A TBOX upgrading method, device, TBOX and system
By introducing a mechanism in TBOX to perform signature verification on MCU and OPENCPU respectively, the risk of MCU upgrade package being tampered with in the existing technology is solved, and each processor can independently verify its own security upgrade, thereby improving the security of TBOX upgrade.
Patent Information
- Application Number
- CN202310080334.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-18
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2043-01-18
Smart Images

Figure CN116055204B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of automotive electronics technology, and more particularly to a TBOX upgrading method, device, TBOX, and system. Background Art
[0002] TBOX (Telematics BOX) is the core controller for vehicle informatization. It is used to collect vehicle bus signals in real time and connect to the TSP backend via 4G / 5G to realize functions such as vehicle status upload, vehicle fault reporting, remote diagnosis, vehicle alarm, and remote control. Users can remotely control the vehicle and remotely diagnose the vehicle health status through a mobile phone app.
[0003] Most of the current TBOXs have two processors: MCU (Microcontroller Unit) and OPENCPU. Figure 1 When remotely upgrading the TBOX, the IoV server usually sends the upgrade package of the MCU and OPENCPU as a whole to the OPENCPU. The OPENCPU verifies and decrypts the upgrade package, and then uses the decrypted upgrade package to upgrade the OPENCPU and MCU separately.
[0004] In the prior art, since the MCU upgrade package is verified and decrypted by OPENCPU, it does not comply with the security principle that each processor independently verifies its own upgrade package, and there is a risk that the MCU upgrade package will be tampered with in OPENCPU. Summary of the Invention
[0005] In view of this, the present invention discloses a TBOX upgrade method, device, TBOX and system, so as to realize signature verification of MCU software package by MCU and signature verification of OPENCPU by OPENCPU, which complies with the security principle that each processor independently verifies its own upgrade package, thereby effectively avoiding the risk of MCU upgrade package being tampered with in OPENCPU.
[0006] A TBOX upgrade method is applied to OPENCPU in the TBOX, and the upgrade method includes:
[0007] Obtain the TBOX upgrade package from the Internet of Vehicles server;
[0008] Processing the TBOX upgrade package to obtain a TBOX original file, wherein the TBOX original file includes: an MCU software package, an MCU software package signature file, an OPENCPU software package, and an OPENCPU software package signature file;
[0009] If the MCU software package and the MCU software package signature file exist, sending the MCU software package signature file to the MCU in the TBOX, and having the MCU perform signature verification on the MCU software package;
[0010] When receiving a message from the MCU indicating that the signature verification of the MCU software package is successful, upgrading the MCU based on the MCU software package;
[0011] When the MCU software package and the MCU software package signature file do not exist, or when the MCU is upgraded successfully, if the OPENCPU software package and the OPENCPU software package signature file exist, performing signature verification on the OPENCPU software package based on the OPENCPU software package signature file;
[0012] When the signature verification of the OPENCPU software package succeeds, the OPENCPU is upgraded based on the OPENCPU software package.
[0013] Optionally, the step of obtaining the TBOX upgrade package from the Internet of Vehicles server includes:
[0014] Obtaining a remote upgrade instruction issued by the Internet of Vehicles server;
[0015] Extract the Manifest file download address from the remote upgrade instruction;
[0016] Download the corresponding Manifest file based on the Manifest file download address;
[0017] Parse the manifest file to obtain the TBOX upgrade package download address and the standard hash value of the TBOX upgrade package;
[0018] Download the TBOX upgrade package from the Internet of Vehicles server based on the TBOX upgrade package download address.
[0019] Optionally, the step of processing the TBOX upgrade package to obtain the TBOX original file includes:
[0020] The calculated current hash value of the TBOX upgrade package;
[0021] When the current hash value and the standard hash value are the same, performing a format inverse transformation on the TBOX upgrade package to obtain a TBOX encrypted upgrade package;
[0022] Decrypting the TBOX encrypted upgrade package to obtain a TBOX upgrade package compressed file;
[0023] The compressed file of the TBOX upgrade package is decompressed to obtain the original TBOX file.
[0024] Optionally, the step of performing signature verification on the OPENCPU software package based on the OPENCPU software package signature file includes:
[0025] Calculate the first MD5 value of the OPENCPU software package;
[0026] Decrypt the OPENCPU software package signature file to obtain a first standard MD5 value;
[0027] The first MD5 value is compared with the first standard MD5 value, and the signature of the OPENCPU software package is verified. When the first MD5 value is equal to the first standard MD5 value, it is determined that the signature verification of the OPENCPU software package is successful.
[0028] Optionally, sending the MCU software package signature file to the MCU in the TBOX, and having the MCU perform signature verification on the MCU software package, includes:
[0029] Calculate the second MD5 value of the MCU software package;
[0030] The second MD5 value and the MCU software package signature file are sent to the MCU, and the MCU decrypts the second standard MD5 value from the MCU software package signature file and compares the second MD5 value with the second standard MD5 value to perform signature verification on the MCU software package.
[0031] A TBOX upgrade device, applied to the OPENCPU in the TBOX, comprising:
[0032] An upgrade package acquisition unit, used to obtain the TBOX upgrade package from the Internet of Vehicles server;
[0033] An upgrade package processing unit is used to process the TBOX upgrade package to obtain a TBOX original file, wherein the TBOX original file includes: an MCU software package, an MCU software package signature file, an OPENCPU software package, and an OPENCPU software package signature file;
[0034] A first judging unit, configured to judge whether the MCU software package and the MCU software package signature file exist;
[0035] a sending unit, configured to, if the first judging unit determines that the result is yes, send the MCU software package signature file to the MCU in the TBOX, so that the MCU performs signature verification on the MCU software package;
[0036] a first upgrading unit, configured to upgrade the MCU based on the MCU software package when a message indicating that the MCU software package is successfully verified is received;
[0037] a second judging unit, configured to continue judging whether the OPENCPU software package and the OPENCPU software package signature file exist when the first judging unit judges no or the first upgrading unit successfully upgrades the MCU;
[0038] a signature verifying unit, configured to verify the signature of the OPENCPU software package based on the OPENCPU software package signature file when the second judging unit judges yes;
[0039] a second upgrading unit, configured to upgrade the OPENCPU based on the OPENCPU software package when the OPENCPU software package is successfully verified.
[0040] A TBOX, comprising an OPENCPU and an MCU;
[0041] the OPENCPU comprises the upgrading device of the TBOX in claim 6;
[0042] the MCU is connected with the OPENCPU and is configured to verify the signature of the MCU software package based on the MCU software package signature file sent by the OPENCPU.
[0043] An upgrading system of a TBOX, comprising an Internet of Vehicles server and the TBOX in claim 7;
[0044] the Internet of Vehicles server is configured to generate a TBOX upgrading package;
[0045] the TBOX is configured to acquire the TBOX upgrading package from the Internet of Vehicles server and upgrade based on the TBOX upgrading package.
[0046] Optionally, the process in which the Internet of Vehicles server generates the TBOX upgrading package comprises:
[0047] compiling MCU software source code to generate an MCU software package;
[0048] verifying the signature of the MCU software package to obtain an MCU software package signature file;
[0049] packing the MCU software package and the MCU software package signature file into a first package file;
[0050] compiling OPENCPU software source code to generate an OPENCPU software package;
[0051] sign the OPENCPU software package to obtain an OPENCPU software package signature file;
[0052] pack the OPENCPU software package and the OPENCPU software package signature file into a second package file;
[0053] place the first package file and the second package file in the same directory to obtain a TBOX original file;
[0054] compress the TBOX original file to obtain a TBOX upgrade package compressed file;
[0055] encrypt the TBOX upgrade package compressed file by using a preset encryption algorithm to obtain a TBOX encrypted upgrade package;
[0056] convert the format of the TBOX encrypted upgrade package to obtain the TBOX upgrade package.
[0057] Optionally, the signing of the MCU software package to obtain an MCU software package signature file comprises:
[0058] calculating a second MD5 value of the MCU software package;
[0059] encrypting the second MD5 value by using a first private key to obtain the MCU software package signature file.
[0060] Optionally, the signing of the OPENCPU software package to obtain an OPENCPU software package signature file comprises:
[0061] calculating a first MD5 value of the OPENCPU software package;
[0062] encrypting the first MD5 value by using a second private key to obtain the OPENCPU software package signature file.
[0063] Optionally, the preset encryption algorithm comprises an AES128 key.
[0064] Optionally, the vehicle networking server is further configured to:
[0065] calculating a standard hash value of the TBOX upgrade package by using a preset algorithm;
[0066] placing the standard hash value and the TBOX upgrade package in a Manifest file at a TBOX upgrade package download address corresponding to the vehicle networking server;
[0067] storing the Manifest file.
[0068] From the above technical solution, it can be seen that the present invention discloses a TBOX upgrade method, device, TBOX and system, OPENCPU obtains a TBOX upgrade package from a car networking server, processes the TBOX upgrade package to obtain a TBOX original file, when it is determined that the MCU package and the MCU package signature file in the TBOX original file are both present, the MCU package signature file is sent to the MCU in the TBOX, and the MCU package is signature-verified by the MCU, and when a message is received from the MCU that the MCU package signature is successfully verified, the MCU is upgraded based on the MCU package; when the MCU package and the MCU package signature file do not exist, or the MCU is successfully upgraded, when it is determined that the OPENCPU package and the OPENCPU package signature file are both present, the OPENCPU package is signature-verified based on the OPENCPU package signature file, and when the OPENCPU package signature is successfully verified, the OPENCPU is upgraded based on the OPENCPU package. In the present invention, the MCU performs signature verification on the MCU package, and the OPENCPU performs signature verification on the OPENCPU package, so as to comply with the security principle that each processor independently verifies its own upgrade package, thereby effectively avoiding the risk of the MCU upgrade package being tampered with in the OPENCPU. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the disclosed drawings without any creative work.
[0070] Figure 1 This is a schematic diagram of the structure of the entities involved in TBOX remote upgrade;
[0071] Figure 2 This is a flow chart of a TBOX upgrade method disclosed in an embodiment of the present invention;
[0072] Figure 3 A schematic diagram of a public-private key pair for signing and verifying MCU software disclosed in an embodiment of the present invention;
[0073] Figure 4 A schematic diagram of a public and private key pair for signing and verifying OPENCPU software disclosed in an embodiment of the present invention;
[0074] Figure 5 This is a flow chart of a method for obtaining a TBOX upgrade package from an Internet of Vehicles server disclosed in an embodiment of the present invention;
[0075] Figure 6This is a flow chart of a method for processing a TBOX upgrade package to obtain a TBOX original file disclosed in an embodiment of the present invention;
[0076] Figure 7 A schematic diagram of encrypting and decrypting an AES128 key for a TBOX upgrade package disclosed in an embodiment of the present invention;
[0077] Figure 8 A schematic structural diagram of a TBOX upgrading device disclosed in an embodiment of the present invention;
[0078] Figure 9 This is a flow chart of a method for generating a TBOX upgrade package by an Internet of Vehicles server disclosed in an embodiment of the present invention. DETAILED DESCRIPTION
[0079] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0080] The embodiment of the present invention discloses a TBOX upgrade method, device, TBOX and system. An OPENCPU obtains a TBOX upgrade package from an Internet of Vehicles server, processes the TBOX upgrade package to obtain a TBOX original file, and when it is determined that both an MCU software package and an MCU software package signature file exist in the TBOX original file, sends the MCU software package signature file to an MCU in the TBOX, and the MCU performs signature verification on the MCU software package. When a message indicating that the MCU software package signature verification is successful is received from the MCU, the MCU is upgraded based on the MCU software package. When the MCU software package and the MCU software package signature file do not exist, or the MCU is successfully upgraded, when it is determined that both the OPENCPU software package and the OPENCPU software package signature file exist, the OPENCPU software package is signature verified based on the OPENCPU software package signature file, and when the OPENCPU software package signature verification is successful, the OPENCPU is upgraded based on the OPENCPU software package. In the present invention, the MCU performs signature verification on the MCU software package, and the OPENCPU performs signature verification on the OPENCPU software package, thereby complying with the security principle that each processor independently verifies its own upgrade package, thereby effectively avoiding the risk of the MCU upgrade package being tampered with in the OPENCPU.
[0081] See also Figure 2 , a flowchart of a TBOX upgrade method disclosed in an embodiment of the present invention, the upgrade method is applied to the OPENCPU in the TBOX, the upgrade method includes:
[0082] Step S101: Obtain a TBOX upgrade package from the Internet of Vehicles server.
[0083] In practical applications, the TBOX upgrade package may be a CBF file. In this embodiment, the CBF file is a user-defined binary format file, and the format can be defined by the user.
[0084] Step S102: Process the TBOX upgrade package to obtain the TBOX original file.
[0085] The TBOX original files include: MCU software package, MCU software package signature file, OPENCPU software package, and OPENCPU software package signature file.
[0086] In actual applications, the Internet of Vehicles server can generate a public and private key pair for MCU software signature and verification through the RSA2048 algorithm. The public key is preset in the secure storage area of the MCU when the TBOX leaves the factory, and is used to verify the signature of the MCU software package when the MCU software is upgraded after the TBOX leaves the factory; the private key is stored in the secure storage area of the Internet of Vehicles server where the upgrade package is made, and is used to sign the MCU software package. In this embodiment, the public key is stored in the secure storage area of the MCU, and the private key is stored in the secure storage area of the Internet of Vehicles server where the upgrade package is made. Figure 3 As shown in the figure, the public and private key pair for MCU signature verification is represented by public key 1 and private key 1.
[0087] Example: RSA2048, PKCS8 format
[0088] Public Key 1:
[0089] -----BEGIN PUBLIC KEY-----
[0090] MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtmimEx+WThTcNqg5P5yU
[0091] LEm3IdTITdGsnA+ekLEKFoBBcPw5yxp1 / kMQBdkJruaotjbKFFgOr / x4IVp Y7pVe
[0092] PslNaUjjt3jRprG2sDJWIBT7ICyzBrtOYQfG8P5i / lFZOJRDxJJuVjqWtrhUh5G8
[0093] bcCFHcRGUfTaVcc9LrptX+eZKj9mjsyJLoRQkm9zbuiBcnwNxGGTMYoF b2cu3PF+
[0094] G37iq1PxPCXHT4MZCQaY9 / GlAXXfRBI2Mj7miHvPZfH1ek9YwCaLx5daHaqk1lgh
[0095] oUx688W / 0iIn / c9DermzOgtAHC0eyNFdA782BzHZgt8EGKUeTymgEQkP
[0096] HkPtbNlC
[0097] YQIDAQAB
[0098] -----END PUBLIC KEY-----
[0099] 私钥1:
[0100] -----BEGIN PRIVATE KEY-----
[0101] MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQC2aKYTH5ZOFNw2
[0102] qDk / nJQsSbch1MhN0aycD56QsQoWgEFw / DnLGnX+QxAF2Qmu5qi2Nso UWA6v / Hgh
[0103] WljulV4+yU1pSOO3eNGmsbawMlYgFPsgLLMGu05hB8bw / mL+UVk4lEP Ekm5WOpa2
[0104] uFSHkbxtwIUdxEZR9NpVxz0uum1f55kqP2aOzIkuhFCSb3Nu6IFyfA3EYZ MxigVv
[0105] Zy7c8X4bfuKrU / E8JcdPgxkJBpj38aUBdd9EEjYyPuaIe89l8fV6T1jAJovHl1od
[0106] qqTWWCGhTHrzxb / SIif9z0N6ubM6C0AcLR7I0V0DvzYHMdmC3wQYpR5PKaARCQ8e
[0107] Q+1s2UJhAgMBAAECggEAPb6euMpwbm3RPQ8kkcvGvFcXjnQgeXcIHq uK2R+Ucpln
[0108] jX9TcNS8LB03R0N4a6PYaBWTwd8s2ZV0dJXIlLoq9MXfVkw+CNT04qA1Xt8rGCEC
[0109] AJog3553oZCoXts9VyjiMqy9Y8TNZJLggWlT86 / 5QI1ygej2hLeFUJPoufCRJW0F
[0110] KNAE / +alq58NX5lu5hhK / lhik0sidSxDVgfEdAMOOC0BARQ8uTKMy / fXnl8INNl4
[0111] wB08RsIFsnvdIwC / pvGKjJPDqf0wuN1cIF30aVQzPsxde5s8yaXL5IKM9dbupW9j
[0112] t6ZY6l2L5nomULYydhf0fbTphoV / d3oGPrrJQ / WNIQKBgQDr03f / xHM3zJtj8gbW
[0113] MH7ylRPAeYz / SQvZinpIpeI196fW4y8DWbsJTJIA4GXHNCzg5zcmXfTfOhrgb / nO
[0114] RYyRol7Sg2vc4PVF3A57Jj+Yfy2nG1f0zhMfpFHWRKS6sO9BXPTr8bX / qv7Q4b63
[0115] 0BfvVqcwRedzk7Cs2VXzW8qJ8wKBgQDGA1rzwxsfgQ8iAJ5ccQMp+eUbNovy5pGl
[0116] FRR5smc8YNNW85DgEPQ6Ycq9nVWwNU0mCNHriStSHeGPBH / CE4zK / D2D9IatK1cm
[0117] p2ni4zu / qLnIB2ksK9F7 / 5bjvnvyZGOfBgET5731QcljFQ6m9Qjf4tdZdKLydL4N
[0118] mq6NyoojWwKBgQCrdzeiBRGNObymH9zusZYsBU62POrS1ybBhplA5zQh7y7e5JJT
[0119] SlPfAAiMkJwQChSzdgo4YEpiYFoYY / JrE1CQt1FgmOO9VuefYtA4pGfLFnV4Mj5y
[0120] pb9r20sRkxl / EJT1noQKZdXhzk+2St0jwy8T+5pWVA1kkLb+BowjBNOwFwKBgQCG
[0121] iWESnk2faiDOCX2PcXmk25U+mCEeOGpcr6Xpyb062M6 / FV4p31sRD8CgdHXz80Mn
[0122] xHZcgiZc9NB8S6JCSuYuRJPHRCz9G6VrLfRTo / DEl+8iaWacDGmYxl / O / W1Zk7vc
[0123] IEg7Lglyye / 60iPSbEpLU+TdctIDyi4XMDHJRQP2YQKBgELkAJH2z0tTXi8B7Yr9
[0124] w6AFevNc / CsE5lSJofh4UkJkZciCuxfc5VWfRwIQDQqwV5DNQqxyLgha6z / I2zBn
[0125] p7E2IoXMdpCGXv+hHQ0 / pOeoVLa9QZwfdw59EWJNukhYEiW7TYIL8VpRLcyHK6lR
[0126] iWd9so4k9PEIcG+p+J+3vszI
[0127] -----END PRIVATE KEY-----
[0128] The vehicle networking server can generate the public and private key pair of the OPENCPU software signature and verification by the RSA2048 algorithm. The public key is pre-stored in the secure storage area of the OPENCPU when the TBOX is shipped, and is used for verifying the OPENCPU software package when the OPENCPU software is upgraded after the TBOX is shipped. The private key is stored in the secure storage area of the vehicle networking server for making the upgrade package, and is used for signing the OPENCPU software package. In the embodiment, the public key is stored in the secure storage area of the OPENCPU, and the private key is stored in the secure storage area of the vehicle networking server for making the upgrade package. As shown in FIG. 8, the public and private key pair of the OPENCPU verification is represented by public key 2 and private key 2. Figure 4
[0129] For example: RSA2048, PKCS8 format
[0130] Public key 2:
[0131] -----BEGIN PUBLIC KEY-----
[0132] MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA12Z2BImT px2qJjG+btCL
[0133] 2WCg0WstMPerPc38jsbI1OHbtBmESQ52N2FRYNgHtUw0V2g0UED79NP BMY6HKG96
[0134] / jyppywX3OnypvqXjjFcZANyVmzlmMPsyFOLrqc / 1vSk6ixwhagS / UMGwp sPe+RV
[0135] BlEyZiakjcSjqpKMtEhLsl7 / pFGDttDRQK8KAg+TGYA+cgSYpzZ3VXbb+eWS4ZV5
[0136] sFSXXs6eSXtRsKjtb9ORA5ogoh19VIITddzUqHM3ByfYl4PzmtXOGwtdP3dP5lkZ
[0137] WglkC07ExcmLCioqYQ87zbOdZTzXnRwI7WYIhDviW8a1A8kaKPFWhuv+12U4YJrZ
[0138] AQIDAQAB
[0139] -----END PUBLIC KEY-----
[0140] 私钥2:
[0141] -----BEGIN PRIVATE KEY-----
[0142] MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDX ZnYEiZOnHaom
[0143] Mb5u0IvZYKDRay0w96s9zfyOxsjU4du0GYRJDnY3YVFg2Ae1TDRXaDR QQPv008Ex
[0144] jocob3r+PKmnLBfc6fKm+peOMVxkA3JWbOWYw+zIU4uupz / W9KTqLH CFqBL9QwbC
[0145] mw975FUGUTJmJqSNxKOqkoy0SEuyXv+kUYO20NFArwoCD5MZgD5yBJinNndVdtv5
[0146] 5ZLhlXmwVJdezp5Je1GwqO1v05EDmiCiHX1UghN13NSoczcHJ9iXg / Oa1c4bC10 /
[0147] d0 / mWRlaCWQLTsTFyYsKKiphDzvNs51lPNedHAjtZgiEO+JbxrUDyRoo8VaG6 / 7X
[0148] ZThgmtkBAgMBAAECggEAHAueMCcNj4PARKrTZbBHlS0Mo1e2EZsds7VfPePKAFXL
[0149] +l4cKDr2z20fYGGgV02tvve1YAGmDJGJpP8uv+gL9pBFcpu+G6hmTLFy DDSHGAqO
[0150] 14vkNQjFiqu+EyZ5nG5MDqVsnSpuFoWkmq / / yxzGqUTnL / +2CzNgL / RW155WJMoW
[0151] iovbFD / aEZU5as1pMr9VaFXcn4csomnmsuJK4iUqi+jxLEi9J0o+N / fZt1CSv9ja
[0152] WRat85+X+xJdhQiXU6s1Fhbji3CXvcfTGWUvFmDHIcM7eUpQwchfxPWt nasn+pH0
[0153] rRNGq6MjDH2w38KWvScdjneDOffvL23Z8pitjYvxcQKBgQDwQC / 8zQp+ivKz9Kkp
[0154] 9ZOfjBaxhQRfhR07tpgVUeYeSzhkdissm5v2gm7TlQEMeaHI8P3hAMIegzi fIV2z
[0155] 6jb7WvL0l98wPK7CxBIE+RZajwtAsQxUrnSLRtG5OxH0CHPSGdvRySZ9YuDzVkgx
[0156] SJAachICorJf4W+m / mSaaX9t3QKBgQDlhT2HgpKfHB7zMptNgSboh+10P1U4Mo7Q
[0157] kjxtQeujfElRcXJJ / J0ZK / HeHhOHQaYxiDsmiJDG4EU1J9tjmqE369V / 8l5a9Gz1
[0158] K0EJatmEEH6YlNuus107mvsARgmXZt4SqpL7euvk5U+rcRxUDJZgUcfXf MpvLiPU
[0159] Ea+UVAF / dQKBgF3BPrjRr0G4qYPue0Fjk0tU2NpHxXAdO049MFZJkprJ0eTqdGjB
[0160] BPkK54LsB++9W5RV700qBZbwsFzxIWb / hJtMX7lxtuhVFgHtj / ae2clXPxX swZoe
[0161] Rl6 / sUIuug / YaJJaAv14GOwfdReg2SVaYtnfIAYlRaTDDdZGOi5D8zWFAo GABJEa
[0162] IFAgyrmsg / pFzMz9ETNjLiT0dSHMZaoDOclN / vrCGrS / KWm1VoLhVSIU EWTlAadM
[0163] RgABoXNk7SHV461397zhiqIv7m9em6I4sQ9HNLF / U1ni5R78g+sZg2 / hUP njAUwT
[0164] kJ1phCxr4WVmwuVdOJ1n9ImvHXc1j0qqy7DANuECgYEAjbGokn8Rwgr LIgw0ZDFT
[0165] chBKDD+pcIiz / cZf8UGJ87yDypxgBWSuuG9BnKeggfzX1 / jt3UlWnEVSq7BfqMNC
[0166] C3RXbJy3ivVjpQailMKEuubG2+xHlrif3t3UOhm7n5ZEdFxnP+cIXbUH9Gz URYJl
[0167] 1FjDrCtwK6oBngZeo1FYCZ8=
[0168] -----END PRIVATE KEY-----
[0169] Step S103: Determine whether the MCU software package and the MCU software package signature file exist. If yes, execute step S104; if not, execute step S106.
[0170] This embodiment determines whether to upgrade the MCU by judging whether the MCU software package and the MCU software package signature file exist.
[0171] Step S104: Send the MCU software package signature file to the MCU in the TBOX, and the MCU performs signature verification on the MCU software package.
[0172] Step S105: When receiving a message from the MCU indicating that the signature verification of the MCU software package is successful, the MCU is upgraded based on the MCU software package. When the MCU upgrade is successful, step S106 is executed.
[0173] If OPENCPU receives the message from MCU indicating that the signature verification of the MCU software package is successful, it will start to upgrade the MCU based on the MCU software package. In addition, the MCU will accept the MCU upgrade process initiated by OPENCPU only if the signature verification is successful. Otherwise, it will reject the MCU upgrade process initiated by OPENCPU.
[0174] If the OPENCPU receives the message of the MCU software package signature verification failure sent by the MCU, the OPENCPU terminates the upgrade of the MCU, and stops starting the upgrade of the OPENCPU, that is, the whole upgrade process of the TBOX is terminated.
[0175] In step S106, it is judged whether the OPENCPU software package and the OPENCPU software package signature file exist, if yes, step S107 is executed.
[0176] In the embodiment, if the MCU software package and the MCU software package signature file do not exist, or the MCU upgrade is successful, it is continued to judge whether the OPENCPU software package and the OPENCPU software package signature file exist, if not, the upgrade process is ended, otherwise, if yes, step S107 is executed.
[0177] In step S107, the OPENCPU software package is verified based on the OPENCPU software package signature file.
[0178] In the application, the MCU verifies the MCU software package, and the OPENCPU verifies the OPENCPU software package.
[0179] In step S108, when the OPENCPU software package signature verification is successful, the OPENCPU is upgraded based on the OPENCPU software package.
[0180] In conclusion, the application discloses a kind of upgrade method of TBOX, OPENCPU obtains TBOX upgrade package from Internet of Vehicles server, TBOX upgrade package is handled to obtain TBOX original file, when determining that MCU software package and MCU software package signature file in TBOX original file all exist, MCU software package signature file is sent to MCU in TBOX, MCU software package is verified by MCU, when receiving the message of MCU software package signature verification success sent by MCU, MCU is upgraded based on MCU software package;When MCU software package and MCU software package signature file do not exist, or the upgrade of MCU is successful, in the case where it is determined that OPENCPU software package and OPENCPU software package signature file all exist, OPENCPU software package is verified based on OPENCPU software package signature file, and when OPENCPU software package signature verification is successful, OPENCPU is upgraded based on OPENCPU software package.In the application, MCU verifies MCU software package, and OPENCPU verifies OPENCPU software package, so it meets the security principle that each processor verifies the upgrade package of itself, thereby effectively avoiding the risk that MCU upgrade package is tampered in OPENCPU.
[0181] To further optimize the above embodiment, after step S108, the method can further comprise:
[0182] The upgrade result of the TBOX is fed back to the Internet of Vehicles server.
[0183] The upgrade result of the TBOX can include MCU upgrade success or failure, OPENCPU upgrade success or failure, and TBOX version after upgrade.
[0184] To further optimize the above embodiment, referring to Figure 5 The method flowchart for obtaining the TBOX upgrade package from the Internet of Vehicles server disclosed by the embodiment of the application, that is, step S101 can specifically include:
[0185] Step S201, obtaining a remote upgrade instruction issued by the Internet of Vehicles server.
[0186] When the TBOX needs to be upgraded, the Internet of Vehicles server issues a remote upgrade instruction to the OPENCPU in the TBOX.
[0187] Step S202, extracting a Manifest file download address from the remote upgrade instruction.
[0188] The Manifest file download address is also the URL address of the Manifest file.
[0189] Step S203, downloading the corresponding Manifest file based on the Manifest file download address.
[0190] Step S204, parsing the Manifest file to obtain a TBOX upgrade package download address and a standard hash value of the TBOX upgrade package.
[0191] The standard hash value of the TBOX upgrade package can be a SHA256 hash value of the TBOX upgrade package.
[0192] Step S205, downloading the TBOX upgrade package from the Internet of Vehicles server based on the TBOX upgrade package download address.
[0193] To further optimize the above embodiment, referring to Figure 6 The method flowchart for processing the TBOX upgrade package to obtain the TBOX original file disclosed by the embodiment of the application, that is, step S102 can specifically include:
[0194] Step S301, calculating the current hash value of the TBOX upgrade package.
[0195] The specific calculation process of the current hash value of the TBOX upgrade package can be found in existing mature methods (which can be the same as the calculation method of the standard hash value), such as the SHA256 hash value, and will not be repeated here.
[0196] Step S302: Determine whether the current hash value is the same as the standard hash value. If yes, execute step S303.
[0197] The current hash value and standard hash value of the TBOX upgrade package can both be SHA256 hash values.
[0198] The present invention verifies the authenticity of a TBOX upgrade package by comparing its current hash value with a standard hash value. If the current hash value and the standard hash value are different, the TBOX upgrade package fails verification and the operation ends. Conversely, if the current hash value and the standard hash value are the same, the TBOX upgrade package passes verification and the process continues with step S303.
[0199] Step S303: Perform inverse format conversion on the TBOX upgrade package to obtain a TBOX encrypted upgrade package.
[0200] In actual applications, when the TBOX upgrade package is stored in the Internet of Vehicles server, the TBOX upgrade package can be in a user-defined binary format and the format of the TBOX upgrade package needs to be reversed.
[0201] Step S304: decrypt the TBOX encrypted upgrade package to obtain a compressed file of the TBOX upgrade package.
[0202] In actual application, the AES128 symmetric key is stored in the secure storage area of the Internet of Vehicles server and is used to encrypt the compressed file of the TBOX upgrade package during the TBOX upgrade package production process. At the same time, the AES128 key is preset in the secure storage area of OPENCPU when the TBOX leaves the factory. It is used to decrypt the TBOX encrypted upgrade package when the TBOX is upgraded after leaving the factory. For details, see Figure 7 shown.
[0203] It should be noted that the decryption key used by OPENCPU to decrypt the TBOX encrypted upgrade package is Figure 7 The AES128 key in .
[0204] Step S305: decompress the compressed file of the TBOX upgrade package to obtain the original TBOX file.
[0205] TBOX original files include: MCU software package, MCU software package signature file, OPENCPU software package, and OPENCPU software package signature file.
[0206] To further optimize the above embodiment, step S107 may specifically include:
[0207] Calculate the first MD5 value of the OPENCPU software package;
[0208] Decrypt the OPENCPU software package signature file and obtain the first standard MD5 value;
[0209] The first MD5 value is compared with the first standard MD5 value to perform signature verification on the OPENCPU software package, and when the first MD5 value is equal to the first standard MD5 value, it is determined that the signature verification of the OPENCPU software package is successful.
[0210] Among them, when OPENCPU decrypts the OPENCPU software package signature file, it uses the public key 3 (such as Figure 4 ).
[0211] It should be noted that when the first MD5 value is the same as the first standard MD5 value, the OPENCPU software signature verification succeeds; otherwise, when the first MD5 value is different from the first standard MD5 value, the OPENCPU software signature verification fails.
[0212] To further optimize the above embodiment, step S104 may specifically include:
[0213] Calculate the second MD5 value of the MCU software package;
[0214] The second MD5 value and the MCU software package signature file are sent to the MCU. The MCU decrypts the second standard MD5 value from the MCU software package signature file and compares the second MD5 value with the second standard MD5 value to perform signature verification on the MCU software package.
[0215] Among them, when MCU decrypts the MCU software package signature file, it uses the public key 1 (such as Figure 3 ).
[0216] It should be noted that when the second MD5 value is the same as the second standard MD5 value, the MCU software signature verification is successful. At this time, the MCU sends a message to OPENCPU indicating that the signature verification of the MCU software package is successful. Conversely, when the second MD5 value is different from the second standard MD5 value, the MCU software signature verification fails. At this time, the MCU sends a message to OPENCPU indicating that the signature verification of the MCU software package has failed.
[0217] Corresponding to the above method embodiment, the present invention also discloses a TBOX upgrading device.
[0218] See also Figure 8, a schematic structural diagram of a TBOX upgrading device disclosed in an embodiment of the present invention, the device includes:
[0219] The upgrade package obtaining unit 401 is configured to obtain the TBOX upgrade package from the Internet of Vehicles server.
[0220] The upgrade package processing unit 402 is used to process the TBOX upgrade package to obtain the TBOX original file.
[0221] The TBOX original files include: MCU software package, MCU software package signature file, OPENCPU software package, and OPENCPU software package signature file.
[0222] The first determining unit 403 is configured to determine whether the MCU software package and the MCU software package signature file exist.
[0223] The sending unit 404 is configured to send the MCU software package signature file to the MCU in the TBOX if the first judging unit 403 determines that the result is yes, so that the MCU performs signature verification on the MCU software package.
[0224] The first upgrading unit 405 is configured to upgrade the MCU based on the MCU software package upon receiving a message from the MCU indicating that the signature verification of the MCU software package is successful.
[0225] The second judging unit 406 is configured to, when the first judging unit 403 judges no, or the first upgrading unit 405 upgrades the MCU successfully, continue to judge whether the OPENCPU software package and the OPENCPU software package signature file exist.
[0226] The signature verification unit 407 is configured to perform signature verification on the OPENCPU software package based on the OPENCPU software package signature file if the second judgment unit 406 determines that the result is yes.
[0227] The second upgrading unit 408 is configured to upgrade OPENCPU based on the OPENCPU software package when the signature verification of the OPENCPU software package succeeds.
[0228] It should be noted that, for the specific working principles of the various components in the device embodiment, please refer to the corresponding part of the method embodiment, which will not be repeated here.
[0229] In summary, the present invention discloses a TBOX upgrade device, OPENCPU obtains a TBOX upgrade package from a car networking server, processes the TBOX upgrade package to obtain a TBOX original file, and when it is determined that the MCU software package and the MCU software package signature file exist in the TBOX original file, the MCU software package signature file is sent to the MCU in the TBOX, and the MCU software package is signature-verified by the MCU. When a message is received from the MCU that the MCU software package is successfully verified, the MCU is upgraded based on the MCU software package; when the MCU software package and the MCU software package signature file do not exist, or when the MCU is successfully upgraded, when it is determined that the OPENCPU software package and the OPENCPU software package signature file exist, the OPENCPU software package is signature-verified based on the OPENCPU software package signature file, and when the OPENCPU software package is successfully verified, the OPENCPU is upgraded based on the OPENCPU software package. In the present invention, the MCU performs signature verification on the MCU software package, and the OPENCPU performs signature verification on the OPENCPU software package, so as to meet the security principle that each processor verifies its own upgrade package separately, thereby effectively avoiding the risk of the MCU upgrade package being tampered with in the OPENCPU.
[0230] To further optimize the above embodiment, the upgrade package obtaining unit 401 may be specifically configured to:
[0231] Obtain remote upgrade instructions issued by the Internet of Vehicles server;
[0232] Extract the Manifest file download address from the remote upgrade command;
[0233] Download the corresponding Manifest file based on the Manifest file download address;
[0234] Parse the manifest file to obtain the TBOX upgrade package download address and the standard hash value of the TBOX upgrade package;
[0235] Download the TBOX upgrade package from the Internet of Vehicles server based on the TBOX upgrade package download address.
[0236] To further optimize the above embodiment, the upgrade package processing unit 402 may be specifically configured to:
[0237] The calculated current hash value of the TBOX upgrade package;
[0238] Determine whether the current hash value is the same as the standard hash value;
[0239] If yes, perform inverse format conversion on the TBOX upgrade package to obtain the TBOX encrypted upgrade package;
[0240] The TBOX encrypted upgrade package is decrypted to obtain a TBOX upgrade package compressed file;
[0241] The TBOX upgrade package compressed file is decompressed to obtain a TBOX original file
[0242] To further optimize the above embodiment, the signature verification unit 407 can be specifically configured to:
[0243] calculate a first MD5 value of the OPENCPU software package;
[0244] decrypt the OPENCPU software package signature file to obtain a first standard MD5 value;
[0245] compare the first MD5 value with the first standard MD5 value, perform signature verification on the OPENCPU software package, and determine that the OPENCPU software package is successfully verified when the first MD5 value is equal to the first standard MD5 value.
[0246] To further optimize the above embodiment, the sending unit 404 can be specifically configured to:
[0247] calculate a second MD5 value of the MCU software package;
[0248] send the second MD5 value and the MCU software package signature file to the MCU, decrypt the second standard MD5 value from the MCU software package signature file by the MCU, and compare the second MD5 value with the second standard MD5 value to perform signature verification on the MCU software package.
[0249] It should be noted that the specific working principle of each component in the upgrading device is described in the corresponding part of the method embodiment, and will not be repeated here.
[0250] Corresponding to the above method, the application also discloses a TBOX.
[0251] For details Figure 1 , the TBOX comprises an OPENCPU and an MCU.
[0252] The OPENCPU comprises the upgrading device of the TBOX described in the above embodiment.
[0253] The MCU is connected with the OPENCPU and is configured to perform signature verification on the MCU software package based on the MCU software package signature file sent by the OPENCPU.
[0254] Among them, the upgrading process of the TBOX can be seen in the corresponding part of the method embodiment, and will not be repeated here.
[0255] In summary, the application discloses a TBOX, which comprises an OPENCPU and an MCU, the OPENCPU obtains a TBOX upgrade package from a vehicle networking server, processes the TBOX upgrade package to obtain a TBOX original file, when it is determined that the MCU software package and the MCU software package signature file in the TBOX original file both exist, the MCU software package signature file is sent to the MCU in the TBOX, the MCU performs signature verification on the MCU software package, when a message that the signature verification on the MCU software package is successful and sent by the MCU is received, the MCU is upgraded based on the MCU software package, when the MCU software package and the MCU software package signature file do not exist or the MCU is successfully upgraded, under the condition that it is determined that the OPENCPU software package and the OPENCPU software package signature file both exist, the OPENCPU software package is subjected to signature verification based on the OPENCPU software package signature file, and when the signature verification on the OPENCPU software package is successful, the OPENCPU is upgraded based on the OPENCPU software package. In the application, the MCU performs signature verification on the MCU software package, and the OPENCPU performs signature verification on the OPENCPU software package, thus meeting the security principle that each processor individually verifies the upgrade package of itself, and thus the risk that the MCU upgrade package is tampered with in the OPENCPU is effectively avoided.
[0256] Corresponding to the above-mentioned embodiments, the application further discloses a TBOX upgrade system.
[0257] The TBOX upgrade system comprises a vehicle networking server and the TBOX in the above-mentioned embodiments.
[0258] The vehicle networking server is used for generating a TBOX upgrade package.
[0259] The TBOX is used for obtaining the TBOX upgrade package from the vehicle networking server and upgrading based on the TBOX upgrade package.
[0260] The specific process in which the TBOX obtains the TBOX upgrade package from the vehicle networking server for upgrading can be referred to the corresponding part of the method embodiments, and will not be described here.
[0261] In summary, the application discloses a TBOX upgrade system, which comprises a vehicle networking server and a TBOX, the vehicle networking server generates a TBOX upgrade package, and the TBOX obtains the TBOX upgrade package from the vehicle networking server and upgrades based on the TBOX upgrade package. In the application, the MCU in the TBOX performs signature verification on the MCU software package, and the OPENCPU in the TBOX performs signature verification on the OPENCPU software package, thus meeting the security principle that each processor individually verifies the upgrade package of itself, and thus the risk that the MCU upgrade package is tampered with in the OPENCPU is effectively avoided.
[0262] To further optimize the above embodiment, see Figure 9 , a flowchart of a method for generating a TBOX upgrade package by a vehicle networking server disclosed in an embodiment of the present invention, the method comprising:
[0263] Step S501: compile the MCU software source code to generate an MCU software package.
[0264] Step S502: Sign the MCU software package to obtain the MCU software package signature file.
[0265] The signing process of the MCU software package is as follows: first calculate the second MD5 value of the MCU software package, and then use the first private key (i.e. Figure 3 The private key 1) in the second MD5 value is encrypted to obtain the MCU software package signature file.
[0266] Step S503: Package the MCU software package and the MCU software package signature file into a first package file.
[0267] Step S504: compile the OPENCPU software source code to generate an OPENCPU software package.
[0268] Step S505: Sign the OPENCPU software package to obtain the OPENCPU software package signature file.
[0269] The signing process of the OPENCPU software package is as follows: first calculate the first MD5 value of the OPENCPU software package, and then use the second private key (i.e. Figure 4 2) Encrypt the first MD5 value to obtain the OPENCPU software package signature file.
[0270] It should be noted that the “first” in the first MD5 value and the “second” in the second MD5 value are only used to distinguish that the two MD5 values are MD5 values of two different software packages.
[0271] Step S506: Package the OPENCPU software package and the OPENCPU software package signature file into a second package file.
[0272] Step S507: Put the first package of files and the second package of files into the same directory to obtain the TBOX original files.
[0273] Step S508: compress the TBOX original file to obtain a TBOX upgrade package compressed file.
[0274] Step S509: Encrypt the compressed file of the TBOX upgrade package using a preset encryption algorithm to obtain a TBOX encrypted upgrade package.
[0275] The preset encryption algorithm can be AES128 encryption, and the encryption key can be Figure 7 AES128 key shown
[0276] Step S510: Convert the format of the TBOX encrypted upgrade package to obtain a TBOX upgrade package.
[0277] In actual application, the TBOX encrypted upgrade package can be converted into a user-defined binary format (CBF format) to obtain a CBF file, which is also the TBOX upgrade package.
[0278] In summary, the present invention packages the MCU software package and its signature file into a first package file, and the OPENCPU software package and its signature file into a second package file, placing them in the same directory to obtain the original TBOX file. The original TBOX file is then compressed, encrypted, and format-converted to produce the final TBOX upgrade package. After the connected vehicle server sends the TBOX upgrade package to TBOX, the MCU performs signature verification on the MCU software package, and the OPENCPU performs signature verification on the OPENCPU software package. This adheres to the security principle that each processor independently verifies its own upgrade package, effectively preventing the risk of tampering with the MCU upgrade package on the OPENCPU.
[0279] To further optimize the above embodiment, the Internet of Vehicles server can also be used for:
[0280] Use the preset algorithm to calculate the standard hash value of the TBOX upgrade package;
[0281] Put the standard hash value and the TBOX upgrade package download address corresponding to the TBOX upgrade package on the Internet of Vehicles server into the Manifest file;
[0282] Stores the manifest file.
[0283] The preset algorithm used when calculating the standard hash value of the TBOX upgrade package may be the SHA256 algorithm. The standard hash value may be a SHA256 hash value string.
[0284] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0285] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0286] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A TBOX upgrade method, characterized in that: Applied to OPENCPU in TBOX, the upgrade method includes: Obtain the TBOX upgrade package from the Internet of Vehicles server; Processing the TBOX upgrade package to obtain a TBOX original file, wherein the TBOX original file includes: an MCU software package, an MCU software package signature file, an OPENCPU software package, and an OPENCPU software package signature file; If the MCU software package and the MCU software package signature file exist, sending the MCU software package signature file to the MCU in the TBOX, and having the MCU perform signature verification on the MCU software package; When receiving a message from the MCU indicating that the signature verification of the MCU software package is successful, upgrading the MCU based on the MCU software package; When the MCU software package and the MCU software package signature file do not exist, or when the MCU is upgraded successfully, if the OPENCPU software package and the OPENCPU software package signature file exist, performing signature verification on the OPENCPU software package based on the OPENCPU software package signature file; When the signature verification of the OPENCPU software package succeeds, the OPENCPU is upgraded based on the OPENCPU software package.
2. The upgrade method according to claim 1, characterized in that: The step of obtaining the TBOX upgrade package from the Internet of Vehicles server includes: Obtaining a remote upgrade instruction issued by the Internet of Vehicles server; Extract the Manifest file download address from the remote upgrade instruction; Download the corresponding Manifest file based on the Manifest file download address; Parse the manifest file to obtain the TBOX upgrade package download address and the standard hash value of the TBOX upgrade package; Download the TBOX upgrade package from the Internet of Vehicles server based on the TBOX upgrade package download address.
3. The upgrade method according to claim 1, characterized in that: The step of processing the TBOX upgrade package to obtain the TBOX original file includes: The calculated current hash value of the TBOX upgrade package; When the current hash value and the standard hash value are the same, performing a format inverse transformation on the TBOX upgrade package to obtain a TBOX encrypted upgrade package; Decrypting the TBOX encrypted upgrade package to obtain a TBOX upgrade package compressed file; The compressed file of the TBOX upgrade package is decompressed to obtain the original TBOX file.
4. The upgrade method according to claim 1, characterized in that: The step of performing signature verification on the OPENCPU software package based on the OPENCPU software package signature file includes: Calculate the first MD5 value of the OPENCPU software package; Decrypt the OPENCPU software package signature file to obtain a first standard MD5 value; The first MD5 value is compared with the first standard MD5 value, and signature verification is performed on the OPENCPU software package. When the first MD5 value is equal to the first standard MD5 value, it is determined that the signature verification of the OPENCPU software package is successful.
5. The upgrade method according to claim 1, characterized in that: The step of sending the MCU software package signature file to the MCU in the TBOX, and having the MCU perform signature verification on the MCU software package, includes: Calculate the second MD5 value of the MCU software package; The second MD5 value and the MCU software package signature file are sent to the MCU, and the MCU decrypts the second standard MD5 value from the MCU software package signature file and compares the second MD5 value with the second standard MD5 value to perform signature verification on the MCU software package.
6. A TBOX upgrade device, characterized in that: The OPENCPU used in TBOX, the upgrade device includes: An upgrade package acquisition unit, used to obtain the TBOX upgrade package from the Internet of Vehicles server; An upgrade package processing unit, configured to process the TBOX upgrade package to obtain a TBOX original file, wherein the TBOX original file includes: an MCU software package, an MCU software package signature file, an OPENCPU software package, and an OPENCPU software package signature file; A first judging unit, configured to judge whether the MCU software package and the MCU software package signature file exist; a sending unit, configured to, if the first judging unit determines that the result is yes, send the MCU software package signature file to the MCU in the TBOX, so that the MCU performs signature verification on the MCU software package; a first upgrading unit, configured to upgrade the MCU based on the MCU software package upon receiving a message from the MCU indicating successful signature verification of the MCU software package; a second determining unit configured to, if the first determining unit determines that the OPENCPU software package and the OPENCPU software package signature file exist, continue to determine whether the OPENCPU software package and the OPENCPU software package signature file exist when the first determining unit determines that the OPENCPU software package and the OPENCPU software package signature file exist; a signature verification unit, configured to, if the second judgment unit determines that the result is yes, perform signature verification on the OPENCPU software package based on the OPENCPU software package signature file; The second upgrading unit is configured to upgrade the OPENCPU based on the OPENCPU software package when the signature verification of the OPENCPU software package succeeds.
7. A TBOX, characterized in that: include: OPENCPU and MCU; The OPENCPU includes the TBOX upgrade device according to claim 6; The MCU is connected to the OPENCPU and is used to perform signature verification on the MCU software package based on the MCU software package signature file sent by the OPENCPU.
8. A TBOX upgrade system, characterized in that: include: An Internet of Vehicles server and the TBOX according to claim 7; The Internet of Vehicles server is used to generate a TBOX upgrade package; The TBOX is used to obtain the TBOX upgrade package from the Internet of Vehicles server and perform an upgrade based on the TBOX upgrade package.
9. The upgrade system according to claim 8, characterized in that: The process of generating the TBOX upgrade package by the Internet of Vehicles server includes: Compile the MCU software source code to generate an MCU software package; Sign the MCU software package to obtain an MCU software package signature file; Packing the MCU software package and the MCU software package signature file into a first package file; Compile the OPENCPU software source code to generate an OPENCPU software package; Sign the OPENCPU software package to obtain the OPENCPU software package signature file; Packing the OPENCPU software package and the OPENCPU software package signature file into a second package file; Put the first package file and the second package file into the same directory to obtain the TBOX original file; Compressing the TBOX original file to obtain a TBOX upgrade package compressed file; Encrypt the TBOX upgrade package compressed file using a preset encryption algorithm to obtain a TBOX encrypted upgrade package; The format of the TBOX encrypted upgrade package is converted to obtain the TBOX upgrade package.
10. The upgrade system according to claim 9, characterized in that: The step of signing the MCU software package to obtain the MCU software package signature file includes: Calculate the second MD5 value of the MCU software package; The second MD5 value is encrypted using the first private key to obtain the MCU software package signature file.
11. The upgrade system according to claim 9, characterized in that: The step of signing the OPENCPU software package to obtain the OPENCPU software package signature file includes: Calculate the first MD5 value of the OPENCPU software package; The first MD5 value is encrypted using the second private key to obtain the OPENCPU software package signature file.
12. The upgrade system according to claim 9, characterized in that: The preset encryption algorithm includes: AES128 key.
13. The upgrade system according to claim 9, characterized in that: The Internet of Vehicles server is also used for: Calculate the standard hash value of the TBOX upgrade package using a preset algorithm; Put the standard hash value and the TBOX upgrade package download address corresponding to the TBOX upgrade package on the Internet of Vehicles server into the Manifest file; The Manifest file is stored.
Citation Information
Patent Citations
Signature and signature verification method of upgrade package, and storage medium
CN111274552A
Method for improving stability of vehicle-mounted terminal system based on ThreadX
CN114265678A