PKI certificate filling system and method
By pre-installing a universal certificate chain and private key on components at the factory, and using a two-way authentication secure channel to automate the download of PKI certificates, the problems of difficult production line transformation and complex after-sales service in existing technologies are solved, thereby improving production efficiency and communication security.
Patent Information
- Application Number
- CN202310135820.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-20
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2043-02-20
AI Technical Summary
Existing technologies for PKI certificate filling processes suffer from difficulties in production line modification, high complexity of after-sales service, and low efficiency. In particular, it is difficult to achieve safe and convenient certificate filling without modifying the entire vehicle production line and processes.
A PKI certificate loading system was designed, including an in-vehicle terminal supplier platform, a content service platform, and PKI infrastructure. By pre-installing a universal certificate chain and private key on the parts when they leave the factory, the system uses a two-way authentication security channel to achieve automated certificate download and verification, ensuring the legality of the parts, and automatically triggering certificate download after power-on and network connection.
This technology enables certificate filling during the parts manufacturing process, avoiding production line modifications, improving production efficiency, simplifying after-sales parts replacement procedures, reducing costs and complexity, and ensuring communication security.
Smart Images

Figure CN116170204B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle networking technology, specifically to a PKI (Public Key Infrastructure) certificate filling system and method. Background Technology
[0002] In recent years, the trend of "electrification, intelligentization, connectivity, and sharing" in the automotive industry has become increasingly apparent. As a comprehensive application of cloud computing, big data, IoT / Vehicle-to-Everything (V2X) technology, multi-dimensional sensors, artificial intelligence, and new communication technologies represented by 4G / 5G, automobiles have become intelligent terminals highly integrated with IoT technology. Automakers are fully utilizing IoT technology to create differentiated products and jointly promote the intelligent and connected implementation of more and more business scenarios. The implementation of these scenarios, in turn, drives the improvement of automotive intelligence and connectivity. Automobiles increasingly need to communicate and interact with external data and process and carry more and more user and vehicle data. This also makes automotive information security and data security an unavoidable issue that requires joint efforts from the industry to address. The PKI-based V2X application service security certification system framework is a standard to be developed, proposed in the "Guideline for the Construction of V2X Network Security and Data Security Standard System" issued by the General Office of the Ministry of Industry and Information Technology on February 25, 2022.
[0003] Therefore, many automakers use PKI certificates as their primary solution for connected vehicle security. However, due to various reasons, the methods for installing PKI certificates differ significantly among automakers, making it difficult to balance security and convenience. Incomplete consideration of business scenarios may also lead to a series of problems.
[0004] Regarding the aforementioned problem of PKI certificate installation, Chinese Patent Publication No. CN113094687A, entitled "A Digital Certificate Installation Method, Installation Equipment, and Vehicle Terminal," discloses a digital certificate installation method. In this method, the installation equipment sends a digital certificate request instruction to the vehicle terminal and receives a digital certificate request message carrying the vehicle terminal's identity information from the vehicle terminal; it forwards the digital certificate request message to a content service platform; it receives a digital certificate issued by the content service platform after confirming the vehicle terminal's legitimacy and sends the digital certificate to the vehicle terminal; and it performs a quality inspection and verification of the vehicle terminal's network status based on the digital certificate storage status returned by the vehicle terminal and the vehicle terminal's network status. This patent can solve the problems of cumbersome digital certificate installation processes and the vulnerability of the installation process to malicious writing of illegal certificates by external tools in existing technologies. However, the patent's design is overly idealistic and doesn't adequately consider business scenarios. The solution relies on the end-of-life (EOL) of the vehicle manufacturer's production line and after-sales diagnostic equipment to trigger the filling process. In most existing automakers, this would require modifications to the EOL and diagnostic equipment, making it difficult to integrate well with existing vehicle production lines. This could negatively impact production line efficiency and after-sales service quality.
[0005] Chinese patent CN114626045A, entitled "Safety Filling Method and System, Storage Medium, Front-end Processor, TSP Platform," introduces the concept of a front-end processor to address potential production line downtime caused by online certificate filling failures due to network issues. However, this solution requires additional modifications to the production line and does not consider after-sales replacement scenarios. A separate solution is needed for after-sales scenarios. Summary of the Invention
[0006] The purpose of this invention is to provide a PKI certificate filling system and method. This invention achieves certificate authentication and filling in a safe manner when parts leave the factory without modifying the vehicle production line and processes, thus solving the consistency problem between the production line and after-sales service.
[0007] To achieve this objective, the PKI certificate filling system designed in this invention includes an in-vehicle terminal supplier platform, a content service platform, and PKI infrastructure;
[0008] The vehicle terminal supplier platform is used to send the vehicle terminal production plan information to the content service platform during the production of the vehicle terminal, and to write the pre-set general certificate chain and the corresponding private key into the vehicle terminal.
[0009] The vehicle terminal establishes a two-way authentication secure channel with the content service platform through a certificate chain, and encrypts and decrypts information transmitted in the secure channel using the corresponding private key;
[0010] After production is completed and the vehicle terminal is powered on, it connects to the Internet to trigger the filling certificate application. The vehicle terminal generates a vehicle terminal device number and a corresponding certificate request file based on the filling certificate application. The vehicle terminal sends the generated vehicle terminal device number and the corresponding certificate request file to the content service platform through a two-way authentication secure channel.
[0011] The content service platform compares the received vehicle terminal device number with the vehicle terminal production plan information. If the vehicle terminal device number is in the vehicle terminal production plan information, the platform forwards the corresponding certificate request file to the PKI infrastructure. After receiving the certificate request file forwarded by the content service platform, the PKI infrastructure creates the corresponding vehicle terminal device certificate and sends it to the content service platform.
[0012] The content service platform is used to forward the vehicle terminal equipment certificates created by PKI technology facilities to the corresponding vehicle terminals through a secure two-way authentication channel.
[0013] The beneficial effects of this invention are:
[0014] This invention completes the certificate application process at the vehicle terminal production stage. Since certificate application is implemented at the parts production stage, the entire vehicle production line no longer needs additional workstations for certificate application; only the certificate status needs to be checked at the End-of-Life (EOL) stage, thus improving production efficiency. Furthermore, because certificate application can be completed at the parts production stage, 4S dealerships no longer need to equip themselves with additional equipment for certificate application when replacing parts, reducing the costs and inconveniences associated with production line and after-sales parts replacement processes.
[0015] This invention effectively verifies the legality of filling parts on the content service platform side through production planning. The production plan contains a unique part number (PDSN). When filling the certificate, it automatically verifies whether the part number is in the production plan. If the part is not in the production plan, it is considered an illegal part, and the certificate cannot be installed, so it cannot be used normally.
[0016] This invention automatically triggers and implements the certificate download operation after power-on and network connection, eliminating the need for additional workstations on the production line, greatly improving efficiency and optimizing the process. While improving efficiency, it also reduces the investment in additional workstations, minimizing the cost of production line transformation.
[0017] Compared to the solution in the background, the present invention omits the filling equipment step and achieves automated certificate download through software on the vehicle terminal. Attached Figure Description
[0018] Figure 1 This is a schematic diagram of the structure of the present invention;
[0019] Figure 2Flowchart for filling certificates for vehicle-mounted terminals. Detailed Implementation
[0020] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments:
[0021] like Figure 1 and 2 The PKI certificate filling system shown includes an in-vehicle terminal supplier platform, a content service platform, and PKI infrastructure.
[0022] The vehicle terminal supplier platform is used to send the vehicle terminal production plan information to the content service platform during the production of the vehicle terminal, and to write the pre-set universal certificate chain and the corresponding private key into the vehicle terminal. The pre-set universal certificate can ensure that the parts also use a secure communication channel when downloading the formal certificate, thus ensuring the communication security of the entire life cycle of the parts.
[0023] The vehicle terminal establishes a two-way authentication secure channel with the content service platform through a certificate chain, and encrypts and decrypts information transmitted in the secure channel using the corresponding private key;
[0024] After production is completed and the vehicle terminal is powered on, it connects to the Internet to trigger the filling certificate application (i.e., apply to download the vehicle terminal equipment certificate). The vehicle terminal generates a vehicle terminal equipment number and a corresponding certificate signing request file based on the filling certificate application. The vehicle terminal sends the generated vehicle terminal equipment number and the corresponding certificate signing request file to the content service platform through a two-way authentication secure channel. The certificate signing request file is used to collect key information of the vehicle terminal and to apply for a unique equipment certificate for the vehicle terminal.
[0025] The content service platform compares the received vehicle terminal device number with the vehicle terminal production plan information. If the vehicle terminal device number is in the vehicle terminal production plan information, the corresponding certificate request file is forwarded to the PKI infrastructure. After receiving the certificate request file forwarded by the content service platform, the PKI infrastructure creates the corresponding vehicle terminal device certificate and sends it to the content service platform. If the received vehicle terminal device number is not in the vehicle terminal production plan information, the vehicle terminal device certificate application is rejected. In order to prevent unauthorized devices from downloading certificates, the cloud platform uses the device's unique PDSN for a first round of authentication.
[0026] The content service platform is used to forward the vehicle terminal equipment certificates created by PKI technology facilities to the corresponding vehicle terminals through a secure two-way authentication channel.
[0027] In the above technical solution, the key information includes:
[0028] Common Name (CN) domain name / name, such as CN representing China;
[0029] Organization (O) is the name of the unit, such as XISU representing Xi'an International Studies University;
[0030] Locality (L) refers to a city, such as Xi'an.
[0031] State (ST) refers to the province / municipality, such as ShanXi, which represents Shaanxi.
[0032] Country (C) refers to a country, such as CN representing China;
[0033] And the unique public key generated by the device;
[0034] This information, when combined, generates a unique device certificate for the device.
[0035] In the above technical solutions, the vehicle terminal is an electronic device on the car, such as a Tbox (Telematic BOX, intelligent vehicle terminal) for providing 4G / 5G communication services, or an IVI (In-Vehicle Infotainment) for providing audio-visual entertainment to users.
[0036] In the above technical solution, the production plan information includes the vehicle terminal device number (PDSN) of the planned vehicle-mounted equipment. The vehicle terminal device number is used to verify whether the device accessing the cloud service is a legitimate access device. Only the vehicle terminal device number included in the production plan is recognized as a device that can install a certificate to access the cloud service.
[0037] In the above technical solution, the universal certificate chain and the corresponding private key are manually generated by the PKI infrastructure. The vehicle terminal supplier platform writes the universal certificate chain and the corresponding private key into the secure storage area of the vehicle terminal. After receiving the certificate request file, the PKI infrastructure extracts the key information from the certificate request file and generates the device certificate, i.e., the pre-installed certificate, according to the agreed template.
[0038] In the above technical solution, the universal certificate chain includes a universal certificate (an offline certificate manually generated by the PKI infrastructure). This universal certificate is used to establish a secure, two-way authentication channel between the vehicle terminal and the content service platform. The initial secure communication is conducted through this channel to request and download the vehicle terminal device certificate. Through this two-way authentication, the content service platform will know the identity of the vehicle terminal (vehicle and vehicle terminal device model), and the vehicle terminal will also know the identity of the content service platform (the type of service provided, such as remote vehicle control).
[0039] In the above technical solution, after receiving the vehicle terminal device certificate forwarded by the content service platform, the vehicle terminal saves the unique vehicle terminal device certificate and deletes the general certificate in the general certificate chain.
[0040] In the above technical solution, the certificate chain also includes a root certificate and intermediate certificates used for issuing certificates. The general certificate of the content service platform and the general certificate of the vehicle terminal are both derived from the root certificate and intermediate certificate. The certificate chain can be used to find the association information between the general certificate of the content service platform and the general certificate of the vehicle terminal. Combined with the vehicle terminal device certificate installed on the vehicle terminal, a complete certificate authentication loop is formed.
[0041] In the above technical solution, the general certificate is provided by the vehicle manufacturer or certificate provider and can be reused.
[0042] A method for filling in PKI certificates based on the above system, characterized in that it includes the following steps:
[0043] Step 1: The vehicle terminal supplier platform sends the vehicle terminal production plan information to the content service platform during vehicle terminal production, and writes the pre-set universal certificate chain and corresponding private key into the vehicle terminal.
[0044] Step 2: The vehicle terminal establishes a two-way authentication secure channel with the content service platform through the certificate chain, and encrypts and decrypts the information transmitted in the secure channel using the corresponding private key;
[0045] Step 3: After production is completed and the vehicle terminal is powered on, it connects to the Internet to trigger the filling certificate application. The vehicle terminal generates a vehicle terminal device number and a corresponding certificate request file based on the filling certificate application. The vehicle terminal sends the generated vehicle terminal device number and the corresponding certificate request file to the content service platform through a two-way authentication secure channel.
[0046] Step 4: The content service platform compares the received vehicle terminal device number with the vehicle terminal production plan information. If the vehicle terminal device number is in the vehicle terminal production plan information, the platform forwards the corresponding certificate request file to the PKI infrastructure. After receiving the certificate request file forwarded by the content service platform, the PKI infrastructure creates the corresponding vehicle terminal device certificate and sends it to the content service platform.
[0047] Step 5: The content service platform forwards the vehicle terminal equipment certificate created by the PKI technology infrastructure to the corresponding vehicle terminal through a secure two-way authentication channel;
[0048] Step 6: After receiving the vehicle terminal device certificate forwarded by the content service platform, the vehicle terminal saves the unique vehicle terminal device certificate, performs certificate loading, and deletes the general certificate in the general certificate chain.
[0049] A computer-readable storage medium storing a computer program, characterized in that: when the computer program is executed by a processor, it implements the steps of the above-described method.
[0050] The contents not described in detail in this specification are existing technologies known to those skilled in the art.
Claims
1. A PKI certificate filling system, characterized in that: It includes in-vehicle terminal supplier platforms, content service platforms, and PKI infrastructure; The vehicle terminal supplier platform is used to send the vehicle terminal production plan information to the content service platform during the production of the vehicle terminal, and to write the pre-set general certificate chain and the corresponding private key into the vehicle terminal. The vehicle terminal establishes a two-way authentication secure channel with the content service platform through a certificate chain, and encrypts and decrypts information transmitted in the secure channel using the corresponding private key; After production is completed and the vehicle terminal is powered on, it connects to the Internet to trigger the filling certificate application. The vehicle terminal generates a vehicle terminal device number and a corresponding certificate request file based on the filling certificate application. The vehicle terminal sends the generated vehicle terminal device number and the corresponding certificate request file to the content service platform through a two-way authentication secure channel. The content service platform compares the received vehicle terminal device number with the vehicle terminal production plan information. If the vehicle terminal device number is in the vehicle terminal production plan information, the platform forwards the corresponding certificate request file to the PKI infrastructure. After receiving the certificate request file forwarded by the content service platform, the PKI infrastructure creates the corresponding vehicle terminal device certificate and sends it to the content service platform. The content service platform is used to forward the vehicle terminal equipment certificates created by PKI technology facilities to the corresponding vehicle terminals through a secure two-way authentication channel; Production planning information includes the vehicle terminal device number of the planned vehicle-mounted equipment. The vehicle terminal device number is used to verify whether the device accessing the cloud service is a legitimate access device. The universal certificate chain and the corresponding private key are generated by the PKI infrastructure. The universal certificate chain includes a universal certificate, which is used to establish a secure two-way authentication channel between the vehicle terminal and the content service platform, and to conduct the first secure communication through this secure two-way authentication channel to apply for and download the vehicle terminal device certificate.
2. The PKI certificate filling system according to claim 1, characterized in that: Only the vehicle terminal device number included in the production plan is recognized as a device that can install certificates to access cloud services.
3. The PKI certificate filling system according to claim 1, characterized in that: The vehicle terminal supplier platform writes the universal certificate chain and the corresponding private key into the secure storage area of the vehicle terminal.
4. The PKI certificate filling system according to claim 1, characterized in that: If the received vehicle terminal equipment number is not in the vehicle terminal production plan information, the vehicle terminal equipment certificate application will be rejected.
5. The PKI certificate filling system according to claim 1, characterized in that: After receiving the vehicle terminal device certificate forwarded by the content service platform, the vehicle terminal saves the unique vehicle terminal device certificate and deletes the universal certificate in the universal certificate chain.
6. The PKI certificate filling system according to claim 1, characterized in that: The certificate chain also includes root certificates and intermediate certificates used to issue certificates. Both the general certificate of the content service platform and the general certificate of the vehicle terminal are derived from root certificates and intermediate certificates. The certificate chain can be used to find the association information between the general certificate of the content service platform and the general certificate of the vehicle terminal. Combined with the vehicle terminal device certificate installed on the vehicle terminal, a complete certificate authentication loop is formed.
7. The PKI certificate filling system according to claim 1, characterized in that: The general certificate is provided by the vehicle manufacturer or certificate provider and can be reused.
8. A method for filling PKI certificates based on the system of claim 1, characterized in that, It includes the following steps: Step 1: The vehicle terminal supplier platform sends the vehicle terminal production plan information to the content service platform during vehicle terminal production, and writes the pre-set universal certificate chain and corresponding private key into the vehicle terminal. Step 2: The vehicle terminal establishes a two-way authentication secure channel with the content service platform through the certificate chain, and encrypts and decrypts the information transmitted in the secure channel using the corresponding private key; Step 3: After production is completed and the vehicle terminal is powered on, it connects to the Internet to trigger the filling certificate application. The vehicle terminal generates a vehicle terminal device number and a corresponding certificate request file based on the filling certificate application. The vehicle terminal sends the generated vehicle terminal device number and the corresponding certificate request file to the content service platform through a two-way authentication secure channel. Step 4: The content service platform compares the received vehicle terminal device number with the vehicle terminal production plan information. If the vehicle terminal device number is in the vehicle terminal production plan information, the platform forwards the corresponding certificate request file to the PKI infrastructure. After receiving the certificate request file forwarded by the content service platform, the PKI infrastructure creates the corresponding vehicle terminal device certificate and sends it to the content service platform. Step 5: The content service platform forwards the vehicle terminal equipment certificate created by the PKI technology infrastructure to the corresponding vehicle terminal through a secure two-way authentication channel; Step 6: After receiving the vehicle terminal device certificate forwarded by the content service platform, the vehicle terminal saves the unique vehicle terminal device certificate, performs certificate loading, and deletes the general certificate in the general certificate chain.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, it implements the steps of the method as described in claim 8.
Citation Information
Patent Citations
Safe canning method and system, storage medium, front-end processor and TSP platform
CN114626045A
Digital certificate filling method, filling equipment and vehicle-mounted terminal
CN113094687A
Internet of vehicles digital certificate issuing method and system
CN113541939A