A Quantum-Secure OTA Upgrade Method and System

The vehicle key information and upgraded data packets are encrypted and protected by quantum keys and device-independent quantum random numbers, solving the security risks in the existing OTA upgrade technology and achieving high security and efficient data transmission.

CN116566824BActive Publication Date: 2025-07-18JINAN INST OF QUANTUM TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310594460.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-23
Publication Date
2025-07-18
Estimated Expiration
2043-05-23

AI Technical Summary

Technical Problem

The existing OTA upgrade technology has security risks. The digital certificate authentication system for asymmetric keys is deployed in complex and easy to be cracked. The method of pre-setting shared keys is not very easy to use and secure, resulting in an increase in the risk of data leakage during terminal upgrades.

Method used

The vehicle key information and upgrade data packets during the OTA upgrade process are encrypted and protected by quantum key and device-independent quantum random numbers. The dual verification of the quantum key and device-independent quantum random number blocks is performed to ensure data transmission security and symmetric encryption is used to improve efficiency.

Benefits of technology

It improves the security and efficiency of data transmission during the OTA upgrade process, ensures communication security, reduces the risk of data leakage, and improves the security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116566824B_ABST
    Figure CN116566824B_ABST
Patent Text Reader

Abstract

The present invention provides a quantum-secure OTA upgrade method and system, which relates to the fields of vehicle networking and communication technologies. A quantum key is shared between a vehicle management server and an OTA server; a device-independent quantum random number generator is provided at the vehicle management server, and the OTA server stores upgrade data packets of different versions for vehicle upgrade. After receiving the upgrade data packet, the vehicle performs an upgrade and transmits the latest vehicle information to the vehicle management server; the OTA upgrade method uses a quantum key and a quantum random number to encrypt and protect the key vehicle information and the upgrade data packet during the OTA upgrade process, and performs double verification on the vehicle information and the random number during the upgrade process, improving the security of data transmission during the OTA upgrade process. Symmetric encryption is adopted during the upgrade process, which improves the efficiency while ensuring security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of vehicle networking and communication technologies, and particularly to a quantum-secure OTA upgrade method and system. Background Art

[0002] With the continuous development of computer technologies, network technologies, etc., the number of terminals is increasing. People's requirements for the intelligence and security of terminals are also getting higher and higher, and terminals are becoming more intelligent and multimedia. Various hardware and software (applications) are often deployed in current terminals. For example, vehicles are equipped with intelligent cockpits, sensing systems, and autonomous driving systems, and also install in-vehicle operating systems, navigation applications, audio and video playback applications, etc. Although these hardware and software make the functions of the terminal more abundant, they are also more likely to have vulnerabilities or need to be replaced with more advanced versions, etc. Therefore, it is necessary to upgrade and update the hardware and software (applications) of the terminal.

[0003] OTA technology mainly performs automatic upgrades by downloading OTA upgrade data packets (and also supports upgrades by copying the OTA upgrade package to the SD card). OTA upgrades are fast and have little impact on data. Therefore, OTA upgrades have become the main method for terminal function upgrades. While providing convenience, this method also has certain security risks. For example, passwords are easily leaked, resulting in the leakage of upgrade data, causing the core technologies of component suppliers to be leaked or relevant data to be exposed. In severe cases, it will even threaten the driving safety of vehicle users. Currently, the security measures for OTA upgrades include a digital certificate authentication system using asymmetric keys, or data protection and key negotiation during the authentication process based on pre-set shared keys. Deploying the digital certificate authentication system is relatively complex, increasing the cost of the system, and based on the asymmetric cryptographic algorithm with computational complexity, there is a risk of being cracked as computing power improves; the method of pre-setting shared keys requires manual pre-setting of the keys used in the authentication method, and still requires manual updates when the keys are updated, with low usability and security. Summary of the Invention

[0004] To solve the above technical problems, this solution proposes a quantum-secure OTA upgrade method, which uses quantum keys and quantum random numbers (especially device-independent quantum random numbers) to encrypt and protect the key vehicle information and upgrade data packets during the OTA upgrade process, improving the security of data transmission during the OTA upgrade process.

[0005] A quantum-secure OTA upgrade method includes the following steps:

[0006] Step 1: Share a quantum key between the vehicle management server and the OTA server;

[0007] Step 2: After the OTA server receives the updated vehicle version information list or the latest version information, it finds the corresponding quantum key according to the key identifier, decrypts the vehicle version information list or the latest version information, and compares whether the version number of the current software in the vehicle version information list is the latest version number. If the two are inconsistent, it sends the latest version number to the relevant vehicles and asks whether an upgrade is required;

[0008] Step 3: After the vehicle receives the new upgrade query, it determines whether an upgrade is required. If an upgrade is required, it sends an upgrade request to the vehicle management server. The upgrade request includes vehicle version information, the new version number to be upgraded, and the device-independent quantum random number block of the vehicle, and performs an irreversible function operation on the device-independent quantum random number block and the latest version number to obtain the key X(RAND);

[0009] Step 4: After the vehicle management server decrypts the upgrade request sent by the vehicle using the key X(RAND), the vehicle management server verifies the upgrade request sent by the vehicle and performs double verification on the vehicle version information and the device-independent quantum random number block;

[0010] Step 5: The vehicle management server selects a new quantum key QKD3 and sends the vehicle version information, the version number that the vehicle is about to upgrade, and the key X(RAND) to the OTA server by means of quantum key encryption, and sends the key identifier IDQKD3 corresponding to the quantum key to the OTA server;

[0011] Step 6: The OTA server finds the corresponding shared quantum key according to the key identifier, decrypts the information of the vehicle ID, the existing vehicle version number, the version number that the vehicle is about to upgrade, and the key X(RAND), and compares the vehicle ID and the existing vehicle version information. After successful comparison, it encrypts the upgrade data packet with the key X(RAND) as the key and sends it to the vehicle;

[0012] Step 7: After the vehicle receives the upgrade data packet, it decrypts the upgrade data with the key X(RAND) for upgrading. After the upgrade is completed, the vehicle feeds back the confirmation information and the latest version number to the vehicle management server, and encrypts the latest vehicle version information with the key X(RAND) as the key and sends it to the vehicle management server;

[0013] Step 8: The vehicle management server decrypts the vehicle version information with the key X(RAND), updates the version number corresponding to the vehicle in the list information according to the feedback latest version number, and sends the latest vehicle version information list to the OTA server by means of quantum key QKD4 encryption, and sends the quantum key identifier IDQKD4;

[0014] Step 9: The OTA server finds the corresponding quantum key according to the quantum key identifier IDQKD4, decrypts the vehicle version information sent in Step 8 with the quantum key, and the OTA server updates the vehicle information list.

[0015] Further, in Step S3, the upgrade request includes vehicle version information, the new version number to be upgraded, and the random number block of the vehicle, and an irreversible function operation is performed on the random number block and the new version number. Let the number represented by the random number block be a and the version number be v. The calculation method of the N-bit encryption key is: Let t be the first N digits of a, and the N-bit key X(RAND)=a v mod t, where mod is the remainder function, and N is determined by the data length of the upgrade request.

[0016] Further, in Step S4, double verification is performed on the vehicle version information and the random number block: Compare whether the vehicle ID and the existing vehicle version number are the same as the content in the previously stored vehicle information list; Compare and verify the device-independent quantum random number block with the device-independent quantum random number blocks adjacent before and after in the random number block list, and verify the timestamp, the digital signature of the server, and the hash values of the previous and subsequent device-independent quantum random number blocks.

[0017] Further, let the device-independent quantum random number block corresponding to vehicle ID(n) be RAND(n), the device-independent quantum random number block corresponding to vehicle ID(n - 1) be RAND(n - 1), and the device-independent quantum random number block corresponding to vehicle ID(n + 1) be RAND(n + 1). Verify: (1) The timestamp of RAND(n) is later than RAND(n - 1) and the timestamp of RAND(n) is earlier than RAND(n + 1); (2) The digital signatures of RAND(n) and RAND(n - 1), RAND(n + 1) are the same; (3) The "hash value of the previous device-independent quantum random number block" in RAND(n) is equal to the "device-independent quantum random number block" in RAND(n - 1); The "hash value of the previous device-independent quantum random number block" in RAND(n + 1) is equal to the "device-independent quantum random number block" in RAND(n). If all three points are satisfied, the verification is successful, and Step 5 is performed. If the verification fails, the process ends, and an end-of-process message is sent to the vehicle.

[0018] Further, in Step S1, if the vehicle version information is updated, the vehicle management server sends the vehicle version information list to the OTA server in the encrypted manner of quantum key QKD1. If there is a new upgrade version, the vehicle management server sends the latest vehicle version information to the OTA server in the encrypted manner of quantum key QKD2.

[0019] Further, the quantum key transmits the ciphertext in a one-time pad manner.

[0020] The present invention also proposes a quantum - secure OTA upgrade system for implementing the quantum - secure OTA upgrade method, including: a vehicle management server, an OTA server, and a vehicle;

[0021] The vehicle management server and the OTA server are connected through a quantum network, and they share a quantum key;

[0022] After the OTA server receives the updated vehicle version information list or the latest version information, it finds the corresponding quantum key according to the key identifier;

[0023] A device - independent quantum random number generator is provided at the vehicle management server, and the device - independent quantum random number server sends the newly generated device - independent quantum random number blocks to the vehicle in the order of vehicle IDs;

[0024] The OTA server stores upgrade data packets of different versions, sends the latest version number to the vehicle that needs to be upgraded, and can send the upgrade data packet to the vehicle that needs to be upgraded for the vehicle to perform the upgrade;

[0025] The vehicle, as a terminal device, performs the upgrade after receiving the upgrade data packet and transmits the latest vehicle information to the vehicle management server.

[0026] Compared with the prior art, the present invention has the following beneficial technical effects:

[0027] This solution proposes a quantum - secure OTA upgrade method, which uses quantum keys and quantum random numbers (especially device - independent quantum random numbers) to encrypt and protect the key vehicle information and upgrade data packets during the OTA upgrade process, performs double - verification on the vehicle information and random numbers during the upgrade process, improves the security of data transmission during the OTA upgrade process, and uses symmetric encryption during the upgrade process, which improves the efficiency while ensuring security.

[0028] 1. Based on quantum keys and device - independent quantum random numbers, a new OTA upgrade method is proposed, and this solution has high security and reliability.

[0029] 2. The vehicle management server and the OTA server use a shared quantum key to ensure the communication security between the two.

[0030] 3. During the OTA upgrade process, if the vehicle needs to be upgraded, a function operation is performed using the version information and the initialized random number block, such as calculating their hash values, to ensure that the passwords used in each upgrade are different.

[0031] 4. The vehicle management server only verifies the upgrade request sent from the vehicle side, performs double - verification on the vehicle information and random numbers, and improves the security.

[0032] 5. The vehicle management server and the vehicle terminal perform the same irreversible function operation on the random number block and the latest version number information of the corresponding vehicle to obtain the key X(RAND), which can ensure that the upgrade requests for each version are different keys, facilitating the secure data transmission between the two.

[0033] 6. During the data transmission process, both the quantum key and the key X(RAND) are symmetric keys, which improve the encryption and decryption efficiency while ensuring the security of encryption and decryption. Description of the Drawings

[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0035] Figure 1 Schematic diagram of the OTA upgrade system of the present invention;

[0036] Figure 2 Data structure diagram of the quantum random number block irrelevant to the present invention;

[0037] Figure 3 Schematic diagram of the vehicle version information list of the present invention;

[0038] Figure 4 OTA upgrade flowchart of the present invention. Detailed Embodiments

[0039] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.

[0040] In the drawings of the specific embodiments of the present invention, in order to better and more clearly describe the working principles of the components in the system and show the connection relationships of the various parts of the device, only the relative positional relationships between the components are clearly distinguished, and it does not constitute a limitation on the signal transmission direction, connection sequence, and the sizes, dimensions, and shapes of the various parts of the structure within the component or structure.

[0041] The OTA upgrade system proposed in this solution is as Figure 1As shown in the figure, it includes a vehicle management server, an OTA server, and vehicles. The vehicle management server and the OTA server are connected through a quantum network, and the two can share quantum keys. Each group of keys QKDn has a corresponding key identifier IDQKDn, and both parties can find the corresponding shared quantum key according to the key identifier.

[0042] A device-independent quantum random number generator is set at the vehicle management server. When the vehicle leaves the factory, the device-independent quantum random number server sends newly generated blocks of device-independent quantum random numbers with uniform randomness to the vehicle in the order of vehicle ID. Each block of device-independent quantum random numbers contains newly generated device-independent quantum random numbers, and also has a timestamp, a digital signature of the vehicle server, and the hash value of the previous random number block, so as to prevent the tampering of the generated data and facilitate the subsequent verification of the random number blocks by the vehicle management server. At the same time, a list of random number blocks is formed at the vehicle management server and arranged in the order of vehicle ID. The data structure of the device-independent quantum random number blocks in the list of random number blocks is as Figure 2 shown.

[0043] A vehicle version information list is formed at the vehicle management server. The vehicle version information list contains the vehicle information of all vehicles that have left the factory and is arranged in the order of vehicle ID. The vehicle version information list is as Figure 3 shown, and includes: vehicle ID, version number of the vehicle's current software.

[0044] Among them, the vehicle management server has two lists. One is the list of random number blocks, which is formed when the vehicle leaves the factory and the data in it usually does not change. The other is the vehicle version information list, which stores the vehicle ID and the vehicle's version number. If the vehicle upgrades the version, the vehicle version information will change.

[0045] The vehicle management server manages and stores the vehicle version information and generates the latest version of the upgrade data packet.

[0046] The OTA server stores different versions of the upgrade data packets, can send the latest version number to the vehicles that need to be upgraded, and can also send the upgrade data packets to the vehicles that need to be upgraded for the vehicles to perform the upgrade.

[0047] As a terminal device, the vehicle initiates an upgrade request according to its own needs, performs the upgrade after receiving the upgrade data packet, and transmits the latest vehicle information to the vehicle management server.

[0048] The OTA upgrade process of this solution is as Figure 4 shown, and the specific steps are as follows:

[0049] Step 1: Share quantum keys between the vehicle management server and the OTA server.

[0050] If the vehicle version information is updated, the vehicle management server sends the vehicle version information list to the OTA server in an encrypted manner using the quantum key QKD1. If there is a new upgrade version, the vehicle management server sends the latest vehicle version information to the OTA server in an encrypted manner using the quantum key QKD2. The vehicle version information includes the latest version number and the corresponding latest upgrade data packet and other information.

[0051] Step 2: After receiving the updated vehicle version information list or the latest version information, the OTA server finds the corresponding quantum key according to the key identifier, decrypts the vehicle version information list or the latest version information, and compares whether the version number of the current software in the vehicle version information list is the latest version number. If the two are inconsistent, the corresponding vehicle needs to be upgraded. Filter out the vehicle IDs that need to be upgraded, send the latest version number to the relevant vehicles, and ask whether they need to be upgraded.

[0052] Step 3: After receiving the new upgrade inquiry, the vehicle determines whether it needs to be upgraded. If it needs to be upgraded, it sends an upgrade request to the vehicle management server. The upgrade request includes vehicle version information, the new version number to be upgraded, and the device-independent quantum random number block of the vehicle, and performs an irreversible function operation on the device-independent quantum random number block and the latest version number to obtain the key X(RAND). The key X(RAND) is a symmetric key, and the key for decryption and encryption is the key X(RAND).

[0053] In the preferred embodiment, let the number represented by the device-independent quantum random number block be a, and the version number be v. Optionally, the calculation method of the N-bit encryption key is as follows: Let t be the first N digits of a, and the N-bit key X(RAND) is expressed as: X(RAND) = a v mod t, where mod is the remainder function, and N is determined by the data length of the upgrade request. Encrypt the upgrade request with the encryption key X(RAND) and then send it to the vehicle management server side.

[0054] Step 4: The vehicle management server performs the same function operation on the device-independent quantum random number block of the corresponding vehicle and the latest version number information to obtain the key X(RAND). After decrypting the upgrade request sent by the vehicle with the key X(RAND), the vehicle management server verifies the upgrade request sent by the vehicle and performs double verification on the vehicle version information and the device-independent quantum random number block.

[0055] The double verification process is as follows: (1) Mainly compare whether the vehicle ID and the current vehicle version number are the same as the content in the previously stored vehicle information list; (2) Compare and verify the device-independent quantum random number block with the device-independent quantum random number blocks adjacent before and after in the random number block list, verify the time stamp, the digital signature of the server, and the hash values of the device-independent quantum random number blocks before and after.

[0056] Let the device-independent quantum random number block corresponding to vehicle ID (n) be RAND(n), the device-independent quantum random number block corresponding to vehicle ID (n - 1) be RAND(n - 1), and the device-independent quantum random number block corresponding to vehicle ID (n + 1) be RAND(n + 1). Verify: (1) The timestamp of RAND(n) is later than that of RAND(n - 1) and earlier than that of RAND(n + 1); (2) The digital signatures of RAND(n) and RAND(n - 1), RAND(n + 1) are the same; (3) The "hash value of the previous device-independent quantum random number block" in RAND(n) is equal to the "hash value of the device-independent quantum random number block" in RAND(n - 1); The "hash value of the previous device-independent quantum random number block" in RAND(n + 1) is equal to the "hash value of the device-independent quantum random number block" in RAND(n). If all three of the above points are satisfied, the verification is successful, and proceed to step 5. If the verification fails, end the process and send a process end message to the vehicle.

[0057] Step 5: The vehicle management server selects a new quantum key QKD3, encrypts the vehicle version information, the version number to which the vehicle is about to be upgraded, and the key X (RAND) through quantum key encryption, and sends them to the OTA server, and sends the key identifier IDQKD3 corresponding to the quantum key to the OTA server, so that the OTA server can find the corresponding shared quantum key according to the key identifier.

[0058] Step 6: After receiving the information in step 5, the OTA server finds the corresponding shared quantum key according to the key identifier, decrypts the information of the vehicle ID, the existing vehicle version number, the version number to which the vehicle is about to be upgraded, and the key X (RAND), and compares the vehicle ID and the existing vehicle version information. After successful comparison, encrypt the data packet to be upgraded with the key X (RAND) as the key and send it to the vehicle.

[0059] Step 7: After receiving the upgrade data packet in step 6, the vehicle decrypts the upgrade data with the key X (RAND) and upgrades the vehicle. After the upgrade is completed, the vehicle feeds back the confirmation information and the latest version number to the vehicle management server. The latest vehicle version information is encrypted with the key X (RAND) and sent to the vehicle management server.

[0060] Step 8: The vehicle management server decrypts the vehicle version information with the key X (RAND), and updates the version number corresponding to the vehicle in the list information according to the fed-back latest version number. And send the latest vehicle version information list to the OTA server in the form of encryption with the quantum key QKD4, and send the quantum key identifier IDQKD4.

[0061] Step 9: The OTA server finds the corresponding quantum key according to the quantum key identifier, decrypts the vehicle version information sent in Step 8 with the quantum key, and the OTA server updates the vehicle information list.

[0062] In a preferred embodiment, the quantum key transmits the ciphertext in a one-time pad manner to ensure the security of data transmission. Each transmitted ciphertext carries the key identifier corresponding to the quantum key, so that the OTA server can find the corresponding shared quantum key according to the key identifier.

[0063] The key source of the quantum key comes from quantum random numbers, which has higher security than traditional random numbers based on technologies such as algorithms and noise sources. Especially device-independent quantum random numbers, which are random numbers based on the intrinsic randomness of quantum mechanics, have unpredictability and are considered to be the random numbers with the highest security. Based on the quantum key distribution technology of quantum mechanics, due to the characteristics of quantum states such as non-clonability, uncertainty, and measurement collapse, the key distribution process is guaranteed not to be effectively eavesdropped. Therefore, using the quantum key distribution technology can securely distribute shared quantum keys for both parties of data transmission, which are used for the encrypted transmission of data between the two parties, no longer relying on asymmetric key encryption, and thus there are no problems of low encryption efficiency and possible cracking brought by the asymmetric encryption algorithm.

[0064] The device-independent quantum random number generator utilizes the unique properties of quantum physics. By detecting the loophole-free Bell inequality, it can verify whether there is a quantum entanglement state without making any assumptions about the device, and the quantum entanglement state can be used as the most basic resource for generating quantum randomness to generate random numbers. The security of device-independent quantum random numbers only depends on the violation of the Bell inequality and does not require the source and working principle of the device used, so it is considered to be the random number with the highest security.

[0065] The device-independent quantum random number server sends newly generated blocks of device-independent quantum random numbers with uniform randomness to the target user. Each random number block contains newly generated device-independent quantum random numbers, and also has a timestamp, the digital signature of the server, and the hash value of the previous random number block, so as to prevent the tampering of the generated data. Legitimate users can obtain the real-time generated random number blocks through the server network and obtain relevant information such as hash values and signatures, and can also verify the previous data. The random number blocks generated by the present invention based on the device-independent quantum random number server network have characteristics such as unpredictability, non-tampering, and verifiability, solving problems such as easy leakage of passwords in the prior art, and this solution has higher reliability and security. In addition, as an absolutely secure symmetric key, the quantum key can use encryption methods such as "one-time pad" or "XOR" when encrypting transmission data, and theoretically has the highest level of security.

[0066] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or a data center that integrates one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD)), etc.

[0067] As described above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A quantum-secure OTA upgrade method, characterized in that, It includes the following steps: Step 1: Share quantum keys between the vehicle management server and the OTA server; Step 2: After the OTA server receives the updated vehicle version information list or the latest version information, it finds the corresponding quantum key according to the key identifier, decrypts the vehicle version information list or the latest version information, and compares whether the version number of the current software in the vehicle version information list is the latest version number. If the two are inconsistent, it sends the latest version number to the vehicle and asks whether an upgrade is required; Step 3: After the vehicle receives the new upgrade query, it determines whether an upgrade is required. If an upgrade is required, it sends an upgrade request to the vehicle management server. The upgrade request includes vehicle version information, the new version number to be upgraded, and the device-independent quantum random number block of the vehicle, and performs an irreversible function operation on the device-independent quantum random number block and the latest version number to obtain the key X(RAND); Step 4: After the vehicle management server decrypts the upgrade request sent by the vehicle using the key X(RAND), the vehicle management server verifies the upgrade request sent by the vehicle and performs double verification on the vehicle version information and the device-independent quantum random number block; Step 5: The vehicle management server selects a new quantum key QKD3, and sends the vehicle version information, the version number that the vehicle is about to upgrade, and the key X(RAND) to the OTA server by means of quantum key encryption, and sends the key identifier IDQKD3 corresponding to the quantum key to the OTA server; Step 6: The OTA server finds the corresponding shared quantum key according to the key identifier IDQKD3, decrypts the information of the vehicle ID, the existing vehicle version number, the version number that the vehicle is about to upgrade, and the key X(RAND), and compares the vehicle ID and the existing vehicle version information. After successful comparison, it encrypts the upgrade data packet with the key X(RAND) as the key and sends it to the vehicle; Step 7: After the vehicle receives the upgrade data packet, it decrypts the upgrade data for upgrading. After the upgrade is completed, the vehicle feeds back the confirmation information and the latest version number to the vehicle management server, and encrypts the latest vehicle version information with the key X(RAND) and sends it to the vehicle management server; Step 8: The vehicle management server decrypts the vehicle version information with the key X(RAND), and updates the version number corresponding to the vehicle in the list information according to the fed-back latest version number, and sends the latest vehicle version information list to the OTA server by means of quantum key QKD4 encryption, and sends the quantum key identifier IDQKD4; Step 9: The OTA server finds the corresponding quantum key according to the quantum key identifier IDQKD4, decrypts the vehicle version information sent in Step 8 with the quantum key, and the OTA server updates the vehicle information list.

2. The quantum-secure OTA upgrade method according to claim 1, wherein, In Step S3, the upgrade request includes vehicle version information, the new version number to be upgraded, and the device-independent quantum random number block of the vehicle, and performs an irreversible function operation on the device-independent quantum random number block and the new version number; Let the number represented by the random number block be a, the version number be v, and the calculation method of the N-bit encryption key be: Let t be the first N digits of a, and the N-bit key X(RAND) = a v mod t, where mod is the remainder function, and N is determined by the data length of the upgrade request.

3. The quantum-secure OTA upgrade method according to claim 1, wherein In step S4, double verification is performed on the vehicle version information and the device-independent quantum random number block: compare whether the vehicle ID and the existing vehicle version number are the same as the content in the previously stored vehicle information list; use the device-independent quantum random number block to compare and verify with the device-independent quantum random number blocks adjacent before and after in the random number block list, and verify the timestamp, the digital signature of the server, and the hash values of the device-independent quantum random number blocks before and after.

4. The quantum-secure OTA upgrade method according to claim 3, wherein it is assumed that The device-independent quantum random number block corresponding to the vehicle ID(n) is RAND(n), the device-independent quantum random number block corresponding to the vehicle ID(n - 1) is RAND(n - 1), and the device-independent quantum random number block corresponding to the vehicle ID(n + 1) is RAND(n + 1). Verify: (1) The timestamp of RAND(n) is later than that of RAND(n - 1) and the timestamp of RAND(n) is earlier than that of RAND(n + 1); (2) The digital signatures of RAND(n) and RAND(n - 1), RAND(n + 1) are the same; (3) The "hash value of the previous device-independent quantum random number block" in RAND(n) is equal to the "hash value of the device-independent quantum random number block" in RAND(n - 1); the "hash value of the previous device-independent quantum random number block" in RAND(n + 1) is equal to the "hash value of the device-independent quantum random number block" in RAND(n). If all of the above three points are satisfied, the verification is successful, and step 5 is performed. If the verification fails, the process ends, and an end-of-process message is sent to the vehicle.

5. The quantum-secure OTA upgrade method according to claim 1, characterized in that In step S1, if the vehicle version information is updated, the vehicle management server sends the vehicle version information list to the OTA server in the form of encryption with the quantum key QKD1. If there is a new upgrade version, the vehicle management server sends the latest vehicle version information to the OTA server in the form of encryption with the quantum key QKD2.

6. The quantum-secure OTA upgrade method according to claim 1, wherein The quantum key is used to transmit the ciphertext in a one-time pad manner.

7. A quantum-secure OTA upgrade system, characterized in that, Used to implement the quantum-secure OTA upgrade method described in any one of claims 1-6, including: a vehicle management server, an OTA server, and a vehicle; The vehicle management server and the OTA server are connected through a quantum network, and both share a quantum key; After receiving the updated vehicle version information list or the latest version information, the OTA server finds the corresponding quantum key according to the key identifier; A device-independent quantum random number generator is set at the vehicle management server, and the device-independent quantum random number server sends the newly generated device-independent quantum random number blocks to the vehicle in the order of vehicle ID; The OTA server stores upgrade data packets of different versions, sends the latest version number to the vehicle that needs to be upgraded, and can send the upgrade data packet to the vehicle that needs to be upgraded for the vehicle to perform the upgrade; The vehicle, as a terminal device, performs an upgrade after receiving the upgrade data packet and transmits the latest vehicle information to the vehicle management server.

Citation Information

Patent Citations

  • Vehicle software upgrading method, vehicle-mounted terminal, vehicle and server

    CN113867748A

  • Upgrade package encryption and decryption method and device

    CN115119208A