mirror partition, and the second digest algorithm can be used to calculate the digest of the slave mirror partition to obtain the information at the head of the slave mirror partition. Whether the signature of the digest of the mirror data is trustworthy can be determined according to the information at the head of the slave mirror partition and the signature of the digest of the mirror data. The signature of the digest of the mirror data can be verified, which can improve the security of the signature of the digest of the mirror data.
[0009] In combination with the first aspect and the above implementation manners, in some possible implementation manners, determining whether the mirror data has been tampered with according to the signature of the digest of the mirror data and the mirror data includes: decrypting the signature of the digest of the mirror data by using a private key to obtain the standard digest of the mirror data; calculating the test digest of the mirror data by using the first digest algorithm; and determining whether the mirror data has been tampered with according to the test digest of the mirror data and the standard digest of the mirror data.
[0010] In the above technical solution, the test summary is obtained by actually receiving the mirror data. The test summary of the mirror data is to convert the actually received mirror data into a return value with a fixed length through the first rule. And the standard summary of the mirror data is to convert the real mirror data into a return value with a fixed length through the first rule. Therefore, the test summary can be verified according to the standard summary to determine whether each actually received mirror data has been tampered with. That is, it can be determined whether each actually received mirror data is available, which can improve the security of the use of each mirror data.
[0011] Combined with the first aspect and the above implementation manners, in some possible implementation manners, determining whether the mirror data has been tampered with according to the test summary of the mirror data and the standard summary of the mirror data includes: when the test summary of the mirror data is the same as the standard summary of the mirror data, determining that the mirror data has not been tampered with; when the test summary of the mirror data is different from the standard summary of the mirror data, determining that the mirror data has been tampered with.
[0012] In the above technical solution, since the standard summary of the mirror data is obtained when the signature of the summary of the mirror data is trustworthy, it is considered that the standard summary of the mirror data is correct. The standard summary of the mirror data is compared with the test summary of the mirror data (calculated by using the first summary algorithm for the actually received mirror data) to determine whether the mirror data has been tampered with. The security of the mirror data can be improved.
[0013] In summary, the present application proposes a method for processing mirror data. Since the signature of the summary of the mirror data is stored at the head of the slave mirror partition, and the signature of the summary of the slave mirror partition is stored in the main mirror partition (the summary of the slave mirror partition is the summary of the information at the head of the slave mirror partition), after the controller of the vehicle-mounted chip receives the mirror data packet, the controller can determine whether the information at the head of the slave mirror partition is trustworthy according to the signature of the summary of the slave mirror partition stored in the main mirror partition. Since the signature of the summary of each mirror data is stored at the head of the slave mirror partition, the signature of the summary of the mirror data can be used to verify whether each actually received mirror data by the controller of the vehicle-mounted chip has been tampered with when the signature of the summary of the mirror data is trustworthy. In this way, it can be determined whether the received mirror data packet by the controller is available. When each mirror data has not been tampered with, each mirror data is directly used and written to the vehicle-mounted chip, which can improve the security of the data written to the vehicle-mounted chip.
[0014] In addition, since the standard digest of the mirror image data is obtained when the signature of the digest of the mirror image data is trustworthy, it is considered that the standard digest of the mirror image data is correct. The standard digest of the mirror image data is compared with the test digest of the mirror image data (calculated by using the first digest algorithm for the actually received mirror image data) to determine whether the mirror image data has been tampered with. This can improve the security of the mirror image data.
[0015] In a second aspect, a method for processing mirror image data is provided. The method is executed by a server and includes: receiving a mirror image request from a user, where the mirror image request is used to request each piece of mirror image data to be burned onto a vehicle-mounted chip; in response to the mirror image request, determining the signature of the digest of the mirror image data; according to the burning process of the data to be burned on the vehicle-mounted chip, storing the signature of the digest of the mirror image data at the head of the secondary mirror partition in the mirror image packet, and storing each piece of mirror image data in the secondary mirror partition; determining the signature of the digest of the secondary mirror partition, and storing the signature of the digest of the secondary mirror partition in the primary mirror partition of the mirror image packet; and sending the mirror image packet to the controller of the vehicle-mounted chip.
[0016] In the above technical solution, after the server receives each piece of mirror image data requested by the user to be burned onto the vehicle-mounted chip, it processes each piece of mirror image data to obtain the signature of the digest of the mirror image data, and stores the signature of the digest of the mirror image data at the head of the secondary mirror partition in the mirror image packet, and stores each piece of mirror image data in the secondary mirror partition of the mirror image packet. The information at the head of the secondary mirror partition is processed to obtain the signature of the digest of the secondary mirror partition (the digest of the secondary mirror partition is the digest of the information at the head of the secondary mirror partition), and the signature of the digest of the secondary mirror partition is stored in the primary mirror partition of the mirror image packet. In this way, the signature of the digest of the mirror image data in the head of the secondary mirror partition can be verified by using the signature of the digest of the secondary mirror partition in the primary mirror partition; when the signature of the digest of the mirror image data in the head is trustworthy, the signature of the digest of the mirror image data can be used to verify whether the mirror image data in the actually received mirror image packet has been tampered with. That is to say, the mirror image packet includes a primary mirror partition and a secondary mirror partition, and each secondary mirror partition in the secondary mirror partition includes a head and corresponding mirror image data. This storage format can reduce the probability of an attacker tampering with each piece of mirror image data.
[0017] Combined with the second aspect and the above implementation, in some possible implementation manners, determining the signature of the digest of the mirror image data includes: calculating the digest of the mirror image data by using a preset first digest algorithm, and determining the digest of the mirror image data; encrypting the digest of the mirror image data by using a preset private key to determine the signature of the digest of the mirror image data.
[0018] In the above technical solution, the first digest algorithm can be used to change the data format of the mirror data, so that the mirror data is presented in another form, making it difficult for attackers to identify the mirror data; then, the private key is used to encrypt the digest of the mirror data, further preventing attackers from attacking the mirror data and preventing the mirror data from being tampered with by attackers.
[0019] Combined with the second aspect and the above implementation, in some possible implementations, determining the signature of the digest of the mirror partition includes: using the second digest algorithm to calculate the information of the head of the mirror partition to obtain the digest of the mirror partition, and the digest is the digest of the information of the head of the mirror partition; using the private key to encrypt the digest of the mirror partition to determine the signature of the digest of the mirror partition.
[0020] In the above technical solution, the second digest algorithm can be used to change the data format of the information of the head of the mirror partition, so that the information of the head is presented in another form, making it difficult for attackers to identify the information of the head; then, the private key is used to encrypt the digest of the mirror partition, further preventing attackers from attacking the information of the head and preventing the information of the head from being tampered with by attackers.
[0021] In summary, the present application proposes a method for processing mirror data. After the server receives each mirror data to be burned onto the vehicle-mounted chip in response to a user request, it processes each mirror data to obtain the signature of the digest of the mirror data, and stores the signature of the digest of the mirror data in the head of the mirror partition in the mirror packet in the secondary mirror, and stores each mirror data in the mirror partition of the mirror packet in the secondary mirror. The information of the head of the mirror partition is processed to obtain the signature of the digest of the mirror partition (the digest of the mirror partition is the digest of the information of the head of the mirror partition), and the signature of the digest of the mirror partition is stored in the primary mirror partition of the mirror packet, so that the signature of the digest of the mirror partition in the primary mirror partition can be used to verify the signature of the digest of the mirror data in the head of the mirror partition in the secondary mirror; when the signature of the digest of the mirror data in the head is trustworthy, the signature of the digest of the mirror data can be used to verify whether the mirror data in the actually received mirror packet has been tampered with. That is to say, the mirror packet includes a primary mirror partition and a secondary mirror partition, and each secondary mirror partition in the secondary mirror partition includes a head and corresponding mirror data. This storage format can reduce the probability of attackers tampering with each mirror data.
[0022] In a third aspect, a device for processing mirror data is provided. The device includes: a first receiving module, configured to receive a mirror data packet sent by a server, where the mirror data packet includes each piece of mirror data to be burned onto a vehicle-mounted chip, the mirror data packet includes a main mirror partition and at least one secondary mirror partition, and the secondary mirror partition includes a header and corresponding mirror data; a first determining module, configured to: when it is determined that the signature of the digest of the mirror data stored in the header of the secondary mirror partition is trustworthy according to the signature of the digest of the secondary mirror partition stored in the main mirror partition, determine whether the mirror data has been tampered with according to the signature of the digest of the mirror data and each piece of mirror data; a burning module, configured to burn each piece of mirror data onto the vehicle-mounted chip when each piece of mirror data has not been tampered with.
[0023] In combination with the third aspect, in some possible implementation manners, the first determining module is specifically configured to: decrypt the signature of the digest of the secondary mirror partition by using a preset public key to obtain the digest of the secondary mirror partition; calculate the information of the header of the secondary mirror partition by using a preset second digest algorithm; determine whether the signature of the digest of the mirror data is trustworthy according to the information of the header of the secondary mirror partition and the signature of the digest of the mirror data.
[0024] In combination with the third aspect and the above implementation manners, in some possible implementation manners, the first determining module is specifically further configured to decrypt the signature of the digest of the mirror data by using a private key to obtain the standard digest of the mirror data; calculate the test digest of the mirror data by using a first digest algorithm; determine whether the mirror data has been tampered with according to the test digest of the mirror data and the standard digest of the mirror data.
[0025] In combination with the third aspect and the above implementation manners, in some possible implementation manners, the first determining module is specifically further configured to determine that the mirror data has not been tampered with when the test digest of the mirror data is the same as the standard digest of the mirror data; determine that the mirror data has been tampered with when the test digest of the mirror data is different from the standard digest of the mirror data.
[0026] Fourthly, a device for processing mirror image data is provided. The device includes: a second receiving module, configured to receive a mirror image request from a user, where the mirror image request is used to request various mirror image data to be burned to an in-vehicle chip; a second determining module, configured to determine a signature of a digest of the mirror image data in response to the mirror image request; a storage module, configured to store the signature of the digest of the mirror image data at the head of a secondary mirror partition in the secondary mirror partition of the mirror image packet according to the burning process of the data to be burned on the in-vehicle chip, and store the mirror image data in the secondary mirror partition; the second determining module is further configured to determine a signature of a digest of the secondary mirror partition, and store the signature of the digest of the secondary mirror partition in the primary mirror partition of the mirror image packet; a sending module, configured to send the mirror image packet to a controller of the in-vehicle chip.
[0027] In combination with the fourth aspect, in some possible implementation manners, the second determining module is specifically configured to respond to the mirror image request when a level of the user's request permission is greater than a preset level.
[0028] In combination with the fourth aspect and the above implementation manners, in some possible implementation manners, the second determining module is specifically further configured to calculate a digest of the mirror image data by using a preset first digest algorithm, and determine the digest of the mirror image data; encrypt the digest of the mirror image data by using a preset private key to determine a signature of the digest of the mirror image data.
[0029] In combination with the fourth aspect and the above implementation manners, in some possible implementation manners, the second determining module is specifically further configured to calculate a digest of the secondary mirror partition by using a second digest algorithm for information at the head of the secondary mirror partition, where the digest is a digest of the information at the head of the secondary mirror partition; encrypt the digest of the secondary mirror partition by using a private key to determine a signature of the digest of the secondary mirror partition.
[0030] Fifthly, a system for processing mirror image data is provided. The system includes a vehicle and a server. The vehicle includes an in-vehicle chip, and a controller of the in-vehicle chip is configured to execute the method in the first aspect or any one of the possible implementation manners of the first aspect. The server is configured to execute the method in the second aspect or any one of the possible implementation manners of the second aspect.
[0031] Sixthly, a computer-readable storage medium is provided. Instructions are stored in the computer-readable storage medium. When the instructions run on a computer or a processor, the computer or the processor is caused to execute the method in the first aspect or any one of the possible implementation manners of the first aspect, and the method in the second aspect or any one of the possible implementation manners of the second aspect. Description of the Drawings
[0032] Figure 1It is an architecture diagram of a system for obtaining mirror image data provided by an embodiment of the present application;
[0033] Figure 2 It is a schematic flowchart of a method for processing mirror image data provided by an embodiment of the present application;
[0034] Figure 3 It is a schematic diagram of the format of a mirror image data packet provided by an embodiment of the present application;
[0035] Figure 4 It is a schematic flowchart of another method for processing mirror image data provided by an embodiment of the present application;
[0036] Figure 5 It is a schematic structural diagram of a device for processing mirror image data provided by an embodiment of the present application;
[0037] Figure 6 It is a schematic structural diagram of another device for processing mirror image data provided by an embodiment of the present application;
[0038] Figure 7 It is a schematic structural diagram of a server provided by an embodiment of the present application;
[0039] Figure 8 It is a schematic structural diagram of a vehicle provided by an embodiment of the present application. Detailed implementation manners
[0040] Next, the technical solutions in the present application will be clearly and elaborately described in conjunction with the accompanying drawings. Among them, in the description of the embodiments of the present application, "a plurality of" means two or more than two. The terms "first" and "second" are only used for descriptive purposes and cannot be construed as implying or suggesting relative importance or implicitly indicating the number of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features.
[0041] Figure 1 It is an architecture diagram of a system for obtaining mirror image data provided by an embodiment of the present application.
[0042] The Figure 1 The system for obtaining mirror image data shown includes a server, a computer terminal, and a vehicle. Among them, the vehicle includes an in-vehicle chip. The operation of various hardware vehicle components on the vehicle requires data in the chip (in-vehicle chip) of the vehicle components. When a certain in-vehicle chip cannot be used, the controller of the in-vehicle chip can obtain the data on the in-vehicle chip from the server again through the computer terminal. After obtaining the data, the data can be rewritten to the in-vehicle chip again so that the vehicle components supported by the in-vehicle chip can be put into use.
[0043] Exemplarily, when the in-vehicle SOC chip cannot be used, the controller of the in-vehicle SOC chip can send a request for the mirror data of the in-vehicle SOC chip to the server through a computer terminal; after receiving the request for the mirror data, the server, in response to the request for the mirror data, stores the mirror data of the in-vehicle SOC chip in a mirror data packet and sends the mirror data packet to the computer terminal; the computer terminal forwards it to the controller of the in-vehicle SOC chip. The controller of the in-vehicle SOC chip burns the mirror data in the mirror data packet onto the in-vehicle SOC chip.
[0044] Figure 2 It is a schematic flowchart of a method for processing mirror data provided by an embodiment of the present application.
[0045] It should be understood that a method for processing mirror data provided by an embodiment of the present application can be executed by Figure 1 the server in the system for obtaining mirror data shown.
[0046] Exemplarily, as Figure 2 shown, the method 200 includes:
[0047] 201. The server receives a mirror request from the user, and the mirror request is used to request each piece of mirror data to be burned onto the in-vehicle chip.
[0048] It should be understood that the server receives the mirror request from the user through a wireless communication method.
[0049] It should also be understood that each piece of mirror data is data that is rewritten or burned onto the in-vehicle chip when the in-vehicle chip cannot be used.
[0050] Optionally, the in-vehicle chip can be an in-vehicle system-on-chip (SOC) chip.
[0051] It should be understood that the "in-vehicle SOC chip" can be understood as integrating multiple processing systems on one chip. The multiple processing systems include Figure 3The Central Processing Unit (CPU), Graphic Processing Unit (GPU), Digital Signal Processing Unit (DSPU), Neural Processing Unit (NPU), Modem unit (MU), etc. are shown. Among them, the CPU is the "brain" of the in-vehicle SOC chip and is used for processing various instructions or data; the GPU is used for processing graphics-related tasks. For example, it is used for the user interface of visualization applications; the DSPU is used for processing signals such as acquisition, transformation, filtering, estimation, enhancement, compression, or recognition in digital form to obtain a signal form that meets the user's needs. For example, the DSPU is used for decompressing music files; the NPU is used for high-end smartphones to accelerate machine learning tasks. For example, the NPU is used for speech recognition; and the MU is used for the conversion between analog signals and digital signals.
[0052] In a possible implementation, the server receives a mirror request of a user sent by a computer terminal.
[0053] In the above technical solution, the server receives a mirror request for mirror data of the in-vehicle chip, and the specific implementation process is sent by the computer terminal to the server. This is because the controller of the in-vehicle chip may be far away from the server. If the controller directly sends the mirror request to the server, the server may not receive the mirror request. Therefore, the method of the controller sending the mirror request to the computer terminal and the computer terminal then forwarding it to the server can increase the probability of the server receiving the mirror request.
[0054] 202, the server, in response to the mirror request, determines the signature of the digest of the mirror data.
[0055] Optionally, the mirror data can be stored in the compilation background server. When the server responds to the mirror request, it can obtain the mirror data from the compilation background server and calculate the digest of the mirror data using a preset first digest algorithm to determine the digest of the mirror data.
[0056] In a possible implementation, the server's response to the mirror request includes: when the level of the user's request permission is greater than a preset level, the server responds to the mirror request.
[0057] In the above technical solution, the server responds to the user's mirror request only when the level of the user's requested permission is greater than the preset level. That is to say, not any user can request each piece of mirror data to be burned onto the in-vehicle chip. This can reduce the probability of abuse of each piece of mirror data of the in-vehicle chip and prevent illegal users from misusing each piece of mirror data of the in-vehicle chip.
[0058] In a possible implementation manner, step 202 includes: the server responds to the mirror request, calculates the mirror data using a preset first digest algorithm to determine the digest of the mirror data; the server encrypts the digest of the mirror data using a preset private key to determine the signature of the digest of the mirror data.
[0059] In the above technical solution, using the first digest algorithm can change the data format of the mirror data, making the mirror data presented in another form, which is not convenient for attackers to identify the mirror data; then, encrypting the digest of the mirror data using the private key further prevents attackers from attacking the mirror data and prevents the mirror data from being tampered with by attackers.
[0060] Preferably, the first digest algorithm is an asymmetric encryption algorithm.
[0061] Among them, the first digest algorithm can be any one of the Message Digest (MD) algorithm, the Secure Hash Algorithm (SHA) algorithm, and the Message Authentication Code (MAC) algorithm.
[0062] It should be understood that the digest algorithm is to convert the input data of any length into a fixed-length return value through a series of calculation methods and rules, and this value is called the Hash value. Therefore, the digest algorithm is also called the hash algorithm.
[0063] Among them, the solution of "encrypting the digest of the mirror data using the private key to determine the signature of the digest of the mirror data" in a possible implementation manner of step 202 is equivalent to the process of signing the mirror data using the private key.
[0064] 203. The server stores the signature of the digest of the mirror data at the head of the slave mirror partition in the mirror data packet and stores the mirror data in the slave mirror partition according to the burning process of the data to be burned on the in-vehicle chip.
[0065] In a possible implementation manner, after step 203, the method further includes: the server stores the size of the slave mirror partition, the head address offset of the next slave mirror partition corresponding to the slave mirror partition, the running entity of the mirror data, and the loading address of the mirror data at the head of the slave mirror partition.
[0066] Among them, the size of the slave mirror partition is used to indicate the address size occupied by the head of the slave mirror partition and the corresponding mirror data; the head address offset of the next slave mirror partition corresponding to the slave mirror partition is used to indicate the address difference between the head address of the next slave mirror partition and the head address of the current slave mirror partition, and the head address refers to the address of the head of the slave mirror partition; the running entity of the mirror data is used to indicate who executes the mirror data. For example, mirror data 1 is executed by the first core in a 4-core CPU; the loading address of the mirror data is used to indicate the address of the mirror data in the slave mirror partition.
[0067] In the above technical solution, the size of the slave mirror partition stored in the head can be used to verify the actual size of the slave mirror partition; the head address offset of the next slave mirror partition can determine the address difference between the next slave mirror partition and the current slave mirror partition. Based on the head address of the current slave mirror partition, the head address of the next slave mirror partition can be determined, so that the loading address of the next mirror data can be determined, and then the next mirror data can be determined according to the loading address of the next mirror data; the loading address of the mirror data can determine the storage location of the mirror data, and the determined mirror data can be burned onto the vehicle-mounted chip; the running entity of the mirror data is used to indicate the execution entity of the mirror data. When a certain mirror data fails to be burned successfully, the running entity of the mirror data can be determined first, and whether there is a problem with the running entity can be checked, so that whether there is a problem with the running entity can be excluded.
[0068] 204. The server determines the signature of the digest of the slave mirror partition and stores the signature of the digest of the slave mirror partition in the master mirror partition in the mirror data packet.
[0069] In a possible implementation, the server determines the signature of the digest of the slave mirror partition, including: the server calculates the digest of the head information of the slave mirror partition by using a second digest algorithm, and the obtained digest is the digest of the head information of the slave mirror partition; the digest of the slave mirror partition is encrypted by using a private key to determine the signature of the digest of the slave mirror partition.
[0070] In the above solution, it is equivalent to the process of signing the head information of the slave mirror partition by using a private key. Using the second digest algorithm can change the data format of the head information of the slave mirror partition, so that the head information is presented in another form, making it inconvenient for attackers to identify the head information; then, the digest of the slave mirror partition is encrypted by using a private key to further prevent attackers from attacking the head information and prevent the head information from being tampered with by attackers.
[0071] Preferably, the second digest algorithm is an asymmetric encryption algorithm.
[0072] Among them, the second digest algorithm can be any one of the MD algorithm, the SHA algorithm, and the MAC algorithm.
[0073] Optionally, the second digest algorithm can be the same as or different from the first digest algorithm.
[0074] 205. The server sends the mirror data packet to the controller of the vehicle-mounted chip.
[0075] It should be understood that the server can send the mirror data packet to the controller through wireless communication.
[0076] In a possible implementation, the server sends the mirror data packet to the computer terminal, and the computer terminal forwards the mirror data packet to the controller.
[0077] In the above technical solution, since the distance between the server and the controller may be very far, the controller may not receive the mirror data packet sent by the server. Therefore, the method of the server sending the mirror data packet to the computer terminal and the computer terminal forwarding it can increase the probability that the controller receives the mirror data packet.
[0078] In summary, method 200 provides a method for processing mirror data. After the server receives the mirror request of the user, it judges the level of the request permission of the user; when the level of the request permission of the user is greater than the preset level, it responds to the mirror request. Process the mirror data to obtain the signature of the digest of the mirror data, and store the signature of the digest of the mirror data in the head of the slave mirror partition in the mirror data packet (other contents are also stored in the head, for example, the size of the slave mirror partition, the running entity of the mirror data, etc.), and store the mirror data in the slave mirror partition of the mirror data packet. Process the information in the head of the slave mirror partition to obtain the signature of the digest of the slave mirror partition (the digest of the slave mirror partition is the digest of the information in the head of the slave mirror partition), and store the signature of the digest of the slave mirror partition in the main mirror partition of the mirror data packet. Send the mirror data packet to the controller. That is to say, the mirror data packet includes a main mirror partition and at least one slave mirror partition, and the slave mirror partition in the at least one slave mirror partition includes a head and corresponding mirror data. This storage format can reduce the probability of attackers tampering with the mirror data.
[0079] Figure 3 It is a schematic diagram of the format of a mirror data packet provided by an embodiment of the present application.
[0080] Exemplarily, taking the mirror data packet including a main mirror partition and two slave mirror partitions as an example, where the two slave mirror partitions are slave mirror partition 1 and slave mirror partition 2. Both slave mirror partition 1 and slave mirror partition 2 include a header and a data part; the header of slave mirror partition 1 stores the size of slave mirror partition 1, the signature of the digest of mirror data 1, the head address offset of slave mirror partition 2, the running entity of mirror data 1, and the loading address of mirror data 1; the data part of slave mirror partition 1 stores mirror data 1. The header of slave mirror partition 2 stores the size of slave mirror partition 2, the signature of the digest of mirror data 2, the running entity of mirror data 2, and the loading address of mirror data 2; the data part of slave mirror partition 2 stores mirror data 2. The main mirror partition stores the signature of the digest of the information of the header of slave mirror partition 1 and the signature of the digest of the information of the header of slave mirror partition 2.
[0081] The above Figure 2 The method in describes the process that the server receives the mirror requests of each piece of mirror data of the vehicle-mounted chip, the server generates a mirror data packet, and sends the mirror data packet to the controller of the vehicle-mounted chip. It should be understood that the mirror data packet should also have a process of being received and used. The specific process of using the mirror data packet can refer to the method in Figure 4 .
[0082] Figure 4 is a schematic flowchart of another method for processing mirror data provided by an embodiment of the present application.
[0083] It should be understood that another method for processing mirror data provided by an embodiment of the present application can be executed by the vehicle-mounted chip on the vehicle in the system for obtaining mirror data shown in Figure 1 , specifically executed by the controller of the vehicle-mounted chip.
[0084] Optionally, the method for processing mirror data can be executed by the controller of the vehicle-mounted SOC chip.
[0085] Exemplarily, as shown in Figure 4 , the method 400 includes:
[0086] 401. The controller receives the mirror data packet sent by the server. The mirror data packet includes each piece of mirror data to be burned onto the vehicle-mounted chip. The mirror data packet includes a main mirror partition and at least one slave mirror partition, and the slave mirror partition includes a header and corresponding mirror data.
[0087] It should be understood that the controller in the above solution refers to the controller of the vehicle-mounted chip.
[0088] In a possible implementation manner, the controller receives the mirror data packet sent by the server through a computer terminal.
[0089] In the above technical solution, it can be understood as the process in which the server sends the mirror data packet to the computer terminal, and the computer terminal forwards the mirror data packet to the controller. This can increase the probability that the controller receives the mirror data packet and avoid the situation that the controller cannot receive the mirror data packet due to the too long distance between the controller and the server.
[0090] 402. When the controller determines that the signature of the digest of the mirror data stored in the head of the slave mirror partition is trustworthy according to the signature of the digest of the slave mirror partition stored in the master mirror partition, the controller determines whether the mirror data has been tampered with based on the signature of the digest of the mirror data and the mirror data.
[0091] Wherein, the digest of the slave mirror partition is the digest of the information in the head of the slave mirror partition.
[0092] In a possible implementation manner, the process of judging the trustworthiness of the signature of the digest of the mirror data in step 402 includes: the controller decrypts the signature of the digest of the slave mirror partition by using a preset public key to obtain the digest of the slave mirror partition; the controller calculates the digest of the slave mirror partition by using a preset second digest algorithm to obtain the information in the head of the slave mirror partition; the controller determines whether the signature of the digest of the mirror data is trustworthy according to the information in the head of the slave mirror partition and the signature of the digest of the mirror data.
[0093] It should be understood that the "public key" in the above implementation manner corresponds to the "private key" in a possible implementation manner of step 202. There are two asymmetric keys in the asymmetric encryption algorithm, namely the private key and the public key. In this solution, the private key is used for encryption and the public key is used for decryption.
[0094] It should also be understood that the "public key" in the sentence "the controller decrypts the signature of the digest of the at least one slave mirror partition by using the public key to obtain the digest of the at least one slave mirror partition" in the above step corresponds to the "private key" in a possible implementation manner of step 204. There are two asymmetric keys in the asymmetric encryption algorithm, namely the private key and the public key. In this solution, the private key is used for encryption and the public key is used for decryption.
[0095] It should also be understood that the second digest algorithm in the above implementation manner is the same as the second digest algorithm in a possible implementation manner of step 204, and it is also an asymmetric encryption algorithm.
[0096] In the above technical solution, the controller decrypts the signature of the digest of the slave image partition using the public key, and calculates the digest of the slave image partition using the second digest algorithm to obtain the information of the header of the slave image partition. Since the information of the header of the slave image partition includes the signature of the digest of the mirror data, the signature of the digest of the mirror data can be verified using the information of the header of the slave image partition, that is, the signature verification process. In this way, it can be determined whether the signature of the digest of the mirror data is trustworthy, and the security of the signature of the digest of the mirror data can be improved.
[0097] In a possible implementation, the controller determines whether the mirror data has been tampered with based on the signature of the digest of the mirror data and the mirror data, including: the controller decrypts the signature of the digest of the mirror data using the private key to obtain the standard digest of the mirror data; the controller calculates the test digest of the mirror data using the first digest algorithm; the controller determines whether the mirror data has been tampered with based on the test digest and the standard digest of the mirror data.
[0098] It should be understood that the first digest algorithm in the above implementation is the same as the first digest algorithm in a possible implementation of step 202, and is also an asymmetric encryption algorithm.
[0099] Among them, in the above implementable manner, the standard digest of the mirror data is obtained using the public key, and the test digest of the mirror data is obtained using the first digest algorithm, and the process of verifying the test digest using the standard digest is a signature verification process.
[0100] In the above technical solution, the test digest is obtained by actually receiving the mirror data, and the test digest of the mirror data is converted into a return value of a fixed length through the first rule for the actually received mirror data. And the standard digest of the mirror data is converted into a return value of a fixed length through the first rule for the real mirror data. Therefore, the test digest can be verified according to the standard digest, so as to determine whether the actually received mirror data has been tampered with. That is, it can be determined whether each actually received mirror data is available, and the security of the use of each mirror data can be improved.
[0101] In a possible implementation, the controller determines whether the mirror data has been tampered with based on the test digest and the standard digest of the mirror data, including: when the test digest of the mirror data is the same as the standard digest of the mirror data, the controller determines that the mirror data has not been tampered with; when the test digest of the mirror data is different from the standard digest of the mirror data, the controller determines that the mirror data has been tampered with.
[0102] In the above technical solution, the test summary can be compared with the standard summary to verify whether the test summary is correct and whether the mirror data received by the controller has been tampered with by an attacker, so as to determine whether the received mirror data is consistent with the mirror data sent by the server. This can enhance the security of using mirror data.
[0103] In a possible implementation, the head of the slave mirror partition of the mirror data packet received by the controller further includes the size of the slave mirror partition, the head address offset of the next slave mirror partition corresponding to the slave mirror partition, the running entity of the mirror data, and the loading address of the mirror data.
[0104] In the above technical solution, the controller can verify the actual size of the slave mirror partition by using the size of the slave mirror partition; it can determine the address difference between the next slave mirror partition and the current slave mirror partition by using the head address offset of the next slave mirror partition in the slave mirror partition, and based on the head address of the current slave mirror partition, the head address of the next slave mirror partition can be determined, so that the loading address of the next mirror data can be determined; the loading address of the mirror data can enable the controller to clarify the storage location of the mirror data; when a certain mirror data fails to be burned successfully, the controller can first determine the running entity of the mirror data and check whether there is any problem with the running entity, so as to rule out whether there is a problem with the running entity.
[0105] 403. When the controller determines that each mirror data has not been tampered with, it burns each mirror data onto the vehicle-mounted chip.
[0106] In the above technical solution, when each mirror data has not been tampered with, that is, each actually received mirror data has not been damaged by an attacker, each mirror data can be burned onto the vehicle-mounted chip to put the vehicle-mounted chip into use.
[0107] In summary, method 400 provides another method for processing mirror data. Since the signature of the digest of the mirror data is stored at the head of the slave mirror partition (the head also stores other content, such as the size of the slave mirror partition, the running entity of the mirror data, etc.), the signature of the digest of the slave mirror partition is stored in the master mirror partition (the digest of the slave mirror partition is the digest of the information at the head of the slave mirror partition). After the controller of the vehicle-mounted chip receives the mirror data packet, it can determine whether the information at the head of the slave mirror partition is trustworthy based on the signature of the digest of the slave mirror partition stored in the master mirror partition. Since the signature of the digest of the mirror data is stored at the head of the slave mirror partition, that is, it can be obtained whether the signature of the digest of the mirror data is trustworthy. When the signature of the digest of the mirror data is trustworthy, the signature of the digest of the mirror data is decrypted using the public key to obtain the standard digest of the mirror data; the mirror data is calculated using the first digest algorithm to obtain the actual digest (test digest) of the mirror data; according to the standard digest of the mirror data and the actual digest of each mirror data, it can be obtained whether the mirror data has been tampered with. That is, whether each mirror data actually received by the controller of the vehicle-mounted chip has been tampered with. In this way, it can be determined whether the mirror data packet received by the controller is available, improving the security of the data burned onto the vehicle-mounted chip.
[0108] Exemplarily, as follows, taking the case where the controller receives the mirror data packet of the vehicle-mounted SOC chip, specifically taking the Figure 3 mirror data packet shown as an example, the process of the controller using this mirror data packet is described.
[0109] After the controller receives this mirror data packet, it first checks the master mirror partition of the mirror data packet, and uses the public key to decrypt the signature of the digest of the slave mirror partition 1 and the signature of the digest of the slave mirror partition 2 stored in the master mirror partition (where the digest of the slave mirror partition 1 is the digest of the information at the head of the slave mirror partition 1, and the digest of the slave mirror partition 2 is the digest of the information at the head of the slave mirror partition 2), to obtain the digest of the slave mirror partition 1 and the digest of the slave mirror partition 2; the MD5 digest algorithm is used to calculate the digest of the slave mirror partition 1 and the digest of the slave mirror partition 2 respectively to obtain the information at the head of the slave mirror partition 1 and the information at the head of the slave mirror partition 2, and the content in the head of the actually received slave mirror partition 1 and the content in the head of the slave mirror partition 2 are verified using the information at the head of the slave mirror partition 1 and the information at the head of the slave mirror partition 2.
[0110] When the content in the head of the actually received slave mirror partition 1 and the content in the head of the slave mirror partition 2 are correct, the signature of the digest of the mirror data 1 stored at the head of the slave mirror partition 1 is determined, and the mirror data 1 stored in the data part of the actually received slave mirror partition 1 is verified whether it has been tampered with using the signature of the digest of the mirror data 1.
[0111] When the actually received mirror data 1 is not tampered with, use the running entity of the mirror data 1 to burn the mirror data 1 onto the vehicle-mounted chip, and then determine the address of the head of the secondary mirror partition 2 according to the offset of the head address of the secondary mirror partition 2 stored in the head of the primary mirror partition 1; determine the signature of the digest of the mirror data 2 stored in the head of the secondary mirror partition 2 according to the address of the head of the secondary mirror partition 2, and use the signature of the digest of the mirror data 2 to verify whether the mirror data 2 stored in the data part of the actually received secondary mirror partition 2 is tampered with. When the actually received mirror data 2 is not tampered with, use the running entity of the mirror data 2 to burn the mirror data 2 onto the vehicle-mounted chip.
[0112] Figure 5 It is a schematic structural diagram of a device for processing mirror data provided by an embodiment of the present application.
[0113] Exemplarily, as Figure 5 shown, the device 500 includes:
[0114] A second receiving module 501, configured to receive a mirror request from a user, where the mirror request is used to request each mirror data to be burned onto the vehicle-mounted chip;
[0115] A second determining module 502, configured to determine the signature of the digest of the mirror data in response to the mirror request;
[0116] A storage module 503, configured to store the signature of the digest of the mirror data in the head of the secondary mirror partition in the mirror data packet according to the burning process of the data to be burned on the vehicle-mounted chip, and store the mirror data in the secondary mirror partition;
[0117] The second determining module 502 is further configured to determine the signature of the digest of the secondary mirror partition, and store the signatures of the digests of each secondary mirror partition in the primary mirror partition in the mirror data packet;
[0118] A sending module 504, configured to send the mirror data packet to the controller of the vehicle-mounted chip.
[0119] Optionally, the second determining module 502 is specifically further configured to calculate the digest of the mirror data by using a preset first digest algorithm, and determine the signature of the digest of the mirror data by encrypting the digest of the mirror data with a preset private key.
[0120] Optionally, the second determining module 502 is specifically further configured to calculate the digest of the secondary mirror partition by using a second digest algorithm, where the digest is the digest of the information in the head of the secondary mirror partition; and determine the signature of the digest of the secondary mirror partition by encrypting the digest of the secondary mirror partition with a private key.
[0121] Figure 6 It is a schematic structural diagram of another device for processing mirror image data provided by an embodiment of the present application.
[0122] Exemplarily, as Figure 6 shown, the device 600 includes:
[0123] A first receiving module 601, configured to receive a mirror image data packet sent by a server, where the mirror image data packet includes each piece of mirror image data to be burned onto an in-vehicle chip, the mirror image data packet includes a main mirror image partition and at least one secondary mirror image partition, and the secondary mirror image partition includes a header and corresponding mirror image data;
[0124] A first determining module 602, configured to: when determining that the signature of the summary of the mirror image data stored in the header of the secondary mirror image partition is trustworthy according to the signature of the summary of the secondary mirror image partition stored in the main mirror image partition, determine whether the mirror image data has been tampered with according to the signature of the summary of the mirror image data and the mirror image data;
[0125] A burning module, configured to burn the mirror image data onto the in-vehicle chip when the mirror image data has not been tampered with.
[0126] Optionally, the first determining module 602 is specifically configured to decrypt the signature of the summary of the secondary mirror image partition by using a preset public key to obtain the summary of the secondary mirror image partition; calculate the summary of the secondary mirror image partition by using a preset second summary algorithm to obtain the information of the header of the secondary mirror image partition; and determine whether the signature of the summary of the mirror image data is trustworthy according to the information of the header of the secondary mirror image partition and the signature of the summary of the mirror image data.
[0127] Optionally, the first determining module 602 is specifically configured to decrypt the signature of the summary of the mirror image data by using a private key to obtain the standard summary of the mirror image data; calculate the test summary of the mirror image data by using a first summary algorithm; and determine whether the mirror image data has been tampered with according to the test summary of the mirror image data and the standard summary of the mirror image data.
[0128] Optionally, the first determining module 602 is specifically further configured to determine that the mirror image data has not been tampered with when the test summary of the mirror image data is the same as the standard summary of the mirror image data; and determine that the mirror image data has been tampered with when the test summary of the mirror image data is different from the standard summary of the mirror image data.
[0129] Figure 7 It is a schematic structural diagram of a server for processing mirror image data provided by an embodiment of the present application.
[0130] Exemplarily, as Figure 7As shown in the figure, the server 700 includes: a memory 701, a processor 702, and a computer program 703 stored in the memory 701 and running on the processor 702. When the processor 702 executes the computer program 703, the server 700 can execute any of the methods for processing mirror data introduced above.
[0131] In this embodiment, the server can be divided into functional modules according to the above method examples. For example, each functional module can be corresponded, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is illustrative, only a logical function division, and there can be other division methods in actual implementation.
[0132] In the case of corresponding each function to divide each functional module, the server may include: a receiving module, a determining module, a storage module, a sending module, etc. It should be noted that all relevant contents of each step involved in the above method embodiment can be cited in the function description of the corresponding functional module, and will not be elaborated here.
[0133] The server provided in this embodiment is used to execute the above method for processing mirror data, so it can achieve the same effect as the above implementation method.
[0134] In the case of adopting an integrated unit, the server may include a processing module and a storage module. Among them, the processing module can be used to control and manage the actions of the server. The storage module can be used to support the server to execute mutual program codes and data, etc.
[0135] Figure 8 It is a schematic structural diagram of a vehicle provided by an embodiment of the present application.
[0136] Exemplarily, as Figure 8 shown, the vehicle 800 includes: an in-vehicle chip 801, and the in-vehicle chip 801 includes: a memory 802, a controller 803, and a computer program 804 stored in the memory 802 and running on the controller 803. When the controller 803 executes the computer program 804, the controller 803 can execute any of the methods for processing mirror data introduced above.
[0137] In this embodiment, the controller can be divided into functional modules according to the above method examples. For example, each functional module can be corresponded, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is illustrative, only a logical function division, and there can be other division methods in actual implementation.
[0138] In the case of dividing into respective functional modules corresponding to each function, the controller may include: a receiving module, a determining module, etc. It should be noted that all relevant contents of each step involved in the above method embodiment can be cited in the function description of the corresponding functional module, and will not be elaborated here.
[0139] The controller provided in this embodiment is used to execute the above method for processing mirror data, so the same effect as the above implementation method can be achieved.
[0140] In the case of adopting an integrated unit, the controller may include a processing module and a storage module. Among them, the processing module may be used to control and manage the actions of the controller. The storage module may be used to support the controller to execute mutual program codes and data, etc.
[0141] Among them, the processing module may be a processor or a controller, which can implement or execute various exemplary logic blocks, modules and circuits described in combination with the disclosure content of this application. The processor may also be a combination for implementing computing functions, such as including a combination of one or more microprocessors, a combination of digital signal processing (DSP) and a microprocessor, etc. The storage module may be a memory.
[0142] This embodiment provides a computer-readable storage medium, in which instructions are stored. When the instructions run on a computer or a processor, the computer or the processor is enabled to execute any one of the methods for processing mirror data introduced above.
[0143] This embodiment also provides a computer program product containing instructions. When the computer program product runs on a computer or a processor, the computer or the processor is enabled to execute the above related steps to implement any one of the methods for processing mirror data introduced above.
[0144] Among them, the server, vehicle, computer-readable storage medium, computer program product containing instructions or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved by them can refer to the beneficial effects in the corresponding methods provided above, and will not be elaborated here.
[0145] Through the description of the above embodiments, those skilled in the art can understand that for the convenience and conciseness of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0146] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.
[0147] The above content is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for processing mirror image data, characterized in that, The method is executed by a controller of an in-vehicle chip, and the method includes: Receiving a mirror data packet sent by a server, where the mirror data packet includes various mirror data to be burned onto the in-vehicle chip, the mirror data packet includes a main mirror partition and at least one secondary mirror partition, and the secondary mirror partition includes a header and corresponding mirror data; When it is determined that the signature of the digest of the mirror data stored in the header of the secondary mirror partition is credible according to the signature of the digest of the secondary mirror partition stored in the main mirror partition, determining whether the mirror data is tampered with according to the signature of the digest of the mirror data and the mirror data; When the mirror data is not tampered with, burning the mirror data onto the in-vehicle chip; Among them, the process of judging the credibility of the signature of the digest of the mirror data includes: Decrypting the signature of the digest of the secondary mirror partition by using a preset public key to obtain the digest of the secondary mirror partition, where the digest of the secondary mirror partition is the digest of the information in the header of the secondary mirror partition; Calculating the digest of the secondary mirror partition by using a preset second digest algorithm to obtain the information in the header of the secondary mirror partition; Determining whether the signature of the digest of the mirror data is credible according to the information in the header of the secondary mirror partition and the signature of the digest of the mirror data; Among them, the header of the secondary mirror partition further includes the size of the secondary mirror partition, the head address offset corresponding to the next secondary mirror partition of the secondary mirror partition, the running entity of the mirror data, and the loading address. The size of the secondary mirror partition is used to verify the actual size of the secondary mirror partition, the head address offset is used to determine the address difference between the head address of the next secondary mirror partition and the head address of the current secondary mirror partition, the head address refers to the address of the header of the secondary mirror partition, the running entity is used to indicate the execution object of the mirror data, and the loading address is used to indicate the storage address of the mirror data in the secondary mirror partition.
2. The method according to claim 1, wherein The determining whether the mirror data is tampered with according to the signature of the digest of the mirror data and the mirror data includes: Decrypting the signature of the digest of the mirror data by using a private key to obtain the standard digest of the mirror data; Calculating the mirror data by using a first digest algorithm to obtain the test digest of the mirror data; Determining whether each piece of mirror data is tampered with according to the test digest of the mirror data and the standard digest of the mirror data.
3. The method according to claim 2, wherein The determining whether the mirror data is tampered with according to the test digest of the mirror data and the standard digest of the mirror data includes: When the test digest of the mirror data is the same as the standard digest of each piece of mirror data, determining that the mirror data is not tampered with; When the test digest of the mirror data is different from the standard digest of each piece of mirror data, determining that the mirror data is tampered with.
4. A method for processing mirror image data, characterized in that, The method is executed by a server, and the method includes: Receiving a mirror request from a user, where the mirror request is used to request various mirror data to be burned onto an in-vehicle chip; In response to the mirror request, determine the signature of the digest of the mirror data; According to the burning process of the data to be burned on the vehicle-mounted chip, store the signature of the digest of the mirror data at the head of the slave mirror partition in the mirror data packet, and store each of the mirror data in the slave mirror partition; Determine the signature of the digest of the slave mirror partition, and store the signatures of the digests of each of the slave mirror partitions in the master mirror partition in the mirror data packet; Send the mirror data packet to the controller of the vehicle-mounted chip; Moreover, the method further includes: Store the size of the slave mirror partition, the head address offset corresponding to the next slave mirror partition of the slave mirror partition, the running entity of the mirror data, and the loading address at the head of the slave mirror partition. The size of the slave mirror partition is used to verify the actual size of the slave mirror partition, the head address offset is used to determine the address difference between the head address of the next slave mirror partition and the head address of the current slave mirror partition. The head address refers to the address of the head of the slave mirror partition. The running entity is used to indicate the execution object of the mirror data, and the loading address is used to indicate the storage address of the mirror data in the slave mirror partition.
5. The method according to claim 4, characterized in that, The determining the signature of the digest of the mirror data includes: Calculate the mirror data by using a preset first digest algorithm to determine the digest of the mirror data; Encrypt the digest of the mirror data by using a preset private key to determine the signature of the digest of the mirror data.
6. The method according to claim 4, characterized in that, The determining the signature of the digest of the slave mirror partition includes: Calculate the information at the head of the slave mirror partition by using a second digest algorithm to obtain the digest of the slave mirror partition, and the digest is the digest of the information at the head of the slave mirror partition; Encrypt the digest of the slave mirror partition by using a private key to determine the signature of the digest of the slave mirror partition.
7. An apparatus for processing mirror image data, characterized in that, The device is applied to the controller of the vehicle-mounted chip, and the device includes: A first receiving module, configured to receive a mirror data packet sent by a server. The mirror data packet includes each mirror data to be burned onto the vehicle-mounted chip. The mirror data packet includes a master mirror partition and at least one slave mirror partition. The slave mirror partition includes a head and corresponding mirror data; A first determining module, configured to determine that when the signature of the digest of the mirror data stored at the head of the slave mirror partition is credible according to the signature of the digest of the slave mirror partition stored in the master mirror partition, determine whether the mirror data is tampered with according to the signature of the digest of the mirror data and each of the mirror data; A burning module, configured to burn the mirror data onto the vehicle-mounted chip when the mirror data is not tampered with; The first determining module is specifically configured to: Decrypt the signature of the digest of the slave mirror partition by using a preset public key to obtain the digest of the slave mirror partition. The digest of the slave mirror partition is the digest of the information at the head of the slave mirror partition; Calculate the information at the head of the slave mirror partition by using a preset second digest algorithm to obtain the information at the head of the slave mirror partition; Determine whether the signature of the digest of the mirror data is credible according to the information from the head of the mirror partition and the signature of the digest of the mirror data; Wherein, the head of the slave mirror partition further includes the size of the slave mirror partition, the head address offset corresponding to the next slave mirror partition of the slave mirror partition, the running entity of the mirror data, and the loading address. The size of the slave mirror partition is used to verify the actual size of the slave mirror partition. The head address offset is used to determine the address difference between the head address of the next slave mirror partition and the head address of the current slave mirror partition. The head address refers to the address of the head of the slave mirror partition. The running entity is used to indicate the execution object of the mirror data. The loading address is used to indicate the storage address of the mirror data in the slave mirror partition.
8. An apparatus for processing mirror image data, characterized in that, The device is applied to a server, and the device includes: A second receiving module, configured to receive a mirror request from a user, where the mirror request is used to request each mirror data to be burned to the in-vehicle chip; A second determining module, configured to determine the signature of the digest of the mirror data in response to the mirror request; A storage module, configured to store the signature of the digest of the mirror data in the head of the slave mirror partition in the mirror data packet according to the burning process of the data to be burned on the in-vehicle chip, and store each mirror data in the slave mirror partition; The second determining module is further configured to determine the signature of the digest of the slave mirror partition, and store the signatures of the digests of each slave mirror partition in the master mirror partition in the mirror data packet; A sending module, configured to send the mirror data packet to a controller of the in-vehicle chip; The storage module is further configured to store the size of the slave mirror partition, the head address offset corresponding to the next slave mirror partition of the slave mirror partition, the running entity of the mirror data, and the loading address in the head of the slave mirror partition. The size of the slave mirror partition is used to verify the actual size of the slave mirror partition. The head address offset is used to determine the address difference between the head address of the next slave mirror partition and the head address of the current slave mirror partition. The head address refers to the address of the head of the slave mirror partition. The running entity is used to indicate the execution object of the mirror data. The loading address is used to indicate the storage address of the mirror data in the slave mirror partition.
9. A system for processing mirror image data, characterized in that, The system includes a vehicle and a server. The vehicle includes an in-vehicle chip. The controller of the in-vehicle chip is configured to execute the method for processing mirror data according to any one of claims 1 to 3, and the server is configured to execute the method for processing mirror data according to claim 5 or 6.
Citation Information
Patent Citations
Encryption and decryption method and device for mirror image verification, and medium
CN111125725A
Mirror image verification method and device for embedded system, equipment and storage medium
CN112148314A