Confidential transmission method, device, electronic device and storage medium for upgrading data packets
During the OTA upgrade process, the upgraded data packets are encrypted globally or locally and transmitted in segments, the problem of data packets being easily intercepted and tampered is solved, and the confidentiality and security of data transmission are achieved.
Patent Information
- Application Number
- CN202310465514.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-26
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2043-04-26
AI Technical Summary
During the OTA upgrade process, the upgrade data packet is easily intercepted and restored by external devices or maliciously tampered with, resulting in software data leakage or ECU upgrade abnormalities, affecting the functional integrity and security of the vehicle.
By determining the target ECU, obtaining its corresponding upgrade data packet and confidential transmission configuration information, global encryption or local encryption is performed according to the data transmission mode and encryption method in the configuration information, and transmitting it to the target ECU in segments.
It strengthens the confidentiality of data transmission during the OTA upgrade process, increases the difficulty of cracking external devices, avoids software data leakage, and effectively prevents malicious tampering, ensuring the normal upgrade of the ECU and the safety of the vehicle.
Smart Images

Figure CN116506848B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a method, device, electronic device and storage medium for confidentially transmitting an upgrade data packet. Background Art
[0002] In order to meet people's increasing demand for various functions of smart vehicles, higher requirements are also placed on the update and iteration speed and quality of vehicle firmware and software. Due to its fast speed and low cost, OTA (Over the Air Technology) has been widely used in the upgrade of firmware and software of smart vehicles.
[0003] At present, during the OTA upgrade process, the data transmission end usually directly transmits the plaintext upgrade data packet through the CAN (Controller Area Network) bus of the target vehicle to the ECU (Electronic Control Unit) that needs to be flashed and upgraded. During this process, some external devices (such as other vehicles, etc.) can easily intercept the upgrade data packet transmitted by the data transmission end by monitoring the communication messages on the CAN bus of the target vehicle, and can easily restore 100% of the software data in the upgrade data packet, thereby causing software data leakage and easily infringing the intellectual property rights of software developers. In addition, during this process, if the upgrade data packet is intercepted by some illegal external devices and the software data therein is maliciously tampered with, it is easy to cause abnormalities in the ECU upgrade, thereby affecting the functional integrity and vehicle safety of the entire vehicle. Summary of the invention
[0004] In view of this, the embodiments of the present application provide a method, device, electronic device and storage medium for confidential transmission of upgrade data packets, so as to solve the problem in the prior art that upgrade data packets are easily intercepted and restored or maliciously tampered with by external devices, thereby easily causing software data leakage, or easily causing ECU upgrade abnormalities and affecting the functional integrity and vehicle safety of the entire vehicle.
[0005] According to a first aspect of an embodiment of the present application, a method for confidentially transmitting an upgrade data packet is provided, comprising:
[0006] Determine the target ECU and obtain the upgrade data package corresponding to the target ECU;
[0007] Acquire confidential transmission configuration information corresponding to the target ECU, the confidential transmission configuration information including a data transmission mode and an encryption mode, the data transmission mode including a first segment transmission mode and a second segment transmission mode, and the encryption mode including a global encryption mode and a local encryption mode;
[0008] If the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the first segment transmission mode and the encryption method is the global encryption method, the upgrade data packet is globally encrypted using the global encryption method to obtain an overall encrypted data packet, and the globally encrypted data packet is transmitted to the target ECU according to the first segment transmission mode;
[0009] If the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the second segmented transmission mode, and the encryption method is the local encryption method, the upgrade data packet is split into multiple sub-data packets, and each sub-data packet is encrypted separately using the local encryption method to obtain a segmented encrypted data packet corresponding to each sub-data packet, and each segmented encrypted data packet is transmitted to the target ECU according to the second segmented transmission mode.
[0010] A second aspect of an embodiment of the present application provides a secure transmission device for an upgrade data packet, including:
[0011] A determination module is configured to determine a target ECU and obtain an upgrade data packet corresponding to the target ECU;
[0012] An acquisition module is configured to acquire confidential transmission configuration information corresponding to a target ECU, wherein the confidential transmission configuration information includes a data transmission mode and an encryption mode, wherein the data transmission mode includes a first segment transmission mode and a second segment transmission mode, and the encryption mode includes a global encryption mode and a local encryption mode;
[0013] The first transmission module is configured to, if the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the first segmented transmission mode and the encryption mode is the global encryption mode, globally encrypt the upgrade data packet using the global encryption mode to obtain an overall encrypted data packet, and transmit the global encrypted data packet to the target ECU according to the first segmented transmission mode;
[0014] The second transmission module is configured to split the upgrade data packet into multiple sub-data packets if the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is segmented transmission and the encryption method is local encryption. Each sub-data packet is encrypted separately using the local encryption method to obtain a segmented encrypted data packet corresponding to each sub-data packet, and each segmented encrypted data packet is transmitted to the target ECU according to the second segmented transmission mode.
[0015] According to a third aspect of an embodiment of the present application, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.
[0016] According to a fourth aspect of an embodiment of the present application, a computer-readable storage medium is provided, which stores a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0017] Compared with the prior art, the beneficial effects of the embodiment of the present application include at least: first determining the target ECU and obtaining an upgrade data packet corresponding to the target ECU; then obtaining confidential transmission configuration information corresponding to the target ECU; thereafter, according to the data transmission mode and encryption method in the confidential transmission configuration information, globally encrypting the upgrade data packet using a global encryption method to obtain an overall encrypted data packet, and transmitting the global encrypted data packet to the target ECU according to the first segmented transmission mode; or, splitting the upgrade data packet into multiple sub-data packets, and encrypting each sub-data packet separately using a local encryption method to obtain a segmented encrypted data packet corresponding to each sub-data packet, and transmitting each segmented encrypted data packet to the target ECU according to the second segmented transmission mode, which not only strengthens the confidentiality of the upgrade data packet transmitted from the data transmission end to the target ECU during the OTA upgrade process, but also increases the difficulty of cracking the upgrade data packet by an external device, so that even if the upgrade data packet is intercepted by an external device, it is difficult to crack and restore all the software data, thereby avoiding the leakage of software data, and effectively preventing malicious tampering of the upgrade data by external devices, which is beneficial to ensuring the normal upgrade of the ECU and ensuring the functional integrity and vehicle safety of the whole vehicle. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0019] Figure 1 It is a schematic diagram of an application scenario of an embodiment of the present application;
[0020] Figure 2 It is a flowchart of a method for confidential transmission of an upgrade data packet provided in an embodiment of the present application;
[0021] Figure 3 This is a basic flow chart of a data transmission terminal transmitting upgrade data to an ECU provided in an embodiment of the present application;
[0022] Figure 4 It is a structural schematic diagram of a secure transmission device for an upgrade data packet provided in an embodiment of the present application;
[0023] Figure 5It is a structural schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0024] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0025] A method and device for confidentially transmitting an upgrade data packet according to an embodiment of the present application will be described in detail below with reference to the accompanying drawings.
[0026] Figure 1 1 is a schematic diagram of an application scenario of an embodiment of the present application. The application scenario may include a data transmission terminal 101 and a target ECU 102. The data transmission terminal 101 and the target ECU 102 may be connected via a gateway. The data transmission terminal 101 and the gateway may be connected via an Ethernet bus, and the gateway and the target ECU 102 may be connected via a CAN bus, a CANFD bus or an Ethernet bus. The communication protocol between the data transmission terminal 101 and the target ECU 102 may adopt the UDS (Unified Diagnostic Services) communication protocol.
[0027] The data transmission terminal 101 may be a TBOX (telematics processor), which is used to obtain an upgrade data packet provided by a software developer and forward the upgrade data packet to the target ECU 102 via a gateway.
[0028] The target ECU 102 generally refers to an ECU that needs to be flashed and upgraded, for example, it can be an ECU related to vehicle power control (such as engine, etc.) in the vehicle, or it can be an ECU related to the entertainment system in the vehicle (such as car music, etc.).
[0029] In the embodiment of the present application, the data transmission terminal 101 can be connected to the server of the software developer via a network (which can be a wired network connected by coaxial cable, twisted pair and optical fiber, or a wireless network that can realize the interconnection of various communication devices without wiring, such as Bluetooth, Near Field Communication (NFC), infrared, etc.), and connected to each ECU of the vehicle via a gateway. After determining the target ECU, obtain the upgrade data packet corresponding to the target ECU provided by the software developer; then, obtain the confidential transmission configuration information corresponding to the target ECU; then, according to the data transmission mode and encryption method in the confidential transmission configuration information, use the global encryption method to globally encrypt the upgrade data packet to obtain the overall encrypted data packet, and transmit the global encrypted data packet to the target ECU via the gateway according to the first segmented transmission mode; or, split the upgrade data packet into multiple sub-data packets, and use the local encryption method to encrypt each sub-data packet respectively, to obtain the segmented encrypted data packet corresponding to each sub-data packet, and transmit each segmented encrypted data packet to the target ECU via the gateway according to the second segmented transmission mode. Through the above method, not only the confidentiality of the upgrade data packet transmitted from the data transmission end to the target ECU during the OTA upgrade process is strengthened, but also the difficulty of external devices to crack the upgrade data packet is increased, so that even if the upgrade data packet is intercepted by an external device, it is difficult to crack and restore all the software data, thus avoiding the leakage of software data. In addition, it can effectively prevent external devices from maliciously tampering with the upgrade data, which is conducive to ensuring the normal upgrade of the ECU and ensuring the functional integrity and safety of the entire vehicle.
[0030] Figure 2 It is a flow chart of a method for confidential transmission of an upgrade data packet provided in an embodiment of the present application. Figure 2 The confidentiality transmission method of the upgrade data packet can be Figure 1 The data transmission terminal 101 executes. Figure 2 As shown, the confidentiality transmission method of the upgrade data packet includes:
[0031] Step S201, determining a target ECU, and acquiring an upgrade data package corresponding to the target ECU.
[0032] In one embodiment, the data transmission terminal 101 can determine the target ECU based on the ECU update and upgrade data packet issued by the software developer for a certain (or some) ECU on the vehicle side. For example, the software developer can issue updated ECU upgrade data packets regularly or irregularly, and the data transmission terminal 101 can monitor and download the ECU update and upgrade data packet issued by the software developer in real time. The ECU update and upgrade data packet carries the unique identification information of the ECU (such as a unique ID), and the ECU corresponding to the unique identification information is the target ECU.
[0033] In another embodiment, the data transmission terminal 101 can also determine the target ECU based on the ECU upgrade request initiated by the client (such as the car owner's mobile phone) (the ECU upgrade request carries the unique identification information of the ECU (such as the unique ID)). After the target ECU is determined, the data transmission terminal 101 can make a request to the software developer's server to obtain the upgrade data packet corresponding to the target ECU, and receive the upgrade data packet returned by the server in response to the request.
[0034] Step S202, obtaining confidential transmission configuration information corresponding to the target ECU, the confidential transmission configuration information including a data transmission mode and an encryption method, the data transmission mode including a first segmented transmission mode and a second segmented transmission mode, the encryption method including a global encryption method and a local encryption method.
[0035] In actual applications, the data transmission end 101 can first negotiate with the vehicle end on the confidentiality transmission requirements used for OTA upgrades of different ECUs, and then set the confidentiality transmission configuration information corresponding to each ECU according to the confidentiality transmission requirements.
[0036] Step S203, if the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the first segmented transmission mode, and the encryption method is the global encryption method, the global encryption method is used to globally encrypt the upgrade data packet to obtain an overall encrypted data packet, and the globally encrypted data packet is transmitted to the target ECU according to the first segmented transmission mode.
[0037] Step S204: If the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the second segmented transmission mode and the encryption method is the local encryption method, the upgrade data packet is split into multiple sub-data packets, and each sub-data packet is encrypted separately using the local encryption method to obtain a segmented encrypted data packet corresponding to each sub-data packet, and each segmented encrypted data packet is transmitted to the target ECU according to the second segmented transmission mode.
[0038] The technical solution provided in the embodiment of the present application first determines the target ECU and obtains the upgrade data packet corresponding to the target ECU; then, obtains the confidential transmission configuration information corresponding to the target ECU; thereafter, according to the data transmission mode and encryption method in the confidential transmission configuration information, the upgrade data packet is globally encrypted using a global encryption method to obtain an overall encrypted data packet, and the global encrypted data packet is transmitted to the target ECU according to the first segmented transmission mode; or, the upgrade data packet is split into multiple sub-data packets, and each sub-data packet is encrypted separately using a local encryption method to obtain a segmented encrypted data packet corresponding to each sub-data packet, and each segmented encrypted data packet is transmitted to the target ECU according to the second segmented transmission mode, which not only strengthens the confidentiality of the upgrade data packet transmitted from the data transmission end to the target ECU during the OTA upgrade process, but also increases the difficulty of cracking the upgrade data packet by an external device, so that even if the upgrade data packet is intercepted by an external device, it is difficult to crack and restore all the software data, thereby avoiding the leakage of software data, and effectively preventing malicious tampering of the upgrade data by external devices, which is beneficial to ensuring the normal upgrade of the ECU and ensuring the functional integrity and vehicle safety of the whole vehicle.
[0039] In some embodiments, in the above step S203, the upgrade data package is globally encrypted using a global encryption method to obtain an overall encrypted data package, specifically including:
[0040] Determine the target symmetric encryption algorithm and target key length;
[0041] Extracting first dimension parameters, second dimension parameters and third dimension parameters from the upgrade data packet, the first dimension parameters including summary information of completing this OTA upgrade, the second dimension parameters including the starting address and data length of the data segment completing this confidential transmission, and the third dimension parameters including transmission data information of completing this confidential transmission;
[0042] Generate a symmetric key according to at least one dimension parameter among the first dimension parameter, the second dimension parameter and the third dimension parameter, wherein the key length of the symmetric key is consistent with the target key length;
[0043] Based on the target symmetric encryption algorithm, the upgrade data package is globally encrypted using a symmetric key to obtain an overall encrypted data package.
[0044] The target symmetric encryption algorithm may be any one of the DES (Data Encryption Standard) algorithm, the AES (Advanced Encryption Standard) algorithm, the RC4 algorithm, the CAST algorithm, the Blowfish algorithm, and the like.
[0045] The key length of each target symmetric encryption algorithm is different. For example, the key length of the AES algorithm can be 16 bits, 24 bits, or 32 bits. The target key length can be any key length selected therefrom, for example, 16 bits.
[0046] In practical applications, the target symmetric encryption algorithm and target key length can be flexibly selected according to actual conditions, and are not specifically limited in this application.
[0047] During the OTA upgrade process, the data transmission end uses the UDS protocol to transmit the upgrade data packet to the ECU, mainly using four services, namely #2E write service, #34 request download service, #36 download service, and #37 end download service. The basic process is as follows Figure 3 shown.
[0048] like Figure 3 As shown, the basic process includes the following steps:
[0049] Step S301, #2E write service: write summary information;
[0050] Step S302, #34 requests download service.
[0051] Step S303, #36 download service: data transmission.
[0052] Step S304, determining whether the download is complete.
[0053] Step S305: If the download is complete, then #37 ends the download service.
[0054] Step S306: If the download is not completed, return to step S302.
[0055] In the #2E write service, the summary information of the OTA upgrade is mainly written, and the summary information includes the upgrade method, upgrade time, operation sequence number, etc. The message format is shown in Table 1 below.
[0056] Table 1
[0057]
[0058] Among them, DID stands for diagnosis ID.
[0059] In the #34 download request service, it mainly includes the starting address and data length of the data segment that completes this confidential transmission. Its message format is shown in Table 2 below.
[0060] Table 2
[0061] Data Bytes Parameter name Value (Hex) #1 Request download service ID 34 #2 Data Format xx #3 Address length format xx #4 Memory address (MSB) xx #5 Memory Address xx #6 Memory Address xx #7 Memory address (LSB) xx #8 Data length (MSB) xx #9 Data length xx #10 Data length xx #11 Data length (LSB) xx
[0062] In the #36 download service, it mainly includes the transmission data information for completing this confidential transmission. Its message format is shown in Table 3 below. Among them, the data part can be up to 4095 data.
[0063] Table 3
[0064]
[0065] Exemplarily, the block sequence count may be 0x00 to 0xFF.
[0066] In the #37 download end service, the main information includes the relevant information of ending the transmission of this data segment. The message format is shown in Table 4 below.
[0067] Table 4
[0068] Data Bytes Parameter name Value (Hex) #1 Transfer end service ID 37 #2 Check code (MSB) xx #3 Check code xx #4 Check code xx #5 Check code LSB) xx
[0069] In combination with Tables 1 to 4 above, in some embodiments, the first dimension parameter may be a parameter corresponding to the row where the data bytes are "#4-#13" in Table 1. The second dimension parameter may be a parameter corresponding to the row where the data bytes are "#4-#11" in Table 2. The third dimension parameter may be a parameter corresponding to the row where the data bytes are "#1-#2" in Table 3.
[0070] Next, a symmetric key is generated according to at least one dimension parameter among the first dimension parameter, the second dimension parameter and the third dimension parameter. Specifically, the symmetric key may be generated according to the first dimension parameter, the second dimension parameter and the third dimension parameter.
[0071] As an example, assume that the target symmetric encryption algorithm is the CTR mode (Couter, calculator mode) in the ASE algorithm, and the target key length is 16 bits. Then, the first dimension parameter (the parameter corresponding to the row where "#4-#13" in Table 1), the second dimension parameter (the parameter corresponding to the row where "#4-#11" in Table 2) and the third dimension parameter (the parameter corresponding to the row where "#1-#2" in Table 3) can be merged (for example, the first dimension parameter, the second dimension parameter and the third dimension parameter are spliced together) to obtain the merged parameter; then, the merged parameter is operated by MD5 (Message-Digest Algorithm 5) to obtain a symmetric key with a key length of 16 bits (i.e., the MD5 operation result). After that, some bytes in the MD5 operation result are shuffled or bitwise operated to obtain the self-increment factor. Finally, based on the CTR mode in the ASE algorithm, the upgrade data packet is globally encrypted using the symmetric key and self-increment factor obtained in the above steps to obtain the overall encrypted data packet.
[0072] For example, assume that the parameters corresponding to the rows where 4# to 13# in the first dimension parameters are located are "02", "17", "02", "03", "4F", "54", "41", "20", "20", "20"; the parameters corresponding to the rows where #4-#11 in the second dimension parameters are located are "60", "01", "20", "00", "00", "00", "90", "00"; the parameters corresponding to the rows where #1-#2 in the third dimension parameters are located are "36", "01, 02, 03, 04" respectively. Then, "02", "17", "02", "03", "4F", "54", "41", "20", "20", "20", "60", "01", "20", "00", "00", "00", "90", "00", "36", "01, 02, 03, 04" can be merged to get the merged parameter "02 17 02 03 4F 54 41 20 20 20 60 01 20 0000 00 09 0036 01 02 03 04", and then perform MD5 operation on the merged parameter to get a symmetric key with a key length of 16 bits.
[0073] As another example, in combination with the above example, some parameters can be further selected from the first dimension parameters, the second dimension parameters, and the third dimension parameters for merging, and the MD5 operation is performed on the merged parameters to obtain a symmetric key with a key length of 16 bits. For example, the parameters corresponding to the row where "#4-#8" in the first dimension parameters are located (i.e., "02", "17", "02", "03", "4F"), the parameters corresponding to the row where "#4-#7" in the second dimension parameters are located (i.e., "60", "01", "20", "00"), and the parameters corresponding to the row where "#2" in the third dimension parameters are located (i.e., "01, 02, 03, 04") can be selected for merging, and then the MD5 operation is performed on the merged parameters.
[0074] It can be understood that in the step of generating a symmetric key, all or part of the parameters in the first dimension parameters, all or part of the parameters in the second dimension parameters, and all or part of the parameters in the third dimension parameters can be flexibly selected according to actual needs, and then the MD5 operation is performed to obtain a symmetric key of the target key length.
[0075] As another example, you can also first perform MD5 operation on all or part of the parameters in the first, second and third dimensional parameters respectively to obtain three primary operation results, then merge the three primary operation results to obtain a combined result, and then perform MD5 operation on the combined result to obtain a secondary operation result, that is, to obtain the symmetric key.
[0076] In an embodiment of the present application, by extracting the first dimensional parameters, the second dimensional parameters and the third dimensional parameters in the upgrade data packet, and then generating a symmetric key based on at least one of the dimensional parameters, the second dimensional parameters and the third dimensional parameters, the symmetric key is then used to globally encrypt the upgrade data packet (i.e., encrypt the entire upgrade data packet) to obtain an overall encrypted data packet. This can greatly improve the confidentiality of the upgrade data packet and reduce the risk of the upgrade data packet being intercepted and restored or maliciously tampered with during transmission, which is beneficial to ensuring the normal upgrade of the ECU, thereby ensuring the functional integrity and safety of the entire vehicle.
[0077] In some embodiments, in the above step S203, transmitting the global encrypted data packet to the target ECU according to the first segment transmission mode includes:
[0078] Get the unique identification information of the target ECU;
[0079] In the decryption function library, a function call interface corresponding to the unique identification information is configured;
[0080] Convert the decryption process for the entire encrypted data packet into a decryption library function, put the decryption library function into a decryption function library, and establish a corresponding relationship between the decryption library function and the function call interface;
[0081] The global encrypted data packet is transmitted to the target ECU according to the first segment transmission mode.
[0082] The unique identification information may be a number, letter or other string used to uniquely identify the ECU. For example, it may be ECU1, ECU2, etc. ECU1 and ECU2 represent different ECUs in the same vehicle.
[0083] The decryption function library can be understood as a database for storing decryption library functions that can be called by the ECU. The database can be set in the data transmission end, in the cloud server, or in the vehicle end where the target ECU is located.
[0084] The decryption library function contains the algorithm logic for decrypting the entire encrypted data packet transmitted from the data transmission end, that is, the reverse process of the data transmission end encrypting the upgrade data packet.
[0085] The first segmented transmission mode may be to first split the global encrypted data packet into multiple sub-encrypted data packets, and then transmit each sub-encrypted data packet to the target ECU in batches.
[0086] The target ECU performs global decryption after receiving all sub-encrypted data packets.
[0087] As an example, the target ECU is ECU1, and the unique identification information of ECU1 is "ECU1". In the decryption function library, a function call interface corresponding to "ECU1" is configured. Then, the decryption process for the entire encrypted data packet is converted into a decryption library function, and then put into the decryption function library, and a corresponding relationship between the decryption library function and "ECU1" is established. After that, after receiving the entire encrypted data packet, ECU1 can call the decryption library function corresponding to the function call interface carrying the identification "ECU1" in the decryption function library, and execute the decryption library function to decrypt the entire encrypted data packet, thereby obtaining the decrypted upgrade data packet, and then use the decrypted upgrade data packet for flashing and upgrading.
[0088] In an embodiment of the present application, the data transmission end converts the decryption algorithm logic of the entire encrypted data packet into a decryption library function and puts it into a decryption function library, and provides a function call interface to the target ECU. This allows the target ECU to quickly complete the decryption of the entire encrypted data packet without adding additional key interaction steps between the data transmission end and the target ECU. This not only simplifies the decryption process of the target ECU, but also helps to improve the efficiency of ECU flashing and upgrading.
[0089] In some embodiments, in the above step S204, the upgrade data packet is split into multiple sub-data packets, and each sub-data packet is encrypted separately using a local encryption method to obtain a segmented encrypted data packet corresponding to each sub-data packet, specifically including:
[0090] Determine the number of segments for segmented transmission and the start and end positions of data interception of the data segment corresponding to each segment;
[0091] According to the number of segments and the data interception start and end positions of the data segment corresponding to each segment, the upgrade data packet is split into multiple sub-data packets;
[0092] Determine a local encryption method for encrypting each sub-data packet, where the local encryption methods corresponding to each sub-data packet are the same or different;
[0093] Each sub-data packet is encrypted according to the corresponding local encryption method to obtain a corresponding segmented encrypted data packet.
[0094] The number of segments usually refers to how many data segments the flash upgrade data in an upgrade data packet is divided into. The flash upgrade data usually refers to diagnostic data (eg, UDS data, DOIP data).
[0095] The number of segments can be determined by negotiation between the data transmission end and the vehicle end, or can be set by the data transmission end according to the size of the transmitted data, the transmission network environment, etc., which is not specifically limited in this application. In addition, different numbers of segments can be set for different ECUs.
[0096] The data interception start and end positions refer to the start and end positions of data interception.
[0097] As an example, assuming that the data size of the flash upgrade data in the upgrade data packet 1 is 100MB, the flash upgrade data can be divided into 2 data segments, each of which is 50MB in size. The first data segment is intercepted from the first bit of the flash upgrade data (i.e., the starting position of the data interception of the first data segment) until the data bit with a data size of 50MB (i.e., the end position of the data interception of the first data segment) is intercepted to obtain the first data segment. The starting position of the data interception of the second data segment is the next data bit after the end position of the data interception of the first data segment, and the end position is the last bit of the flash upgrade data. According to the above-mentioned number of segments and the starting and ending positions of the data interception of the data segment corresponding to each segment, the flash upgrade data can be split into 2 sub-data packets, recorded as sub-data packet A and sub-data packet B. Next, determine the local encryption method 1 for sub-data packet A and the local encryption method 2 for sub-data packet B. Local encryption methods 1 and 2 may be the same encryption method or different encryption methods. The local encryption method for different data segments can be determined by negotiation between the data transmission end and the vehicle end, or can be customized by the data transmission end.
[0098] Assume that local encryption methods 1 and 2 are the same and are both as follows. The following is an explanation of local encryption method 1. First, extract the primary parameters, secondary parameters and tertiary parameters in sub-data packet A, where the primary parameters mainly include the summary information written to complete this OTA upgrade, such as the parameters corresponding to the row where "#4-#13" is located in Table 1; the secondary parameters mainly include the starting address and data length of the flash upgrade data of sub-data packet A that completes this confidential transmission; the tertiary parameters mainly include the transmission data information that completes this confidential transmission, for example, the request identifier and block sequence count of the flash upgrade data of sub-data packet A. Then, according to at least one level of parameters among the primary parameters, the secondary parameters and the tertiary parameters, a symmetric key is generated, and the key length of the symmetric key is consistent with the preset target key length; then based on the pre-selected target symmetric encryption algorithm (such as the ASE algorithm, etc.), the symmetric key is used to encrypt sub-data packet A to obtain a segmented encrypted data packet A.
[0099] Similarly, referring to the encryption method of the segmented encrypted data packet A, the sub-data packet B can be encrypted using the local encryption method 2 to obtain the segmented encrypted data packet B. This will not be described in detail here.
[0100] In some embodiments, the upgrade data packet is split into multiple sub-data packets according to the number of segments and the data interception start and end positions of the data segments corresponding to each segment, specifically including:
[0101] Create multiple data encapsulation structures, the number of which is the same as the number of segments;
[0102] Assign a unique segment identification information to each data encapsulation structure;
[0103] According to the data interception start and end positions of the data segment corresponding to each segment, the corresponding segmented data segment is intercepted from the upgrade data packet;
[0104] The segmented data segment is filled into the data encapsulation structure having the same unique segment identification information as the segmented data segment to obtain the corresponding sub-data packet.
[0105] The unique segment identification information may be a number, letter, or other string used to uniquely identify the data encapsulation structure, for example, F1, F2, etc.
[0106] Multiple data encapsulation structures, including a data encapsulation structure for encapsulating non-last data segments and a data encapsulation structure for encapsulating the last data segment. The data encapsulation structure for encapsulating non-last data segments mainly includes first, second, third and fourth data frames connected in sequence, wherein the first data frame is mainly used to store primary parameters, the second data frame is mainly used to store secondary parameters, the third data frame is mainly used to store tertiary parameters, and the fourth data frame is mainly used to store data segments for flashing upgrade data. The data encapsulation structure for encapsulating the last data segment also includes a fifth data frame, which is mainly used to store relevant information for ending the data transmission of this data segment (including a transmission exit request identifier, etc.).
[0107] Combined with the above example, assuming that the number of segments is 2, then create 2 data encapsulation structures, and assign a unique segment identification information, such as "F1, F2" to each data encapsulation structure. According to the above data interception start and end positions of the first data segment and the second data segment, the first data segment and the second data segment can be intercepted from the flash upgrade data of the upgrade data packet 1. Then, fill the first data segment into the fourth data frame of the data encapsulation structure carrying the identification "F1", and fill the second data segment into the fourth data frame of the data encapsulation structure carrying the identification "F2". Next, fill the first-level parameters, second-level parameters and third-level parameters corresponding to the first data segment into the first, second and third data frames of the data encapsulation structure carrying the identification "F1" respectively, and obtain sub-data packet A. Fill the first-level parameters, second-level parameters and third-level parameters corresponding to the second data segment into the first, second and third data frames of the data encapsulation structure carrying the identification "F2", and fill the relevant information of ending the data transmission of this data segment (including the transmission exit request identification, etc.) into the fifth data frame to obtain sub-data packet B.
[0108] In an embodiment of the present application, by first splitting the upgrade data packet and then locally encrypting each sub-data packet using the same or different local encryption methods, the confidentiality of the upgrade data packet can be further improved, while greatly increasing the difficulty of external devices to crack the upgrade data packet, thereby further improving the transmission security of the upgrade data packet.
[0109] In some embodiments, in the above step S204, each segmented encrypted data packet is transmitted to the target ECU according to the second segmented transmission mode, including:
[0110] Determine the transmission timing of each segmented encrypted data packet;
[0111] According to the transmission timing, each segmented encrypted data packet is transmitted to the target ECU in sequence.
[0112] Transmission timing refers to the time and order of transmission.
[0113] In some embodiments, the transmission timing of each segmented encrypted data packet may be determined in the following manner: Specifically, the required transmission resources and data segment assembly order of each segmented encrypted data packet, as well as the currently available transmission resources, may be determined first; then, the transmission timing of each segmented encrypted data packet may be determined based on the required transmission resources, data segment assembly order, and currently available transmission resources.
[0114] The required transmission resources mainly refer to the target ECU's expectation that the data transmission end can transmit a certain amount of segmented encrypted data packets to it completely within a unit time. It can be understood as the amount of data actually transmitted between the target ECU and the data transmission end within a unit time, that is, the data throughput, and the unit is usually bits / second. For example, the data size of a segmented encrypted data packet is 1024 bits, and the target ECU expects the data transmission end to transmit the segmented encrypted data packet to it completely within 1 second, then the required transmission resources for the segmented encrypted data packet are 1024 bits / second.
[0115] The currently available transmission resources mainly refer to the maximum available throughput that the data transmission end can currently use to transmit data to the target ECU, and the unit is usually bit / second.
[0116] The data segment assembly order is the same as the data interception order for the flash upgrade data in the process of splitting the upgrade data packet into multiple sub-data packets. That is, when the upgrade data packet is split into multiple sub-data packets, the first data segment...Nth data segment are intercepted from the first bit of the flash upgrade data, where N is a positive integer ≥ 2. For example, the data interception order for the flash upgrade data is the first data segment → the Nth data segment, and the data segment assembly order is also the first data segment...Nth data segment.
[0117] As an example, assuming that there are currently 4 segmented encrypted data packets to be transmitted, recorded as segmented encrypted data packets 1, 2, 3, and 4, the required transmission resources corresponding to the segmented encrypted data packets 1, 2, 3, and 4 can be determined first. If the required transmission resources of the segmented encrypted data packets 1, 2, 3, and 4 are 1024 bits / second, 1024 bits / second, 2048 bits / second, and 3072 bits / second, respectively. The current available transmission resources of the data transmission end are 1024 megabits / second. By comparison, it can be seen that the current available transmission resources of the data transmission end are greater than the sum of the required transmission resources of the segmented encrypted data packets 1, 2, 3, and 4. If the data assembly order of the segmented encrypted data packets 1, 2, 3, and 4 is determined to be segmented encrypted data packets 1→2→3→4, then the transmission timing of the segmented encrypted data packets 1, 2, 3, and 4 can be determined to be segmented encrypted data packets 1 (corresponding to transmission time 1)→2 (corresponding to transmission time 2)→3 (corresponding to transmission time 3)→4 (corresponding to transmission time 4).
[0118] Of course, a parallel transmission method can also be adopted to transmit the segmented encrypted data packets 1, 2, 3, and 4 to the target ECU in parallel.
[0119] In order to increase the difficulty of external devices restoring and cracking the upgrade data packet, the transmission sequence of the segmented encrypted data packet can be disrupted. For example, the correct data assembly order can be disrupted into segmented encrypted data packets 1→4→2→3, that is, a new transmission sequence is obtained. The data transmission end can segment encrypted data packets 1→4→2→3 according to the new transmission sequence, and transmit the segmented encrypted data packets 1, 4, 2, and 3 to the target ECU in sequence.
[0120] After receiving each segmented encrypted data packet, the target ECU decrypts each segmented encrypted data packet respectively, combines the decrypted data into complete upgrade flash writing data, and uses the complete upgrade flash writing data for upgrade flash writing.
[0121] All the above optional technical solutions can be arbitrarily combined to form optional embodiments of the present application, which will not be described one by one here.
[0122] The following is an embodiment of the device of the present application, which can be used to execute the embodiment of the method of the present application. For details not disclosed in the embodiment of the device of the present application, please refer to the embodiment of the method of the present application.
[0123] Figure 4 Schematic diagram of a secure transmission device for an upgrade data packet provided in an embodiment of the present application. Figure 4 As shown, the confidentiality transmission device of the upgrade data packet includes:
[0124] The determination module 401 is configured to determine a target ECU and obtain an upgrade data packet corresponding to the target ECU;
[0125] The acquisition module 402 is configured to acquire confidential transmission configuration information corresponding to the target ECU, wherein the confidential transmission configuration information includes a data transmission mode and an encryption mode, wherein the data transmission mode includes a first segment transmission mode and a second segment transmission mode, and the encryption mode includes a global encryption mode and a local encryption mode;
[0126] The first transmission module 403 is configured to, if the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the first segmented transmission mode and the encryption mode is the global encryption mode, globally encrypt the upgrade data packet using the global encryption mode to obtain an overall encrypted data packet, and transmit the globally encrypted data packet to the target ECU according to the first segmented transmission mode;
[0127] The second transmission module 404 is configured to split the upgrade data packet into multiple sub-data packets, and encrypt each sub-data packet separately using the local encryption method if the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the second segmented transmission mode and the encryption method is the local encryption method, so as to obtain a segmented encrypted data packet corresponding to each sub-data packet, and transmit each segmented encrypted data packet to the target ECU according to the second segmented transmission mode.
[0128] The technical solution provided by the embodiment of the present application first determines the target ECU through the determination module 401, and obtains the upgrade data packet corresponding to the target ECU; then, the acquisition module 402 obtains the confidential transmission configuration information corresponding to the target ECU; thereafter, the first transmission module 403 globally encrypts the upgrade data packet in a global encryption manner according to the data transmission mode and encryption method in the confidential transmission configuration information, obtains an overall encrypted data packet, and transmits the global encrypted data packet to the target ECU according to the first segmented transmission mode; or, the second transmission module 404 splits the upgrade data packet into multiple sub-data packets, and encrypts each sub-data packet respectively in a local encryption manner to obtain a segmented encrypted data packet corresponding to each sub-data packet, and transmits each segmented encrypted data packet to the target ECU according to the second segmented transmission mode, which not only strengthens the confidentiality of the upgrade data packet transmitted by the data transmission end to the target ECU during the OTA upgrade process, but also increases the difficulty of cracking the upgrade data packet by an external device, so that even if the upgrade data packet is intercepted by an external device, it is difficult to crack and restore all the software data, thereby avoiding the leakage of software data, and effectively preventing malicious tampering of the upgrade data by external devices, which is conducive to ensuring the normal upgrade of the ECU and ensuring the functional integrity and vehicle safety of the whole vehicle.
[0129] In some embodiments, the first transmission module 403 includes:
[0130] a determination unit configured to determine a target symmetric encryption algorithm and a target key length;
[0131] The extraction unit is configured to extract a first dimension parameter, a second dimension parameter, and a third dimension parameter from the upgrade data packet, wherein the first dimension parameter includes summary information for completing this OTA upgrade, the second dimension parameter includes a starting address and a data length of a data segment for completing this confidential transmission, and the third dimension parameter includes transmission data information for completing this confidential transmission;
[0132] A generating unit is configured to generate a symmetric key according to at least one dimension parameter among the first dimension parameter, the second dimension parameter and the third dimension parameter, wherein the key length of the symmetric key is consistent with the target key length;
[0133] The global encryption unit is configured to globally encrypt the upgrade data packet using a symmetric key based on a target symmetric encryption algorithm to obtain an overall encrypted data packet.
[0134] In an embodiment of the present application, by extracting the first dimensional parameters, the second dimensional parameters and the third dimensional parameters in the upgrade data packet, and then generating a symmetric key based on at least one of the dimensional parameters, the second dimensional parameters and the third dimensional parameters, the symmetric key is then used to globally encrypt the upgrade data packet (i.e., encrypt the entire upgrade data packet) to obtain an overall encrypted data packet. This can greatly improve the confidentiality of the upgrade data packet and reduce the risk of the upgrade data packet being intercepted and restored or maliciously tampered with during transmission, which is beneficial to ensuring the normal upgrade of the ECU, thereby ensuring the functional integrity and safety of the entire vehicle.
[0135] In some embodiments, the first transmission module 403 further includes:
[0136] An information acquisition unit is configured to acquire unique identification information of a target ECU;
[0137] A configuration unit is configured to configure a function call interface corresponding to the unique identification information in the decryption function library;
[0138] An establishing unit is configured to convert the decryption process for the entire encrypted data packet into a decryption library function, put the decryption library function into a decryption function library, and establish a corresponding relationship between the decryption library function and the function call interface;
[0139] The transmission unit is configured to transmit the global encrypted data packet to the target ECU according to the first segment transmission mode.
[0140] In an embodiment of the present application, the data transmission end converts the decryption algorithm logic of the entire encrypted data packet into a decryption library function and puts it into a decryption function library, and provides a function call interface to the target ECU. This allows the target ECU to quickly complete the decryption of the entire encrypted data packet without adding additional key interaction steps between the data transmission end and the target ECU. This not only simplifies the decryption process of the target ECU, but also helps to improve the efficiency of ECU flashing and upgrading.
[0141] In some embodiments, the second transmission module 404 includes:
[0142] A segment determination unit is configured to determine the number of segments of the segmented transmission and the data interception start and end positions of the data segment corresponding to each segment;
[0143] A splitting unit is configured to split the upgrade data packet into a plurality of sub-data packets according to the number of segments and the data interception start and end positions of the data segment corresponding to each segment;
[0144] An encryption mode determination unit is configured to determine a local encryption mode for encrypting each sub-data packet, wherein the local encryption modes corresponding to the sub-data packets are the same or different;
[0145] The local encryption unit is configured to encrypt each sub-data packet according to the corresponding local encryption method to obtain a corresponding segmented encrypted data packet.
[0146] In an embodiment of the present application, by first splitting the upgrade data packet and then locally encrypting each sub-data packet using the same or different local encryption methods, the confidentiality of the upgrade data packet can be further improved, while greatly increasing the difficulty of external devices to crack the upgrade data packet, thereby further improving the transmission security of the upgrade data packet.
[0147] In some embodiments, the splitting unit specifically includes:
[0148] A creation component is configured to create a plurality of data encapsulation structures, the number of the plurality of data encapsulation structures being the same as the number of the segments;
[0149] An allocating component configured to allocate a unique segment identification information to each data encapsulation structure;
[0150] The interception component is configured to intercept the corresponding segmented data segments from the upgrade data packet according to the data interception start and end positions of the data segments corresponding to each segment;
[0151] The filling component is configured to fill the segmented data segment into a data encapsulation structure having the same unique segment identification information as the segmented data segment to obtain a corresponding sub-data packet.
[0152] In some embodiments, the second transmission module 404 further includes:
[0153] A timing determination unit, configured to determine a transmission timing of each segmented encrypted data packet;
[0154] The segmented transmission unit is configured to transmit each segmented encrypted data packet to the target ECU in sequence according to the transmission timing.
[0155] In some embodiments, the timing determination unit specifically includes:
[0156] a determination component configured to determine required transmission resources and a data segment assembly order for each segmented encrypted data packet, and currently available transmission resources;
[0157] The timing determination component is configured to determine the transmission timing of each segmented encrypted data packet according to the required transmission resources, the data segment assembly order and the currently available transmission resources.
[0158] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0159] Figure 5 Schematic diagram of an electronic device 5 provided in an embodiment of the present application. Figure 5 As shown, the electronic device 5 of this embodiment includes: a processor 501, a memory 502, and a computer program 503 stored in the memory 502 and executable on the processor 501. When the processor 501 executes the computer program 503, the steps in the above-mentioned method embodiments are implemented. Alternatively, when the processor 501 executes the computer program 503, the functions of the modules / units in the above-mentioned device embodiments are implemented.
[0160] The electronic device 5 may be a desktop computer, a notebook, a PDA, a cloud server, or other electronic device. The electronic device 5 may include, but is not limited to, a processor 501 and a memory 502. Those skilled in the art will appreciate that Figure 5 The electronic device 5 is merely an example and does not limit the electronic device 5 , and may include more or less components than those shown in the figure, or different components.
[0161] The processor 501 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0162] The memory 502 may be an internal storage unit of the electronic device 5, for example, a hard disk or memory of the electronic device 5. The memory 502 may also be an external storage device of the electronic device 5, for example, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 5. The memory 502 may also include both an internal storage unit of the electronic device 5 and an external storage device. The memory 502 is used to store computer programs and other programs and data required by the electronic device.
[0163] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units.
[0164] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. The computer program may include computer program code, and the computer program code may be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electric carrier signals and telecommunication signals.
[0165] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A method for confidential transmission of upgrade data packets, characterized in that: include: Determine a target ECU, and obtain an upgrade data packet corresponding to the target ECU; Acquire confidential transmission configuration information corresponding to the target ECU, the confidential transmission configuration information including a data transmission mode and an encryption mode, the data transmission mode including a first segment transmission mode and a second segment transmission mode, the encryption mode including a global encryption mode and a local encryption mode; the global encryption mode extracts at least one dimension parameter from the upgrade data packet to generate a symmetric key, the local encryption mode extracts at least one level parameter from a sub-data packet to generate a symmetric key corresponding to the sub-data packet, and the key length of the symmetric key is consistent with the target key length; If the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the first segmented transmission mode and the encryption mode is the global encryption mode, the upgrade data packet is globally encrypted in the global encryption mode to obtain an overall encrypted data packet, and the overall encrypted data packet is transmitted to the target ECU in the first segmented transmission mode; If the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the second segmented transmission mode, and the encryption method is the local encryption method, the upgrade data packet is split into multiple sub-data packets, and each of the sub-data packets is encrypted separately using the local encryption method to obtain a segmented encrypted data packet corresponding to each of the sub-data packets, and each of the segmented encrypted data packets is transmitted to the target ECU according to the second segmented transmission mode.
2. The method according to claim 1, characterized in that The upgrade data packet is globally encrypted using a global encryption method to obtain an overall encrypted data packet, including: Determine the target symmetric encryption algorithm and target key length; Extracting a first dimension parameter, a second dimension parameter and a third dimension parameter from the upgrade data packet, wherein the first dimension parameter includes summary information of completing this OTA upgrade, the second dimension parameter includes a starting address and a data length of a data segment for completing this confidential transmission, and the third dimension parameter includes transmission data information for completing this confidential transmission; Generate a symmetric key according to at least one dimension parameter among the first dimension parameter, the second dimension parameter and the third dimension parameter; Based on the target symmetric encryption algorithm, the upgrade data packet is globally encrypted using the symmetric key to obtain an overall encrypted data packet.
3. The method according to claim 2, characterized in that Transmitting the entire encrypted data packet to the target ECU according to the first segment transmission mode includes: Obtaining unique identification information of the target ECU; In the decryption function library, a function calling interface corresponding to the unique identification information is configured; Converting the decryption process for the entire encrypted data packet into a decryption library function, placing the decryption library function into the decryption function library, and establishing a corresponding relationship between the decryption library function and the function call interface; The entire encrypted data packet is transmitted to the target ECU according to a first segmented transmission mode.
4. The method according to claim 1, characterized in that The upgrade data packet is split into multiple sub-data packets, and each of the sub-data packets is encrypted respectively using a local encryption method to obtain a segmented encrypted data packet corresponding to each of the sub-data packets, including: Determine the number of segments for segmented transmission and the start and end positions of data interception of the data segment corresponding to each segment; According to the number of segments and the data interception start and end positions of the data segments corresponding to each segment, the upgrade data packet is split into a plurality of sub-data packets; Determine a local encryption method for encrypting each of the sub-data packets, where the local encryption methods corresponding to the sub-data packets are the same or different; Each of the sub-data packets is encrypted according to the corresponding local encryption method to obtain a corresponding segmented encrypted data packet.
5. The method according to claim 4, characterized in that According to the number of segments and the data interception start and end positions of the data segments corresponding to each segment, the upgrade data packet is split into multiple sub-data packets, including: Creating a plurality of data encapsulation structures, wherein the number of the plurality of data encapsulation structures is the same as the number of the segments; Allocating a unique segment identification information to each of the data encapsulation structures; According to the data interception start and end positions of the data segments corresponding to each segment, the corresponding segmented data segments are intercepted from the upgrade data packet; The segmented data segment is filled into a data encapsulation structure having the same unique segment identification information as the segmented data segment to obtain a corresponding sub-data packet.
6. The method according to claim 1, characterized in that Transmitting each of the segmented encrypted data packets to the target ECU according to the second segmented transmission mode, including: Determining the transmission timing of each of the segmented encrypted data packets; Each of the segmented encrypted data packets is transmitted to the target ECU in sequence according to the transmission timing.
7. The method according to claim 6, characterized in that Determining the transmission timing of each of the segmented encrypted data packets, comprising: Determining the required transmission resources and data segment assembly order of each of the segmented encrypted data packets, as well as currently available transmission resources; The transmission timing of each of the segmented encrypted data packets is determined according to the required transmission resources, the data segment assembly order and the currently available transmission resources.
8. A secure transmission device for upgrading data packets, characterized in that: include: A determination module is configured to determine a target ECU and obtain an upgrade data packet corresponding to the target ECU; an acquisition module, configured to acquire confidential transmission configuration information corresponding to the target ECU, the confidential transmission configuration information including a data transmission mode and an encryption mode, the data transmission mode including a first segment transmission mode and a second segment transmission mode, the encryption mode including a global encryption mode and a local encryption mode; the global encryption mode extracts at least one dimension parameter from the upgrade data packet to generate a symmetric key, and the local encryption mode extracts at least one level parameter from a sub-data packet to generate a symmetric key corresponding to the sub-data packet; A first transmission module is configured to globally encrypt the upgrade data packet using the global encryption mode to obtain an overall encrypted data packet if the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the first segmented transmission mode and the encryption mode is the global encryption mode, and transmit the overall encrypted data packet to the target ECU according to the first segmented transmission mode; The second transmission module is configured to split the upgrade data packet into multiple sub-data packets, and encrypt each of the sub-data packets separately using the local encryption method if the data transmission mode in the confidential transmission configuration information corresponding to the target ECU is the second segmented transmission mode and the encryption method is the local encryption method, so as to obtain a segmented encrypted data packet corresponding to each of the sub-data packets, and transmit each of the segmented encrypted data packets to the target ECU according to the second segmented transmission mode.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
In-vehicle electronic control unit upgrading method, device and equipment and vehicle system
CN111356114A