An encryption and decryption method and device, electronic equipment and storage medium

By utilizing encryption/decryption hardware and trust list management within the same control LAN in the vehicle, data is processed in packets and distributed to multiple control units for encryption/decryption tasks. This solves the problems of slow data encryption/decryption speed and high resource consumption in existing technologies, achieving efficient and reliable encryption/decryption processing.

CN116094754BActive Publication Date: 2026-05-08CHINA AUTOMOTIVE INNOVATION CORP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA AUTOMOTIVE INNOVATION CORP
Filing Date
2022-11-29
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing encryption algorithms are slow when processing large data files, and distributed computing requires a central management module, which increases the amount of computation and affects the user experience.

Method used

By setting up first and second control units in the vehicle, and utilizing encryption and decryption hardware within the same control area network, data is processed in packets and distributed to multiple control units for encryption and decryption tasks. Trust lists and encryption/decryption key management are used to improve processing efficiency and reliability.

Benefits of technology

It improves the speed of big data encryption and decryption processing, reduces user waiting time, enhances user experience, and reduces system resource consumption and improves data transmission reliability through distributed processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116094754B_ABST
    Figure CN116094754B_ABST
Patent Text Reader

Abstract

The application relates to the computer technical field, and discloses an encryption and decryption method and device, electronic equipment and a storage medium. The encryption and decryption method is applied to a first control unit in a vehicle. The method obtains an encryption and decryption request, the encryption and decryption request carries to-be-encrypted data and a corresponding encryption and decryption algorithm type. The to-be-encrypted data is packet-processed to obtain a plurality of data packets. The plurality of data packets are sent to a corresponding second control unit based on the encryption and decryption algorithm type corresponding to the to-be-encrypted data. The second control unit is provided with encryption and decryption hardware. The first control unit and the second control unit are located in the same control local area network. Encryption and decryption data sent by the second control unit is received. The encryption and decryption data is obtained by performing encryption and decryption processing on the data packets based on the encryption and decryption hardware of the second control unit. An encryption and decryption result is determined based on the encryption and decryption data. The processing efficiency of the encryption and decryption task in the vehicle is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to an encryption / decryption method, apparatus, electronic device, and storage medium. Background Technology

[0002] Currently, encryption algorithm implementations can be divided into two types: software implementation and hardware (hardware security module, or HSM) implementation. Compared to software implementation, HSM (built-in hardware encryption / decryption accelerator) has the characteristic of fast encryption / decryption speed.

[0003] However, for files with large amounts of data, even using the HSM module often consumes a lot of time, affecting the user experience; and existing distributed computing requires a central management and scheduling module to uniformly manage computing resources within the domain, and the management and scheduling module itself needs to be deployed separately, which increases the computing load of the in-vehicle system itself. Summary of the Invention

[0004] To address at least one of the aforementioned technical problems, this application provides an encryption / decryption method, apparatus, electronic device, and storage medium. The technical solution is as follows:

[0005] On the one hand, an encryption / decryption method is provided, applied to the first control unit in a vehicle, the method comprising:

[0006] Obtain the encryption / decryption request, which carries the data to be encrypted / decrypted and the corresponding encryption / decryption algorithm type;

[0007] The data to be encrypted or decrypted is split into multiple data packets;

[0008] Based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted, the multiple data packets are sent to the corresponding second control unit; the second control unit is equipped with encryption / decryption hardware; the first control unit and the second control unit are located in the same control local area network.

[0009] The system receives encrypted and decrypted data sent by the second control unit; this encrypted and decrypted data is obtained by encrypting and decrypting each data packet based on the encryption and decryption hardware of the second control unit.

[0010] The encryption / decryption result is determined based on the encrypted / decrypted data.

[0011] In one exemplary implementation, sending the multiple data packets to the corresponding second control unit based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted includes:

[0012] Obtain the attribute information of each of the multiple second control units; the attribute information includes the identifier of the second control unit, the encryption / decryption algorithm type, and the load weight value; the load weight value represents the ability of the second control unit to provide encryption / decryption services;

[0013] Based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted, an initial target second control unit is determined from the plurality of second control units; the encryption / decryption algorithm type of the initial target second control unit includes the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted;

[0014] Based on the load weight value and identifier of the initial target second control unit, the multiple data packets are sent to the corresponding initial target second control unit.

[0015] In an exemplary implementation, when the initial target second control unit includes at least two second control units, sending the plurality of data packets to the corresponding initial target second control unit based on the load weight value and identifier of the initial target second control unit includes:

[0016] Select the identifier of the quasi-target second control unit from the identifiers of the initial target second control unit; the quasi-target second control unit is the second control unit with the largest load weight value among the initial target second control units;

[0017] Based on the identifier of the second control unit of the quasi-target, the first data packet among the plurality of data packets is sent to the second control unit of the quasi-target; the first data packet is any one of the plurality of data packets;

[0018] Based on the identifier of the remaining second control unit, the remaining data packets are sent to the remaining second control unit; the remaining second control unit is the second control unit in the initial target second control unit excluding the quasi-target second control unit; the remaining data is the data packets in the plurality of data packets excluding the first data packet.

[0019] In one exemplary implementation, when the remaining second control unit includes at least two second control units and the remaining data packet includes at least two data packets, sending the remaining data packet to the remaining second control unit based on the identifier of the remaining second control unit includes:

[0020] Select the identifier of the target second control unit from the remaining identifiers of the second control units; the target second control unit is the second control unit with the largest load weight value among the remaining second control units;

[0021] Based on the identifier of the target second control unit, any one of the remaining data packets is sent to the target second control unit; the steps of selecting the identifier of the target second control unit from the identifiers of the remaining second control units and sending any one of the remaining data packets to the target second control unit based on the identifier of the target second control unit are performed until there are no unsent data packets.

[0022] In one exemplary embodiment, receiving encrypted / decrypted data sent by the second control unit and determining the encryption / decryption result based on the encrypted / decrypted data includes:

[0023] Receive encrypted and decrypted data sent by each of the multiple second control units;

[0024] The encryption / decryption result is determined based on the encryption / decryption data sent by each of the multiple second control units.

[0025] In one exemplary embodiment, the first control unit is provided with encryption / decryption hardware;

[0026] If the encryption / decryption hardware of the first control unit is capable of encrypting and decrypting the data packet, the first control unit sends the multiple data packets to the corresponding second control unit based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted; receives the encryption / decryption data sent by the second control unit; the encryption / decryption data is obtained by encrypting and decrypting each data packet based on the encryption / decryption hardware of the second control unit; and determines the encryption / decryption result based on the encryption / decryption data, including:

[0027] Based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted, the first type of data packet among the multiple data packets is sent to the corresponding second control unit;

[0028] The system receives first encrypted and decrypted data sent by the second control unit, which is obtained by encrypting and decrypting a first type of data packet based on the encryption and decryption hardware of the second control unit.

[0029] The encryption and decryption hardware of the first control unit is used to encrypt and decrypt the second type of data packet to obtain the second encrypted and decrypted data; the second type of data packet is the data packet among the plurality of data packets excluding the first type of data;

[0030] The encryption / decryption result is determined based on the first encryption / decryption data and the second encryption / decryption data.

[0031] In one exemplary implementation, prior to obtaining the encryption / decryption request, the following steps are also included:

[0032] Generate a trust list construction request, which carries the identifier of the first control unit, the local area network identifier, and the encryption / decryption algorithm type;

[0033] The request to build a trust list is sent to the second control unit;

[0034] If a table construction response message is received from the second control unit, an encrypted file containing the encryption and decryption keys of the first control unit is sent to the second control unit. The table construction response message includes the identifier of the second control unit, the identifier of its local area network, and the encryption and decryption algorithm type. The identifier of the local area network to which the first control unit belongs is the same as the identifier of the local area network to which the second control unit belongs.

[0035] If an encrypted file containing the encryption / decryption key of the second control unit is received from the second control unit, the encrypted file containing the encryption / decryption key of the second control unit is decrypted to obtain the encryption / decryption key of the second control unit;

[0036] A trust list is constructed based on the identifier of the first control unit, the identifier of the second control unit, the encryption / decryption algorithm type of the first control unit, the encryption / decryption algorithm type of the second control unit, the local area network identifier of the first control unit, the local area network identifier of the second control unit, the encryption / decryption key of the first control unit, and the encryption / decryption key of the second control unit.

[0037] On the other hand, this application also discloses an encryption / decryption device applied to a first control unit in a vehicle, the device comprising:

[0038] The acquisition module is used to acquire encryption / decryption requests, which carry the data to be encrypted / decrypted and the corresponding encryption / decryption algorithm type.

[0039] The packet segmentation module is used to segment the data to be encrypted / decrypted into multiple data packets.

[0040] The sending module is used to send the multiple data packets to the corresponding second control unit based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted; the second control unit is equipped with encryption / decryption hardware; the first control unit and the second control unit are located in the same control local area network.

[0041] The receiving module is used to receive encrypted and decrypted data sent by the second control unit; the encrypted and decrypted data is obtained by encrypting and decrypting each data packet based on the encryption and decryption hardware of the second control unit;

[0042] The determination module is used to determine the encryption / decryption result based on the encryption / decryption data.

[0043] On the other hand, this application also discloses an electronic device including a processor and a memory, wherein the memory stores at least one instruction or at least one program, which is loaded and executed by the processor to implement the above-described encryption and decryption method.

[0044] On the other hand, this application also discloses a computer-readable storage medium storing at least one instruction or at least one program, which is loaded and executed by a processor to implement the above-described encryption and decryption method.

[0045] This application embodiment utilizes the vehicle's control unit for encryption / decryption task distribution. Compared to existing technologies based on distributed control that require a dedicated management module, it offers advantages such as simple structure and low overall system resource consumption. By packetizing encryption / decryption tasks generated or received by a control unit and distributing them to multiple corresponding control units for processing, and because the control units in this application have built-in encryption / decryption hardware, processing efficiency is further improved. The first control unit that publishes the task and the second control unit that processes the encryption / decryption task are on the same local area network, eliminating the need for data forwarding through a gateway, thus improving the reliability of encryption / decryption task processing between the first and second control units. Attached Figure Description

[0046] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0047] Figure 1 This is a schematic diagram of an implementation environment provided in an embodiment of this application;

[0048] Figure 2 This is a flowchart illustrating an encryption / decryption method provided in an embodiment of this application;

[0049] Figure 3 This is a flowchart illustrating another encryption / decryption method provided in an embodiment of this application;

[0050] Figure 4 This is a structural block diagram of an encryption / decryption device provided in an embodiment of this application. Detailed Implementation

[0051] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0052] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0053] It is understood that in the specific embodiments of this application, data such as user information are involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0054] Please see Figure 1 The diagram illustrates an implementation environment provided in this application embodiment. This environment includes a vehicle 10 and an encryption / decryption system 20 located within the vehicle. The encryption / decryption system 20 includes a first control unit 201 and a second control unit 202. The second control unit 202 contains encryption / decryption hardware. The first control unit 201 and the second control unit 202 are located within the same control local area network. The first control unit 201 is used to acquire encryption / decryption requests, which carry data to be encrypted / decrypted and the corresponding encryption / decryption algorithm type. It performs packet processing on the data to be encrypted / decrypted to obtain multiple data packets. Based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted, it sends the multiple data packets to the corresponding second control unit 202. It receives the encryption / decryption data sent by the second control unit 202 and determines the encryption / decryption result based on the encryption / decryption data. The second control unit 202 uses its encryption / decryption hardware to encrypt / decrypt each data packet to obtain encrypted / decrypted data, and then sends it to the first control unit 201.

[0055] In this embodiment, the aforementioned same control local area network refers to the data transmission between these control units located in the same control local area network without the need for a control unit cluster of switches, so as to ensure the reliability of subsequent transmission and processing of encrypted and decrypted data.

[0056] In this embodiment, within the vehicle, the same control local area network (LAN) can be categorized by function, including chassis domain, cockpit domain, etc. Optionally, the same control LAN can also be a set of control units located on the same bus. Optionally, the first control unit and the second control unit can be directly connected via one or more network communication methods such as CAN, Ethernet, LIN, MOST, and FlexRay.

[0057] In some implementations, multiple (e.g., dozens) Electronic Control Units (ECUs) communicate within the vehicle, each responsible for various vehicle functions (engine management, steering, pedals, power windows, etc.). A typical ECU is a computer module containing its own processor, memory, and peripherals necessary to implement its functions and interface with other systems in the vehicle. A typical ECU comprises both the hardware and software to perform its designed functions.

[0058] In some implementations, the first control unit and the second control unit can be applicable to various vehicles (e.g., automobiles, railways, ships, aircraft).

[0059] Please see Figure 2 The diagram shown is a flowchart of an encryption / decryption method provided in an embodiment of this application. This method can be applied to... Figure 1 The encryption / decryption system in the document. It should be noted that this specification provides the operational steps of the methods described in the embodiments or flowcharts, but based on conventional or non-inventive labor, more or fewer operational steps may be included. The order of steps listed in the embodiments is merely one possible execution order among many, and does not represent the only execution order. In actual system or product execution, the methods shown in the embodiments or drawings can be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment). Specifically, as shown... Figure 2 As shown, the method applied to a first control unit in a vehicle may include:

[0060] S201: Obtain encryption / decryption request, which carries the data to be encrypted / decrypted and the corresponding encryption / decryption algorithm type.

[0061] In this embodiment, the encryption / decryption request in step S201 can be generated by the first control unit or received from other external devices.

[0062] In this embodiment, the encryption / decryption request may specifically include an encryption request and a decryption request. Similarly, the "encryption / decryption" data, algorithms, etc. mentioned in this application include both "encryption" and "decryption" types.

[0063] In this embodiment, the encryption and decryption algorithms may include symmetric encryption algorithms (such as AES, DES), asymmetric encryption algorithms (such as RSA, ECC), and hash algorithms (such as MD5, HAVAL, SHA).

[0064] The aforementioned asymmetric encryption algorithm can also be called a public-private key encryption algorithm. The encryption and decryption process requires a public key and a private key. Generally, the public key can be made public, while the private key needs to be kept secret.

[0065] In this embodiment, this application is mainly applied to the encryption and decryption processing of big data, such as the Over-the-Air Technology (OTA) scenario in vehicles.

[0066] In an exemplary embodiment, before step S201, the method further includes: generating a trust list construction request, the trust list construction request carrying the identifier of the first control unit, the local area network identifier, and the encryption / decryption algorithm type; sending the trust list construction request to the second control unit; if a list construction response information is received from the second control unit, sending an encrypted file containing the encryption / decryption key of the first control unit to the second control unit; the list construction response information includes the identifier of the second control unit, the local area network identifier, and the encryption / decryption algorithm type; the local area network identifier of the first control unit is the same as the local area network identifier of the second control unit; if an encrypted file containing the encryption / decryption key of the second control unit is received from the second control unit, decrypting the encrypted file containing the encryption / decryption key of the second control unit to obtain the encryption / decryption key of the second control unit; constructing a trust list based on the identifier of the first control unit, the identifier of the second control unit, the encryption / decryption algorithm type of the first control unit, the encryption / decryption algorithm type of the second control unit, the local area network identifier of the first control unit, the local area network identifier of the second control unit, the encryption / decryption key of the first control unit, and the encryption / decryption key of the second control unit.

[0067] In this embodiment, the encryption and decryption keys of the first control unit and the second control unit are encrypted to prevent eavesdropping by other unauthenticated control units that are not added to the trust list, thereby improving the reliability of data transmission.

[0068] It should be noted that the first and second control units in the same trust list must belong to the same control LAN, that is, their corresponding LAN identifiers are the same. Control units in different trust lists are different; for example, if the first control unit ECU1 and the second control unit ECU2 are in the first trust list, they will not belong to other trust lists.

[0069] In this embodiment, during the process of building the trust list, when either the second control unit or the first control unit sends a trust list building request or a list building response message, it needs to be signed. The control unit receiving the request and message then needs to verify the signature to verify the identity of the accessing control unit and ensure its reliability. Optionally, the signature verification process can be as follows: For the first control unit, when it receives the signature of the list building response message sent by the second control unit, it uses the public key of the second control unit to verify the signature of the list building response message. Only when the verification result is successful will subsequent steps (such as sending its key or certificate) be performed. See the following for details.

[0070] In some feasible embodiments, the signature involves the message sender signing the data using their private key. After obtaining the data and the signature, the message receiver can verify the signature using the message sender's public key to confirm its legitimacy. This not only verifies the sender's identity but also prevents data tampering. Optionally, the message receiver can send the sender's identifier to a Certificate Authority (CA) to obtain a certificate containing the sender's public key. The receiver can then verify the signature of the received message based on this public key. If the verification is successful, it indicates that the message was sent by the legitimate sender, ensuring data reliability. Optionally, the Certificate Authority (CA) provides a signature on the issued certificates to prove information such as the certificate's subject information, public and private key information, key usage, validity period, and issuer.

[0071] In this embodiment, the encryption processing of the encryption / decryption key of the first control unit or the second control unit can be implemented using an asymmetric key. Optionally, the key includes both a symmetric and asymmetric keys, so that both parties can use the key to perform encryption and decryption processing of the corresponding data. Generally, signatures use asymmetric keys, while data encryption can use symmetric keys; the choice can be made based on the requirements for encryption / decryption speed and security.

[0072] In this embodiment, if all control units within the same local area network form a trust list, data in encryption / decryption tasks transmitted within that local area network can be directly transmitted without signature processing (while still requiring its own identifier). Otherwise, to further improve the stability of data in encryption / decryption tasks, any control unit needs to perform signature processing when sending relevant data in encryption / decryption tasks to other control units. Optionally, data (such as data packets) in encryption / decryption tasks needs to be encrypted.

[0073] In some embodiments, during the construction of the trust list, the control units added to the list also need to send whether they have encryption / decryption hardware and a load weight value. The load weight value represents the ability of the second control unit to provide encryption / decryption services, so that the source ECU (such as the first control unit) can determine its role in the encryption / decryption task based on whether each second control unit has encryption / decryption hardware. Optionally, the second control units with encryption / decryption hardware are marked as control units capable of handling encryption / decryption tasks, while the second control units without encryption / decryption hardware are marked as control units that distribute and combine encryption / decryption tasks. Other classification methods can also be used according to other requirements. For example, when all the second control units in the trust list have encryption / decryption hardware and can provide encryption / decryption services, the top n (n is an integer greater than or equal to 1) second control units with the highest load weight values ​​can be regarded as control units capable of handling encryption / decryption tasks, and the rest can be regarded as control units that distribute and combine encryption / decryption tasks. The basis for subsequent allocation of workload (such as the size and number of data packets) based on the load weight values ​​of the second control units is described in detail in step S205 below.

[0074] In this embodiment, for all control units in the trust list, each control unit stores its own and other control units' identifiers, local area network identifiers, load weight values, encryption / decryption algorithm types, encryption / decryption keys or certificates, etc. This allows other control units, when receiving an encryption / decryption request, to directly obtain the aforementioned key information from their local storage when processing encryption / decryption tasks, without needing to interact with the corresponding control unit or management module (such as a CA institution), thus improving encryption / decryption processing efficiency. Optionally, control units within the trust list can share public keys; to enable the processing of encryption / decryption tasks for specific control units, they can also share private keys.

[0075] S203: The data to be encrypted / decrypted is split into multiple data packets.

[0076] In this embodiment, step S203 can be simply divided into packages according to size; for programs, it can also be divided into packages based on the program's own segments (such as boot segment, app segment, etc.).

[0077] In some embodiments, if the encryption request does not specify an encryption algorithm, encryption can be performed according to a preset encryption rule. This preset encryption rule can specifically select an appropriate encryption algorithm based on the data type to be encrypted, confidentiality requirements, etc. If there is a requirement for an encryption algorithm type, it is sent to the corresponding second control unit that can provide the encryption algorithm type service for encryption. The decryption request generally contains the corresponding encryption algorithm type. If it is not provided directly, the source ECU can determine the corresponding encryption algorithm type by analyzing the decrypted data or sending it to other control units for analysis.

[0078] In this embodiment, each of the multiple data packets will include an encrypted / decrypted data packet and its corresponding size.

[0079] S205: Based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted, send the multiple data packets to the corresponding second control unit; the second control unit is equipped with encryption / decryption hardware; the first control unit and the second control unit are located in the same control local area network.

[0080] In one exemplary implementation, see [reference] Figure 3 , Figure 3 This is a flowchart illustrating another encryption / decryption method provided in this application embodiment. Step S205, which involves sending the multiple data packets to the corresponding second control unit based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted, includes:

[0081] S2051: Obtain the attribute information of each of the multiple second control units; the attribute information includes the identifier of the second control unit, the encryption / decryption algorithm type, and the load weight value; the load weight value represents the ability of the second control unit to provide encryption / decryption services.

[0082] In this embodiment, the trust list described above can be local data stored in each control unit, so that the control unit, as the first control unit, can obtain the aforementioned attribute information of each second control unit from the trust list.

[0083] In some embodiments, a higher load weight value for a general control unit indicates a greater capacity to provide encryption and decryption services. The load weight value of the control unit can be determined by comprehensively considering factors such as the number of encryption and decryption algorithm types it can provide and its available computing power.

[0084] S2053: Based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted, determine the initial target second control unit from the plurality of second control units; the encryption / decryption algorithm type of the initial target second control unit includes the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted.

[0085] In this embodiment, the initial target second control unit may include multiple second control units.

[0086] S2055: Based on the load weight value and identifier of the initial target second control unit, send the multiple data packets to the corresponding initial target second control unit.

[0087] In an exemplary embodiment, when the initial target second control unit includes at least two second control units, step S2055 may include: selecting an identifier for a quasi-target second control unit from the identifiers of the initial target second control units; the quasi-target second control unit is the second control unit with the largest load weight value among the initial target second control units; based on the identifier of the quasi-target second control unit, sending a first data packet from the plurality of data packets to the quasi-target second control unit; the first data packet is any one of the plurality of data packets; based on the identifier of the remaining second control units, sending the remaining data packets to the remaining second control units; the remaining second control units are the second control units in the initial target second control units excluding the quasi-target second control unit; the remaining data packets are the data packets among the plurality of data packets excluding the first data packet. When the initial target second control unit includes only one second control unit, then the plurality of data packets are directly sent to the initial target second control unit.

[0088] In some embodiments, the first data packet can be M data packets from a plurality of data packets, where M is an integer greater than or equal to 1; the first data packet can be 1, 2, or 3 data packets from a plurality of data packets, etc. The specific number of data packets can be determined based on the load weight value of the second control unit. For example, for the second control unit with the largest load weight value (e.g., 20%), a first data packet with a total size of K bytes (K is an integer greater than or equal to 50) can be sent to it.

[0089] In an exemplary embodiment, when the remaining second control unit includes at least two second control units and the remaining data packet includes at least two data packets, the step S2055 above, which involves sending the remaining data packets to the remaining second control units based on their identifiers, includes: selecting the identifier of a target second control unit from the identifiers of the remaining second control units; the target second control unit being the second control unit with the largest load weight value among the remaining second control units; sending any one of the remaining data packets to the target second control unit based on its identifier; and performing the steps of selecting the identifier of the target second control unit from the identifiers of the remaining second control units and sending any one of the remaining data packets to the target second control unit based on its identifier until there are no more unsent data packets.

[0090] In this embodiment, there is a one-to-one correspondence between data packets and second control units. In other embodiments, when the number of data packets is greater than the number of second control units, for the remaining unsent data packets, according to the selection order based on the load weight values ​​of the aforementioned second control units, any one of the remaining unsent data packets is sequentially sent to the corresponding second control unit until there are no unsent data packets. To further improve the application flexibility of this application, in other embodiments, the data packets sent to the second control units are not limited to one of the above schemes. Ultimately, some of the second control units in the initial target second control unit may receive data packets, and the second control units in these second control units may receive one or more data packets, which is not limited here.

[0091] S207: Receive encrypted / decrypted data sent by the second control unit; the encrypted / decrypted data is obtained by encrypting and decrypting each data packet based on the encryption / decryption hardware of the second control unit.

[0092] In this embodiment, multiple second control units can encrypt their respective data packets using the same encryption algorithm. If necessary, different encryption algorithms can also be used to encrypt them. Optionally, the data packets they process can be signed or not, which is not limited here.

[0093] To improve the reliability of encrypted data, complex algorithms can be used for encryption, such as AES256. Under the same computing power, AES256 is several to tens of times slower than AES128 in encryption and decryption. However, by using the encryption and decryption method of this application, the speed can be improved through sharing, thereby greatly increasing the difficulty of decryption and reducing the risk of being attacked.

[0094] S209: Determine the encryption / decryption result based on the encryption / decryption data.

[0095] In an exemplary embodiment, steps S207-S209, receiving encryption / decryption data sent by the second control unit and determining the encryption / decryption result based on the encryption / decryption data, include: receiving encryption / decryption data sent by each of the plurality of second control units; and determining the encryption / decryption result based on the encryption / decryption data sent by each of the plurality of second control units.

[0096] In an exemplary embodiment, the first control unit is equipped with encryption / decryption hardware. When the encryption / decryption hardware of the first control unit is capable of encrypting and decrypting the data packet, steps S205-S209 may specifically include: sending a first type of data packet from the plurality of data packets to the corresponding second control unit based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted; receiving first encryption / decryption data sent by the second control unit, the first encryption / decryption data being obtained by encrypting and decrypting the first type of data packet using the encryption / decryption hardware of the second control unit; encrypting and decrypting a second type of data packet using the encryption / decryption hardware of the first control unit to obtain second encryption / decryption data; the second type of data packet being the data packet from the plurality of data packets excluding the first type of data; and determining the encryption / decryption result based on the first encryption / decryption data and the second encryption / decryption data.

[0097] In this embodiment, the first type of data packet and the second type of data packet may include one data packet or two or more data packets; optionally, the encryption / decryption algorithm type and load weight value of the first control unit and the encryption / decryption algorithm and load weight value of the second control unit can be determined by obtaining a trust list; if the encryption / decryption algorithm of the first control unit matches the encryption / decryption algorithm type in the encryption / decryption request, the process of determining the initial target second control unit is repeated, thereby replacing the initial target second control unit in step S2055 with the first control unit and the initial target second control unit, and step S2055 is executed.

[0098] As can be seen from the above technical solutions of the embodiments of this application, the embodiments of this application establish a trusted ECU group among the ECUs in the vehicle. The group can share encryption keys and certificate information, and manage the encryption and decryption HSM resources of each ECU and distribute encryption and decryption tasks based on a service-oriented architecture. This can significantly improve the speed of decryption and upgrade packages in scenarios such as in-vehicle OTA, and provide a feasible technical route for deploying more complex encryption algorithms in the vehicle, reducing user waiting time, improving user experience, and enhancing security.

[0099] Corresponding to the encryption and decryption methods provided in the above embodiments, this application also provides an encryption and decryption device. Since the encryption and decryption device provided in this application corresponds to the encryption and decryption methods provided in the above embodiments, the implementation methods of the aforementioned encryption and decryption methods are also applicable to the encryption and decryption device provided in this embodiment, and will not be described in detail in this embodiment.

[0100] Please see Figure 4 The diagram shown is a structural schematic of an encryption / decryption device provided in an embodiment of this application. This device has the function of implementing the encryption / decryption method described in the above method embodiments. This function can be implemented in hardware or by hardware executing corresponding software. Figure 4 As shown, the encryption / decryption device is applied to a first control unit in a vehicle, and the device may include:

[0101] The acquisition module 401 is used to acquire an encryption / decryption request, which carries the data to be encrypted / decrypted and the corresponding encryption / decryption algorithm type;

[0102] The packet segmentation module 403 is used to segment the data to be encrypted / decrypted into multiple data packets.

[0103] The sending module 405 is used to send the multiple data packets to the corresponding second control unit based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted; the second control unit is equipped with encryption / decryption hardware; the first control unit and the second control unit are located in the same control local area network.

[0104] The receiving module 407 is used to receive encrypted and decrypted data sent by the second control unit; the encrypted and decrypted data is obtained by encrypting and decrypting each data packet based on the encryption and decryption hardware of the second control unit;

[0105] The determination module 409 is used to determine the encryption / decryption result based on the encryption / decryption data.

[0106] In one exemplary embodiment, the sending module is configured to acquire attribute information of each of the plurality of second control units; the attribute information includes the identifier of the second control unit, the encryption / decryption algorithm type, and the load weight value; the load weight value characterizes the ability of the second control unit to provide encryption / decryption services;

[0107] Based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted, an initial target second control unit is determined from the plurality of second control units; the encryption / decryption algorithm type of the initial target second control unit includes the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted;

[0108] Based on the load weight value and identifier of the initial target second control unit, the multiple data packets are sent to the corresponding initial target second control unit.

[0109] In an exemplary embodiment, when the initial target second control unit includes at least two second control units, the sending module is used to select the identifier of the quasi-target second control unit from the identifiers of the initial target second control unit; the quasi-target second control unit is the second control unit with the largest load weight value among the initial target second control units;

[0110] Based on the identifier of the second control unit of the quasi-target, the first data packet among the plurality of data packets is sent to the second control unit of the quasi-target; the first data packet is any one of the plurality of data packets;

[0111] Based on the identifier of the remaining second control unit, the remaining data packets are sent to the remaining second control unit; the remaining second control unit is the second control unit in the initial target second control unit excluding the quasi-target second control unit; the remaining data is the data packets in the plurality of data packets excluding the first data packet.

[0112] In an exemplary embodiment, when the remaining second control unit includes at least two second control units and the remaining data packet includes at least two data packets, the sending module is configured to select the identifier of the target second control unit from the identifiers of the remaining second control units; the target second control unit is the second control unit with the largest load weight value among the remaining second control units;

[0113] Based on the identifier of the target second control unit, any one of the remaining data packets is sent to the target second control unit; the steps of selecting the identifier of the target second control unit from the identifiers of the remaining second control units and sending any one of the remaining data packets to the target second control unit based on the identifier of the target second control unit are performed until there are no unsent data packets.

[0114] In one exemplary embodiment, the receiving module is configured to receive encrypted and decrypted data sent by each of the plurality of second control units;

[0115] The determination module is used to determine the encryption / decryption result based on the encryption / decryption data sent by each of the plurality of second control units.

[0116] In one exemplary embodiment, the first control unit is provided with encryption / decryption hardware;

[0117] If the encryption / decryption hardware of the first control unit is capable of encrypting and decrypting the data packet, the sending module is used to send the first type of data packet among the multiple data packets to the corresponding second control unit based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted;

[0118] The receiving module is configured to receive first encrypted / decrypted data sent by the second control unit, the first encrypted / decrypted data being obtained by encrypting and decrypting a first type of data packet based on the encryption and decryption hardware of the second control unit; and to encrypt and decrypt a second type of data packet using the encryption and decryption hardware of the first control unit to obtain second encrypted / decrypted data; the second type of data packet is the data packet among the plurality of data packets excluding the first type of data.

[0119] The determination module is used to determine the encryption / decryption result based on the first encryption / decryption data and the second encryption / decryption data.

[0120] In one exemplary embodiment, the device further includes:

[0121] The generation module is used to generate a trust list construction request, which carries the identifier of the first control unit, the local area network identifier, and the encryption / decryption algorithm type.

[0122] The request sending module is used to send the request to build the trust list to the second control unit;

[0123] The response information receiving module is used to send an encrypted file containing the encryption and decryption keys of the first control unit to the second control unit if it receives the table construction response information sent by the second control unit; the table construction response information includes the identifier of the second control unit, the local area network identifier, and the encryption and decryption algorithm type; the local area network identifier of the first control unit is the same as the local area network identifier of the second control unit.

[0124] The decryption processing module is used to decrypt the encrypted file containing the encryption and decryption key of the second control unit if it receives an encrypted file sent by the second control unit, thereby obtaining the encryption and decryption key of the second control unit.

[0125] The module is used to construct a trust list based on the identifier of the first control unit, the identifier of the second control unit, the encryption / decryption algorithm type of the first control unit, the encryption / decryption algorithm type of the second control unit, the local area network identifier of the first control unit, the local area network identifier of the second control unit, the encryption / decryption key of the first control unit, and the encryption / decryption key of the second control unit.

[0126] It should be noted that the apparatus provided in the above embodiments is only illustrated by the division of the above functional modules when implementing its functions. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0127] This application provides an electronic device including a processor and a memory. The memory stores at least one instruction or at least one program segment, which is loaded and executed by the processor to implement any of the encryption / decryption methods provided in the above method embodiments.

[0128] Optional, see below Figure 1 In this application scenario, the electronic device can be an electronic control unit (ECU) in a vehicle, where each control unit includes a processor and memory.

[0129] Memory can be used to store software programs and modules. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory. Memory can primarily include a program storage area and a data storage area. The program storage area can store the operating system, application programs required for the functions, etc.; the data storage area can store data created based on the use of the device, etc. Furthermore, memory can include high-speed random access memory, and can also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, memory can also include a memory controller to provide the processor with access to the memory.

[0130] Embodiments of this application also provide a computer-readable storage medium, which can be disposed in an electronic device to store at least one instruction or at least one program related to implementing an encryption / decryption method. The at least one instruction or the at least one program is loaded and executed by the processor to implement any of the encryption / decryption methods provided in the above-described method embodiments.

[0131] Embodiments of this application also provide a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the electronic device to perform any of the encryption / decryption methods provided in the above-described method embodiments.

[0132] Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0133] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0134] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the apparatus embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0135] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0136] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. An encryption / decryption method, characterized in that, The first control unit used in the vehicle includes: Obtain an encryption / decryption request, the encryption / decryption request carrying the data to be encrypted / decrypted and the corresponding encryption / decryption algorithm type; The data to be encrypted or decrypted is divided into packets to obtain multiple data packets; Obtain attribute information for each of the multiple second control units; the attribute information includes the identifier of the second control unit, the encryption / decryption algorithm type, and the load weight value; the load weight value represents the ability of the second control unit to provide encryption / decryption services. Based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted and the attribute information of each of the plurality of second control units, the plurality of data packets are sent to the corresponding second control unit; the second control unit is equipped with encryption / decryption hardware; the first control unit and the second control unit are located in the same control local area network; the encryption / decryption algorithm type of the second control unit corresponding to each data packet includes the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted; The system receives encrypted and decrypted data sent by the second control unit; the encrypted and decrypted data is obtained by encrypting and decrypting each data packet based on the encryption and decryption hardware of the second control unit. The encryption / decryption result is determined based on the encrypted / decrypted data.

2. The encryption / decryption method according to claim 1, characterized in that, The step of sending the multiple data packets to the corresponding second control unit based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted and the attribute information of each of the multiple second control units includes: Based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted, an initial target second control unit is determined from the plurality of second control units; the encryption / decryption algorithm type of the initial target second control unit includes the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted; Based on the load weight value and identifier of the initial target second control unit, the multiple data packets are sent to the corresponding initial target second control unit.

3. The encryption / decryption method according to claim 2, characterized in that, When the initial target second control unit includes at least two second control units, sending the plurality of data packets to the corresponding initial target second control unit based on the load weight value and identifier of the initial target second control unit includes: The identifier of the quasi-target second control unit is selected from the identifiers of the initial target second control unit; the quasi-target second control unit is the second control unit with the largest load weight value among the initial target second control units; Based on the identifier of the quasi-target second control unit, the first data packet among the plurality of data packets is sent to the quasi-target second control unit; the first data packet is any one of the plurality of data packets; Based on the identifier of the remaining second control unit, the remaining data packets are sent to the remaining second control unit; the remaining second control unit is the second control unit among the initial target second control units excluding the quasi-target second control unit; the remaining data is the data packets among the plurality of data packets excluding the first data packet.

4. The encryption / decryption method according to claim 3, characterized in that, In the case that the remaining second control unit includes at least two second control units and the remaining data packet includes at least two data packets, sending the remaining data packet to the remaining second control unit based on the identifier of the remaining second control unit includes: The identifier of the target second control unit is selected from the identifiers of the remaining second control units; the target second control unit is the second control unit with the largest load weight value among the remaining second control units. Based on the identifier of the target second control unit, any one of the remaining data packets is sent to the target second control unit; the steps of selecting the identifier of the target second control unit from the identifiers of the remaining second control units and sending any one of the remaining data packets to the target second control unit based on the identifier of the target second control unit are performed until there are no unsent data packets.

5. The encryption / decryption method according to claim 2, characterized in that, The encrypted / decrypted data sent by the second control unit is received; Determining the encryption / decryption result based on the encrypted / decrypted data includes: Receive encrypted and decrypted data sent by each of the plurality of second control units; The encryption / decryption result is determined based on the encryption / decryption data sent by each of the plurality of second control units.

6. The encryption / decryption method according to any one of claims 1-5, characterized in that, The first control unit is equipped with encryption / decryption hardware; If the encryption / decryption hardware of the first control unit is capable of encrypting / decrypting the data packet, the plurality of data packets are sent to the corresponding second control unit based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted. Receive encrypted and decrypted data sent by the second control unit; The encrypted / decrypted data is obtained by encrypting and decrypting each data packet based on the encryption / decryption hardware of the second control unit; Determining the encryption / decryption result based on the encrypted / decrypted data includes: Based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted, the first type of data packet among the multiple data packets is sent to the corresponding second control unit; The system receives first encrypted / decrypted data sent by the second control unit. The first encrypted / decrypted data is obtained by encrypting and decrypting the first type of data packet based on the encryption and decryption hardware of the second control unit. The encryption and decryption hardware of the first control unit is used to encrypt and decrypt the second type of data packet to obtain the second encrypted and decrypted data; the second type of data packet is the data packet among the plurality of data packets excluding the first type of data. The encryption / decryption result is determined based on the first encryption / decryption data and the second encryption / decryption data.

7. The encryption / decryption method according to claim 1, characterized in that, Before obtaining the encryption / decryption request, the process also includes: Generate a request to build a trust list, the request carrying the identifier of the first control unit, the identifier of its local area network, and the encryption / decryption algorithm type; Send the request to build the trust list to the second control unit; If a table construction response message is received from the second control unit, an encrypted file containing the encryption and decryption keys of the first control unit is sent to the second control unit; the table construction response message includes the identifier of the second control unit, the identifier of its local area network, and the encryption and decryption algorithm type; the identifier of the local area network of the first control unit is the same as the identifier of the local area network of the second control unit. If an encrypted file containing the encryption / decryption key of the second control unit is received from the second control unit, the encrypted file containing the encryption / decryption key of the second control unit is decrypted to obtain the encryption / decryption key of the second control unit; A trust list is constructed based on the identifier of the first control unit, the identifier of the second control unit, the encryption / decryption algorithm type of the first control unit, the encryption / decryption algorithm type of the second control unit, the local area network identifier of the first control unit, the local area network identifier of the second control unit, the encryption / decryption key of the first control unit, and the encryption / decryption key of the second control unit.

8. An encryption / decryption device, characterized in that, A first control unit applied in a vehicle, the device comprising: The acquisition module is used to acquire encryption / decryption requests, which carry the data to be encrypted / decrypted and the corresponding encryption / decryption algorithm type; The packet segmentation module is used to segment the data to be encrypted / decrypted into multiple data packets. The sending module is used to send the multiple data packets to the corresponding second control unit based on the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted and the attribute information of each of the multiple second control units; the second control unit is equipped with encryption / decryption hardware; the first control unit and the second control unit are located in the same control local area network; the encryption / decryption algorithm type of the second control unit corresponding to each data packet includes the encryption / decryption algorithm type corresponding to the data to be encrypted / decrypted; The receiving module is used to receive encrypted and decrypted data sent by the second control unit; the encrypted and decrypted data is obtained by encrypting and decrypting each data packet based on the encryption and decryption hardware of the second control unit; The determination module is used to determine the encryption / decryption result based on the encryption / decryption data; The sending module is further configured to acquire attribute information of each of the multiple second control units; the attribute information includes the identifier of the second control unit, the encryption / decryption algorithm type, and the load weight value; the load weight value represents the ability of the second control unit to provide encryption / decryption services.

9. An electronic device, characterized in that, It includes a processor and a memory, wherein the memory stores at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the encryption / decryption method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one instruction or at least one program, which is loaded and executed by a processor to implement the encryption / decryption method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Data encryption and decryption method and device and electronic equipment

    CN111787534A

  • Data processing method and device

    CN113114457A