Parameter updating method based on secure vehicle-mounted communication and related device
By using an electrical testing device and cloud-based collaborative generation of encryption keys, the key and freshness value of the vehicle's CAN bus are automatically updated, solving the problem of low key update efficiency in existing technologies, improving the speed and accuracy of key updates, and ensuring communication reliability.
Patent Information
- Application Number
- CN202310706657.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-14
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2043-06-14
AI Technical Summary
In existing technologies, the key update process for vehicle CAN bus is complex and relies on manual experience, resulting in low efficiency.
The vehicle identification number of the target vehicle and the initial key of the target component are obtained by the electronic inspection device. An encryption key is generated and distributed in the cloud. The target component decrypts the key, automatically updates the key, and synchronizes the freshness value.
It automates key updates, reduces manual intervention, improves update speed and accuracy, and ensures communication reliability.
Smart Images

Figure CN116647337B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of data updating, and particularly relates to a parameter updating method based on secure vehicle communication and related equipment. BACKGROUND
[0002] Most of the existing vehicle CAN (Controller Area Network) buses are equipped with SecOC (Security Onboard Communication) functions. The SecOC function relies on a key and a freshness value (FV) to ensure the reliability of messages communicated between each component in the vehicle and prevent message replay.
[0003] When a vehicle needs to be repaired and replaced, the key and the freshness value of the replaced component in the vehicle need to be updated, so that the key of the component is synchronized with the key of the vehicle, and the freshness value between the component and each opponent part is synchronized.
[0004] In related technologies, the key is usually updated manually in an artificial manner. However, the key update process is complicated, and the artificial updating method completely depends on the experience of the maintenance personnel, which is time-consuming, labor-intensive, and inefficient. SUMMARY
[0005] The embodiments of the application provide a parameter updating method based on secure vehicle communication and related equipment, which can solve the problem that the key is manually updated in an artificial manner, the key update process is complicated, the artificial updating method completely depends on the experience of the maintenance personnel, and is time-consuming, labor-intensive, and inefficient.
[0006] A first aspect of the embodiments of the application provides a parameter updating method based on secure vehicle communication. The method is applied to a target component of a target vehicle, and the parameters include a key of the target component. The method comprises the following steps.
[0007] A first encrypted key sent by an electrical detector is acquired. The first encrypted key is generated by encrypting an original key of the target vehicle, and the encryption key of the original key of the target vehicle is determined according to the type of the target component.
[0008] The first encrypted key is decrypted by using an initial key of the target component to determine the original key of the target vehicle.
[0009] The key of the target component is updated from the initial key to the original key of the target vehicle.
[0010] The second aspect of the embodiment of the application provides another parameter updating method based on secure vehicle-mounted communication, the method is applied to an electric detection instrument, the parameter includes a key of a target component of a target vehicle, and the method comprises the following steps:
[0011] obtaining a vehicle identification code of the target vehicle and an initial key of the target component;
[0012] sending a vehicle key query request to a cloud, wherein the vehicle key query request comprises the vehicle identification code of the target vehicle;
[0013] obtaining a first encryption key issued by the cloud, wherein the first encryption key is generated by encrypting an original key of the target vehicle, and the encryption key of the original key of the target vehicle is determined according to a type of the target component;
[0014] sending the first encryption key to the target component, so that the target component decrypts the first encryption key by using the initial key of the target component, to determine the original key of the target vehicle, and updates the key of the target component from the initial key to the original key of the target vehicle.
[0015] The third aspect of the embodiment of the application provides still another parameter updating method based on secure vehicle-mounted communication, the method is applied to a cloud, the parameter includes a key of a target component of a target vehicle, and the method comprises the following steps:
[0016] receiving a vehicle key query request sent by an electric detection instrument;
[0017] encrypting an original key of the target vehicle by using an encryption key to generate a first encryption key, wherein the encryption key is determined according to a type of the target component;
[0018] issuing the first encryption key to the electric detection instrument, so that the electric detection instrument sends the first encryption key to the target component.
[0019] The fourth aspect of the embodiment of the application provides a parameter updating system based on secure vehicle-mounted communication, the system comprises an electric detection instrument, a cloud and a target component of a target vehicle, and the system comprises the following steps:
[0020] The electric detection instrument is configured to obtain a vehicle identification code of the target vehicle and an initial key of the target component, send a vehicle key query request to the cloud, obtain a first encryption key issued by the cloud, and send the first encryption key to the target component, wherein the vehicle key query request comprises the vehicle identification code of the target vehicle;
[0021] The cloud receives a vehicle key query request sent by the electric detection instrument, encrypts an original key of the target vehicle by using an encryption key, generates a first encrypted key, and sends the first encrypted key to the electric detection instrument, where the encryption key is determined according to the type of the target component.
[0022] The target component obtains the first encrypted key sent by the electric detection instrument, decrypts the first encrypted key by using an initial key of the target component, to determine the original key of the target vehicle, and updates the key of the target component from the initial key to the original key of the target vehicle.
[0023] A fifth aspect of the embodiment of the application provides a parameter updating device based on secure vehicle-mounted communication, which is applied to a target component of a target vehicle, and the parameter includes a key of the target component.
[0024] The first obtaining module is configured to obtain a first encrypted key sent by the electric detection instrument, where the first encrypted key is generated by encrypting an original key of the target vehicle, and the encryption key of the original key of the target vehicle is determined according to the type of the target component.
[0025] The first decryption module is configured to decrypt the first encrypted key by using an initial key of the target component, to determine the original key of the target vehicle.
[0026] The first updating module is configured to update the key of the target component from the initial key to the original key of the target vehicle.
[0027] A sixth aspect of the embodiment of the application provides another parameter updating device based on secure vehicle-mounted communication, which is applied to an electric detection instrument, and the parameter includes a key of a target component.
[0028] The second obtaining module is configured to obtain a vehicle identification code of the target vehicle and an initial key of the target component.
[0029] The first sending module is configured to send a vehicle key query request to the cloud, where the vehicle key query request includes the vehicle identification code of the target vehicle.
[0030] The third obtaining module is configured to obtain a first encrypted key sent by the cloud, where the first encrypted key is generated by encrypting an original key of the target vehicle, and the encryption key of the original key of the target vehicle is determined according to the type of the target component.
[0031] The second sending module is configured to send the first encrypted key to the target component, so that the target component decrypts the first encrypted key by using an initial key of the target component, to determine the original key of the target vehicle, and updates the key of the target component from the initial key to the original key of the target vehicle.
[0032] A seventh aspect of the embodiments of the present application provides another parameter updating device based on secure vehicle communication, which is applied to a cloud, the parameter comprises a key of a target component, and the device comprises:
[0033] A receiving module is configured to receive a vehicle key query request sent by the electric detector;
[0034] An encryption module is configured to encrypt an original key of the target vehicle by using an encryption key to generate a first encryption key, wherein the encryption key is determined according to the type of the target component;
[0035] A third sending module is configured to send the first encryption key to the electric detector, so that the electric detector sends the first encryption key to the target component.
[0036] An eighth aspect of the embodiments of the present application provides a terminal device, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the parameter updating method based on secure vehicle communication of the first aspect, the second aspect or the third aspect when executing the computer program.
[0037] A ninth aspect of the embodiments of the present application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the parameter updating method based on secure vehicle communication of the first aspect, the second aspect or the third aspect.
[0038] A tenth aspect of the embodiments of the present application provides a computer program product, which, when running on a terminal device, causes the terminal device to execute the parameter updating method based on secure vehicle communication of the first aspect, the second aspect or the third aspect.
[0039] Compared with the prior art, the embodiments of the present application have the beneficial effects that the present application discloses a parameter updating method based on secure vehicle communication and related devices, wherein the electric detector first acquires a vehicle identification code of a target vehicle and an initial key of a target component, then the cloud encrypts an original key of the target vehicle to generate a first encryption key and sends the first encryption key to the electric detector, then the electric detector sends the first encryption key to the target component, finally the target component decrypts the first encryption key by using the initial key, determines the original key of the target vehicle, and updates the key of the target component from the initial key to the original key of the target vehicle, wherein the encryption key of the original key of the target vehicle is determined according to the type of the target component. Thus, by automatically selecting the corresponding key encryption and decryption strategy according to the type of the target component, all components in the target vehicle are automatically synchronized to the first encryption key, manual intervention is reduced, and the speed and accuracy of key updating are improved. BRIEF DESCRIPTION OF DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the accompanying drawings in the following description only constitute some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.
[0041] Figure 1 is a flow diagram of a parameter updating method based on secure vehicle communication provided by an embodiment of the present application;
[0042] Figure 2 is a flow diagram of a parameter updating method based on secure vehicle communication provided by an embodiment of the present application;
[0043] Figure 3 is a flow diagram of a parameter updating method based on secure vehicle communication provided by an embodiment of the present application;
[0044] Figure 4 is a data interaction diagram between devices in a parameter updating system based on secure vehicle communication provided by an embodiment of the present application;
[0045] Figure 5 is a structural diagram of a parameter updating apparatus based on secure vehicle communication provided by an embodiment of the present application;
[0046] Figure 6 is a structural diagram of a parameter updating apparatus based on secure vehicle communication provided by an embodiment of the present application;
[0047] Figure 7 is a structural diagram of a parameter updating apparatus based on secure vehicle communication provided by an embodiment of the present application;
[0048] Figure 8 is a structural diagram of a terminal device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0049] In the following description, specific details are set forth in order to provide a thorough understanding of the embodiments of the present application. However, persons skilled in the art will understand that the present application can be practiced without these specific details. In other instances, well-known structures, devices, circuits and methods have not been described in detail in order to avoid obscuring the present application.
[0050] It should be understood that the word “comprise” or variations such as “comprises” or “comprising”, when used in this specification and in the accompanying claims, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0051] It should also be understood that the term “and / or” when used in this specification and in the following claims is to be interpreted as “one or the other or both” and / or “any combination of the items in the list.
[0052] As used in this specification and in the claims, the terms “if” and “when” can be interpreted to mean “upon” or “in response to a determination” or “in response to a detection” depending on the context. Similarly, the phrase “if it is determined” or “if [a described condition or event] is detected” can be interpreted to mean “upon a determination” or “in response to a determination” or “upon detecting [a described condition or event]” or “in response to detecting [a described condition or event]”, depending on the context.
[0053] In addition, in the description of the application in the specification and the appended claims, the terms “first”, “second”, “third”, etc. are used only to distinguish descriptions, and cannot be understood as indicating or implying relative importance.
[0054] Reference in the specification to “one embodiment” or “some embodiments” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearances of the phrase “in one embodiment” or “in some embodiments” in various places in the specification are not necessarily all referring to the same embodiment, although it can. The terms “comprise”, “comprises”, “comprising”, “include”, “includes”, “including” and “contain”, “contains”, “containing” and their variants, mean “including but not limited to”, unless otherwise expressly specified and are not intended to exclude other integers or steps of the methods, materials or components described.
[0055] It should be understood that the size of the serial number of each step in the embodiments does not mean the order of execution, and the execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the application.
[0056] In the related art, manual key update is usually used in an artificial way, but the key update process is numerous, and the artificial update method completely depends on the experience of maintenance personnel, which is time-consuming and labor-intensive, and the efficiency is very low.
[0057] Therefore, the embodiment of the present application provides a parameter updating method based on secure vehicle-mounted communication and related equipment, which automatically selects a corresponding key encryption and decryption strategy according to the type of the target component, automatically synchronizes all components in the target vehicle to the first encryption key, reduces manual intervention, and improves the speed and accuracy of key updating.
[0058] In order to illustrate the technical solutions of the present application, the following will be illustrated by specific embodiments.
[0059] Referring to Figure 1 , a parameter updating method based on secure vehicle-mounted communication provided by the embodiment of the present application is shown, which is applied to a target component of a target vehicle.
[0060] The target vehicle can refer to large cars, small cars, special cars, etc. For example, according to the vehicle type, the car can be a sedan type, an off-road type, a multi-purpose (MPV) type or other types. The target component refers to the component that needs to be repaired or replaced in the target vehicle.
[0061] It should be noted that the parameter includes the key of the target component. Since all components in a vehicle use one key when implementing the SecOC function, and the target component itself initially has a key, the key of the target component is different from the key of the target vehicle before the key of the target component is updated. Therefore, when repairing or replacing the component, the key of the target component needs to be updated to synchronize the key of the target component with the key of the target vehicle.
[0062] As Figure 1 shown, the parameter updating method can include the following steps:
[0063] Step 101, obtaining the first encryption key sent by the electrical inspection instrument.
[0064] It should be noted that when the components in the vehicle communicate by implementing the SecOC function, the sending component will encrypt the message to be sent using the key, and then send the message in clear text and the encrypted message to the receiving component. The receiving component will encrypt the message in clear text using the same key and compare whether they are the same. If they are the same, it is considered that the received message is reliable. Therefore, the vehicle key is very important and cannot be leaked. When updating the key, the new key needs to be encrypted by the previous key. Therefore, the first encryption key is generated by encrypting the original key of the target vehicle, and the encryption key of the original key of the target vehicle is determined according to the type of the target component.
[0065] Further, the first encryption key is generated by encrypting the original key of the target vehicle using the initial key of the target component. That is, the initial key of the target component is the encryption key of the original key of the target vehicle.
[0066] As a possible implementation of the embodiment of the present application, when the type of the target component includes a new component, for example, when a component on the target vehicle is damaged and needs to be replaced with a new one, the initial key of the target component includes a pre-manufactured key of the target component, wherein the pre-manufactured key is written into the target component on the production line.
[0067] As another possible implementation of the embodiment of the present application, when the type of the target component includes an old component, for example, when the components of the target vehicle need to be cross-debugged to locate a problem, the initial key of the target component includes the key of the vehicle where the target component originally belongs.
[0068] In the embodiment of the present application, the first encryption key can be encrypted by a cloud, which can be a public key infrastructure (PKI). Specifically, the electrical detector establishes communication with the target vehicle, obtains the vehicle identification number (VIN) of the target vehicle and sends it to the cloud for query, thereby obtaining the original key of the target vehicle. The cloud then selects to use the pre-manufactured key of the target component or the key of the vehicle where the target component originally belongs to encrypt the original key of the target vehicle to generate the first encryption key, wherein the key of the vehicle where the target component originally belongs can be obtained by querying the vehicle identification number of the vehicle where the target component originally belongs sent by the electrical detector. The cloud then issues the first check file to the electrical detector, wherein the first check file includes the first encryption key and the first check content, and the first check content is used to verify the original key of the target vehicle. Finally, the target component obtains the first check file written by the electrical detector.
[0069] Step 102, decrypting the first encryption key using the initial key of the target component to determine the original key of the target vehicle.
[0070] Specifically, the target component first reads the initial key, i.e., the pre-manufactured key of the target component from the security chip corresponding to the target component, or the key of the vehicle where the target component originally belongs stored internally. Then, the initial key is used to decrypt the first check file, and the first check content is used to verify the original key of the target vehicle. If the verification is successful, it is considered that the original key of the target vehicle received by the target component is accurate and reliable.
[0071] Step 103, updating the key of the target component from the initial key to the original key of the target vehicle.
[0072] Specifically, the key update of the target component is completed by writing the original key of the target vehicle into the security chip slot corresponding to the target component.
[0073] It should be noted that the target component can be installed in the target vehicle first, and then the key update of the target component is performed. The original key of the target vehicle can also be written into the security chip slot corresponding to the component to be updated first, and then the target component is installed in the target vehicle after the key update of the target vehicle is completed.
[0074] In the embodiment of the present application, the parameters of the SecOC function also include the freshness value of the target component. When the components in the vehicle normally communicate, the freshness value is generally simply monotonically increasing, and is increased by one each time a message is sent on the CAN bus, to prevent message replay. For example, the freshness values of the sending component and the receiving component are both 1, and the freshness value is increased by one each time during normal communication. The sending component first encrypts the message using the key, and then attaches the freshness value, that is, sends the freshness value 2 to the receiving component. The receiving component increases its own freshness value by one after determining that the message is correct through the key. It is determined that the received freshness value and the increased freshness value are both 2, and it is considered that the current message is reliable. If the received freshness value of the receiving component is not the same as the increased freshness value, it is considered that the message is problematic.
[0075] Under the above premise, when the component in the vehicle needs to be repaired or replaced, the freshness value of the target component needs to be updated to be synchronized with the freshness value of the opponent component. The opponent component refers to the component in the target vehicle that has data communication with the target component, and therefore, the target component can be read by the electrical detector.
[0076] The freshness value of the message sent by the opponent component is obtained, and the freshness value of the target component is updated to the freshness value of the opponent component, to complete the synchronization of the freshness values.
[0077] Further, since power needs to be turned off when the component is replaced, the component to be replaced may be powered off in advance, and the opponent component may still be sending messages. This will cause the freshness values of the target component and the opponent component to be unsynchronized when the target component is replaced in the target vehicle. Therefore, the freshness value of the target component can be increased by a large number at this time. For example, the freshness value is monotonically increased by one when the message is sent normally. When the target component obtains the freshness value of the message sent by the opponent component sent by the electrical detector, the freshness value can be increased by five. After the opponent component receives the freshness value corresponding to the message sent by the target component, the freshness value of the opponent component is updated when the freshness value is greater than the current stored freshness value of the opponent component, to complete the synchronization of the freshness values. That is, in a possible implementation manner of the embodiment of the present application, after the step 103, the method can further include:
[0078] obtaining an initial freshness value between the target component and the adversary device sent by the electrical detector, wherein the initial freshness value is a freshness value used by the target component when sending a message to the adversary device;
[0079] increasing the initial freshness value by a preset value to generate a target freshness value;
[0080] updating the freshness value of the target component to the target freshness value;
[0081] when the target vehicle is powered on, sending a freshness value synchronization message to the adversary device, and attaching the target freshness value in the freshness value synchronization message, so that the adversary device updates the freshness value of the adversary device from the initial freshness value to the target freshness value when determining that the target freshness value is greater than the initial freshness value, wherein the freshness value synchronization message is encrypted by using the original key of the target vehicle.
[0082] It should be noted that the preset value needs to be greater than at least the value of the monotonically increasing freshness value during normal communication.
[0083] Further, since the freshness value may not be synchronized, for example, the freshness value of the adversary device fails to be read, the component with the error freshness value cannot be located, etc., at this time, the freshness value can be synchronized by clearing the freshness value of all components in the target vehicle. The freshness value can be cleared by updating the key of all components in the target vehicle, that is, in another possible implementation manner of the embodiment of the present application, after the step 103, the method further includes:
[0084] obtaining a second encryption key sent by the electrical detector, wherein the second encryption key is generated by encrypting a new key of the target vehicle by using the original key of the target vehicle;
[0085] decrypting the second encryption key by using the original key of the target vehicle to determine the new key of the target vehicle;
[0086] updating the key of the target component from the original key of the target vehicle to the new key of the target vehicle, so that the freshness value of the target component is cleared when the keys of all components in the target vehicle are updated from the original key of the target vehicle to the new key of the target vehicle.
[0087] It should be noted that the new key of the target vehicle can be generated by the cloud.
[0088] Specifically, the cloud encrypts the newly generated new key of the target vehicle using the original key of the target vehicle to obtain a second encryption key, and then distributes a second verification file to the electric detection instrument, where the second verification file includes the second encryption key and second verification content, and the second verification content is used to verify the new key of the target vehicle. The target component and the adversary obtain the second verification file sent by the electric detection instrument, decrypt the second verification file using the original key of the target vehicle, and then verify the new key of the target vehicle using the second verification file. If the verification is successful, it is considered that the received new key of the target vehicle is accurate and reliable. Finally, the target component and the adversary write the new key of the target vehicle into the corresponding secure chip slot, so that the keys of all components in the target vehicle are updated, thereby completing the freshness value clearing of all components.
[0089] The parameter updating method based on secure vehicle communication disclosed in the above embodiments of the application automatically selects a corresponding key encryption and decryption strategy according to the type of the target component, automatically synchronizes all components in the target vehicle to the first encryption key, reduces manual intervention, and improves the speed and accuracy of key updating. The above embodiments of the application further provide a target component freshness value updating scheme, and consider various possible scenarios to ensure the normal use of the SecOC function in the target vehicle and improve the reliability of communication. The target component freshness value updating scheme can be automatically implemented, thereby improving the speed and accuracy of freshness value updating.
[0090] Referring to Figure 2 , a parameter updating method based on secure vehicle communication is shown. The above method is applied to an electric detection instrument, and the parameters include the key of the target component of the target vehicle. As Figure 2 indicated, the parameter updating method can include the following steps:
[0091] Step 201, obtaining a vehicle identification code of a target vehicle, and obtaining an initial key of a target component.
[0092] In the embodiments of the application, the electric detection instrument establishes communication with the target vehicle to obtain the vehicle identification code of the target vehicle.
[0093] As a possible implementation manner of the embodiments of the application, when the type of the target component is a new component, for example, when a certain component of the target vehicle is damaged and needs to be replaced with a new one, the initial key of the target component is a pre-prepared key of the target component, where the pre-prepared key is written into the target component on the production line.
[0094] As another possible implementation manner of the embodiments of the application, when the type of the target component is an old component, for example, when the components of the target vehicle need to be cross-debugged and positioned, the initial key of the target component is the key of the vehicle where the target component is originally located.
[0095] Further, the electric detector can obtain the vehicle identification code of the vehicle where the target component was originally located, and send the vehicle identification code to the cloud, so that the cloud obtains the key of the vehicle where the target component was originally located according to the vehicle identification code of the vehicle where the target component was originally located. In a possible implementation manner of the embodiment of the present application, the above-mentioned obtaining of the initial key of the target component can include:
[0096] obtaining the vehicle identification code of the vehicle where the target component was originally located, and sending the vehicle identification code to the cloud to obtain the key of the vehicle where the target component was originally located from the cloud as the initial key.
[0097] In step 202, a vehicle key query request is sent to the cloud.
[0098] In the vehicle key query request, the vehicle identification code of the target vehicle is included.
[0099] It should be noted that the cloud can query the original key of the target vehicle through the vehicle identification code of the target vehicle.
[0100] In step 203, a first encryption key issued by the cloud is obtained.
[0101] The first encryption key is generated by encrypting the original key of the target vehicle, and the encryption key of the original key of the target vehicle is determined according to the type of the target component.
[0102] It should be noted that the cloud can select to use the pre-manufactured key of the target component or the key of the vehicle where the target component was originally located to encrypt the original key of the target vehicle to generate the first encryption key, in combination with the type of the target component.
[0103] In step 204, the first encryption key is sent to the target component, so that the target component decrypts the first encryption key by using the initial key of the target component, to determine the original key of the target vehicle, and updates the key of the target component from the initial key to the original key of the target vehicle.
[0104] It should be noted that the electric detector first obtains the first verification file issued by the cloud, wherein the first verification file includes the first encryption key and first verification content, and the first verification content is used to verify the original key of the target vehicle. Further, the electric detector writes the first verification file including the first encryption key to the target component, so that the target component decrypts the first verification file by using the initial key, and verifies the original key of the target vehicle by using the first verification content. If the verification is successful, it is considered that the original key of the target vehicle received by the target component is accurate and reliable, and the key update is performed accordingly.
[0105] In the embodiments of the present application, the parameters of the SecOC function further include a freshness value of the target component. In one possible implementation manner of the embodiments of the present application, after the step 204, the method further includes:
[0106] reading an initial freshness value between the target component and a peer component, wherein the peer component refers to a component in the target vehicle that has data communication with the target component, and the initial freshness value refers to a freshness value used by the target component when sending a message to the peer component;
[0107] sending the initial freshness value to the target component, so that the target component increases the initial freshness value by a preset value to generate a target freshness value, updates the freshness value of the target component to the target freshness value, and when the target vehicle is powered on, sends a freshness value synchronization message to the peer component, and the target freshness value is attached to the freshness value synchronization message, so that when the peer component determines that the target freshness value is greater than the initial freshness value, the peer component updates the freshness value of the peer component from the initial freshness value to the target freshness value, wherein the freshness value synchronization message is encrypted by using the original key of the target vehicle.
[0108] In another possible implementation manner of the embodiments of the present application, after the step 204, the method further includes:
[0109] obtaining a second encryption key, wherein the second encryption key is generated by encrypting a pre-generated new key of the target vehicle by using the original key of the target vehicle;
[0110] sending the second encryption key to the target component, so that the target component decrypts the second encryption key by using the original key of the target vehicle to determine the new key of the target vehicle, and updates the key of the target component from the original key of the target vehicle to the new key of the target vehicle, and when the keys of all components in the target vehicle are updated from the original key of the target vehicle to the new key of the target vehicle, the freshness value of the target component is cleared.
[0111] The specific implementation process and principle of the freshness value updating can be referred to the detailed description of the above embodiments, which will not be described here.
[0112] Some other specific implementation processes and principles in the embodiments of the present application can be referred to the detailed description of the foregoing embodiments, which will not be described here.
[0113] The parameter updating method based on secure vehicle-mounted communication disclosed in the above embodiments of the application automatically selects a corresponding key encryption and decryption strategy according to the type of the target component, automatically synchronizes all components in the target vehicle to the first encryption key, reduces manual intervention, and improves the speed and accuracy of key updating. The above embodiments of the application further provide a target component freshness value updating scheme, and consider various possible scenarios to ensure the normal use of the SecOC function in the subsequent target vehicle, improve the reliability of communication, and the target component freshness value updating scheme can be automatically implemented to improve the speed and accuracy of freshness value updating.
[0114] Referring to Figure 3 , a parameter updating method based on secure vehicle-mounted communication is shown. The above method is applied to the cloud, and the parameters include the key of the target component of the target vehicle. As Figure 3 indicated, the parameter updating method can include the following steps:
[0115] Step 301, receiving a vehicle key query request sent by the electric detector.
[0116] Step 302, encrypting the original key of the target vehicle using the encryption key to generate the first encryption key.
[0117] The encryption key is determined according to the type of the target component.
[0118] In the embodiments of the application, when the type of the target component includes a new component, the encryption key includes the pre-prepared key of the target component; when the type of the target component includes an old component, the encryption key includes the key of the vehicle where the target component originally belongs.
[0119] Step 303, issuing the first encryption key to the electric detector, so that the electric detector sends the first encryption key to the target component.
[0120] Some other specific implementation processes and principles in the embodiments of the application can be referred to the detailed description of the foregoing embodiments, which will not be described here.
[0121] The parameter updating method based on secure vehicle-mounted communication disclosed in the above embodiments of the application automatically selects a corresponding key encryption and decryption strategy according to the type of the target component, automatically synchronizes all components in the target vehicle to the first encryption key, reduces manual intervention, and improves the speed and accuracy of key updating. The above embodiments of the application further provide a target component freshness value updating scheme, and consider various possible scenarios to ensure the normal use of the SecOC function in the subsequent target vehicle, improve the reliability of communication, and the target component freshness value updating scheme can be automatically implemented to improve the speed and accuracy of freshness value updating.
[0122] Referring toFigure 4 Fig. 3 shows a signaling interaction diagram among the electric detector, the cloud and the target component of a parameter updating system based on secure vehicle communication according to an embodiment of the application. As shown in Fig. 3, the parameter updating system can be used to perform the following steps: Figure 4
[0123] Step 401: The electric detector acquires the vehicle identification code of the target vehicle and acquires the initial key of the target component.
[0124] Step 402: The electric detector sends a vehicle key query request to the cloud.
[0125] The vehicle key query request includes the vehicle identification code of the target vehicle.
[0126] Step 403: The cloud encrypts the original key of the target vehicle using an encryption key to generate a first encrypted key.
[0127] The encryption key is determined according to the type of the target component.
[0128] Step 404: The cloud sends the first encrypted key to the electric detector.
[0129] Step 405: The electric detector sends the first encrypted key to the target component.
[0130] Step 406: The target component decrypts the first encrypted key using the initial key of the target component to determine the original key of the target vehicle.
[0131] Step 407: The target component updates the key of the target component from the initial key to the original key of the target vehicle.
[0132] Other specific contents of the fourth embodiment of the application can be referred to the related contents of the foregoing embodiments, which will not be repeated here.
[0133] The parameter updating system based on secure vehicle communication disclosed in the foregoing embodiments of the application automatically selects the corresponding key encryption and decryption strategy according to the type of the target component, automatically synchronizes all components in the target vehicle to the first encrypted key, reduces manual intervention, and improves the speed and accuracy of key updating.
[0134] Fig. 4 shows a structure schematic diagram of a parameter updating device based on secure vehicle communication according to an embodiment of the application. The device is applied to the key of the target component. For the convenience of description, only the parts related to the embodiments of the application are shown. Figure 5 The parameter updating device can specifically include the following modules:
[0135]
[0136] The first obtaining module 501 is configured to obtain the first encryption key sent by the electrical inspection instrument.
[0137] The first encryption key is generated by encrypting an original key of the target vehicle, and the encryption key of the original key of the target vehicle is determined according to the type of the target component.
[0138] The first decryption module 502 is configured to decrypt the first encryption key by using the initial key of the target component to determine the original key of the target vehicle.
[0139] The first updating module 503 is configured to update the key of the target component from the initial key to the original key of the target vehicle.
[0140] The parameter updating device disclosed in the above embodiments of the present application automatically selects the corresponding key encryption and decryption strategy according to the type of the target component, and automatically synchronizes all components in the target vehicle to the first encryption key, thereby reducing manual intervention and improving the speed and accuracy of key updating.
[0141] In a possible implementation manner of the fifth embodiment of the present application, the parameter further includes a freshness value of the target component, and the parameter updating device can further include the following modules for updating the key of the target component from the initial key to the original key of the target vehicle:
[0142] The fourth obtaining module is configured to obtain an initial freshness value between the target component and the opponent component sent by the electrical inspection instrument.
[0143] The opponent component refers to a component in the target vehicle that has data communication with the target component, and the initial freshness value refers to a freshness value used when the target component sends a message to the opponent component.
[0144] The first generating module is configured to increase the initial freshness value by a preset value to generate a target freshness value.
[0145] The second updating module is configured to update the freshness value of the target component to the target freshness value.
[0146] The fourth sending module is configured to send a freshness value synchronization message to the opponent component when the target vehicle is powered on, and the target freshness value is attached to the freshness value synchronization message, so that the opponent component updates the freshness value of the opponent component from the initial freshness value to the target freshness value when it is determined that the target freshness value is greater than the initial freshness value.
[0147] The freshness value synchronization message is encrypted by using the original key of the target vehicle.
[0148] In a possible implementation of the fifth embodiment of the present application, the parameters further include a freshness value of the target component, and the parameter updating apparatus can further include the following module: a module configured to update the key of the target component from the initial key to the original key of the target vehicle, and then update the key of the target component from the original key of the target vehicle to the new key of the target vehicle.
[0149] The fifth obtaining module is configured to obtain the second encrypted key sent by the electrical inspection instrument.
[0150] The second encrypted key is generated by encrypting the pre-generated new key of the target vehicle using the original key of the target vehicle.
[0151] The first decrypting module is configured to decrypt the second encrypted key using the original key of the target vehicle to determine the new key of the target vehicle.
[0152] The third updating module is configured to update the key of the target component from the original key of the target vehicle to the new key of the target vehicle, and clear the freshness value of the target component when the keys of all components in the target vehicle are updated from the original key of the target vehicle to the new key of the target vehicle.
[0153] In a possible implementation of the fifth embodiment of the present application, when the type of the target component is a new component, the initial key includes a pre-prepared key of the target component; and when the type of the target component is an old component, the initial key includes a key of a vehicle in which the target component is originally located.
[0154] The parameter updating apparatus disclosed in the above embodiments of the present application further provides a target component freshness value updating scheme, considers various possible scenarios, ensures normal use of the SecOC function in the subsequent target vehicle, improves the reliability of communication, and the target component freshness value updating scheme can be automatically implemented, thereby improving the speed and accuracy of freshness value updating.
[0155] Referring to Figure 6 , a structure schematic diagram of a parameter updating apparatus based on secure vehicle-mounted communication is shown, which is applied to an electrical inspection instrument, and only parts related to the embodiments of the present application are shown for ease of description.
[0156] The parameter updating apparatus can include the following modules:
[0157] The second obtaining module 601 is configured to obtain a vehicle identification code of the target vehicle and an initial key of the target component.
[0158] The first sending module 602 is configured to send a vehicle key query request to the cloud.
[0159] The vehicle key query request includes the vehicle identification code of the target vehicle.
[0160] The third obtaining module 603 is configured to obtain a first encryption key issued by the cloud.
[0161] The first encryption key is generated by encrypting an original key of the target vehicle, and the encryption key of the original key of the target vehicle is determined according to the type of the target component.
[0162] The second sending module 604 is configured to send the first encryption key to the target component, so that the target component decrypts the first encryption key by using an initial key of the target component, to determine the original key of the target vehicle, and update the key of the target component from the initial key to the original key of the target vehicle.
[0163] The parameter updating device disclosed in the above embodiments of the present application automatically selects a corresponding key encryption and decryption strategy according to the type of the target component, automatically synchronizes all components in the target vehicle to the first encryption key, reduces manual intervention, and improves the speed and accuracy of key updating.
[0164] In a possible implementation manner of the sixth embodiment of the present application, the parameters further include a freshness value of the target component, and the parameter updating device can further include the following modules after sending the first encryption key to the target component:
[0165] The reading module is configured to read an initial freshness value between the target component and a counterpart.
[0166] The counterpart refers to a component in the target vehicle that has data communication with the target component, and the initial freshness value refers to a freshness value used by the target component when sending a message to the counterpart.
[0167] The fifth sending module is configured to send the initial freshness value to the target component, so that the target component increases the initial freshness value by a preset value to generate a target freshness value, updates the freshness value of the target component to the target freshness value, and when the target vehicle is powered on, sends a freshness value synchronization message to the counterpart, and the target freshness value is attached to the freshness value synchronization message, so that when the target freshness value is greater than the initial freshness value, the freshness value of the counterpart is updated from the initial freshness value to the target freshness value.
[0168] The freshness value synchronization message is encrypted by using the original key of the target vehicle.
[0169] In a possible implementation manner of the sixth embodiment of the present application, the parameters further include a freshness value of the target component, and the parameter updating device can further include the following modules after sending the first encryption key to the target component:
[0170] The sixth obtaining module is configured to obtain a second encryption key, wherein the second encryption key is generated by encrypting a pre-generated new key of the target vehicle using an original key of the target vehicle.
[0171] The sixth sending module is configured to send the second encryption key to the target component, so that the target component decrypts the second encryption key using the original key of the target vehicle to determine the new key of the target vehicle, and updates the key of the target component from the original key of the target vehicle to the new key of the target vehicle, so as to clear the freshness value of the target component when the keys of all components in the target vehicle are updated from the original key of the target vehicle to the new key of the target vehicle.
[0172] In a possible implementation of the sixth embodiment of the present application, the type of the target component is an old component, and the second obtaining module 601 can specifically include the following sub-modules:
[0173] The obtaining sub-module is configured to obtain a vehicle identification code of a vehicle in which the target component was originally located, and send the vehicle identification code to the cloud to obtain a key of the vehicle in which the target component was originally located from the cloud as an initial key.
[0174] The parameter updating device disclosed in the above embodiments of the present application further provides a target component freshness value updating scheme, and considers various possible scenarios, thereby ensuring the normal use of the SecOC function in the subsequent target vehicle, improving the reliability of communication, and automatically implementing the target component freshness value updating scheme, thereby improving the speed and accuracy of freshness value updating.
[0175] The parameter updating device provided by the embodiments of the present application can be applied in the foregoing method embodiments, and details are described in the foregoing method embodiments, which will not be described here.
[0176] Referring to Figure 7 , a structure schematic diagram of a parameter updating device based on secure vehicle communication is shown, which is applied to the cloud. For ease of illustration, only the parts related to the embodiments of the present application are shown.
[0177] The parameter updating device can specifically include the following modules:
[0178] The receiving module 701 is configured to receive a vehicle key query request sent by the electric detector.
[0179] The encryption module 702 is configured to encrypt the original key of the target vehicle using an encryption key to generate a first encryption key, wherein the encryption key is determined according to the type of the target component.
[0180] The third sending module 703 is configured to send the first encryption key to the electric detector, so that the electric detector sends the first encryption key to the target component.
[0181] In one possible implementation of Embodiment Seven of this application, when the target component type includes a new component, the initial key includes a pre-made key for the target component. When the target component type includes an old component, the initial key includes the key of the vehicle where the target component was originally located.
[0182] The parameter update system based on secure vehicle communication disclosed in the above embodiments of this application automatically selects the corresponding key encryption strategy according to the type of the target component, and then sends the key to the target component for corresponding decryption operation. It automatically synchronizes all components in the target vehicle with the first encryption key, reduces manual intervention, and improves the speed and accuracy of key updates.
[0183] Figure 8 This is a schematic diagram of the terminal device provided in Embodiment 8 of this application. Figure 8 As shown, the terminal device 800 of this embodiment includes: at least one processor 810 ( Figure 8 (Only one is shown) a processor, a memory 820, and a computer program 821 stored in the memory 820 and capable of running on at least one processor 810. When the processor 810 executes the computer program 821, it implements the steps in the above-described parameter update method embodiment.
[0184] Terminal device 800 can be a computing device such as a desktop computer, laptop, handheld computer, or cloud server. This terminal device may include, but is not limited to, a processor 810 and a memory 820. Those skilled in the art will understand that... Figure 8 This is merely an example of terminal device 800 and does not constitute a limitation on terminal device 800. It may include more or fewer components than shown in the figure, or combine certain components, or different components, such as input / output devices, network access devices, etc.
[0185] The processor 810 may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0186] The memory 820 can be an internal storage unit of the terminal device 800, such as a hard disk or a memory of the terminal device 800 in some embodiments. The memory 820 can also be an external storage device of the terminal device 800, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, and the like equipped on the terminal device 800 in other embodiments. Further, the memory 820 can include both an internal storage unit and an external storage device of the terminal device 800. The memory 820 is used to store an operating system, an application program, a Boot Loader, data, and other programs, such as program codes of computer programs, and the like. The memory 820 can also be used to temporarily store data that has been output or will be output.
[0187] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional units and modules is exemplified, and in actual application, the above functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for easy distinction, and do not limit the protection scope of the present application. The specific working process of the units and modules in the above system can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0188] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described or recorded in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0189] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0190] In the embodiments of the present application, it should be understood that the disclosed apparatus / terminal device and method can be implemented in other manners. For example, the embodiments of the apparatus / terminal device described above are merely schematic, and the division of the modules or units is merely logical function division, and there can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.
[0191] The units described as separated components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments.
[0192] In addition, each functional unit in the various embodiments of the present application can be integrated in one processing unit, or each unit can exist physically as separate units, or two or more units can be integrated in one unit. The integrated unit can be implemented in the form of hardware, or in the form of software function units.
[0193] If the integrated module / unit is implemented in the form of software function units and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such an understanding, all or part of the flow of the method in the above embodiments can also be implemented by a computer program instructing relevant hardware to complete, and the computer program can be stored in a computer readable storage medium. The computer program can be executed by a processor to implement the steps of the above method embodiments. The computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form. The computer readable medium can include any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier wave signal, telecommunication signal and software distribution medium, etc. It should be noted that the computer readable medium can include or exclude some contents according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to the legislation and patent practice, the computer readable medium does not include electric carrier wave signal and telecommunication signal.
[0194] In an embodiment, the terminal device can be configured to implement all or part of the processes in the above method embodiments, and can also be implemented by a computer program product. When the computer program product runs on the terminal device, the terminal device can implement the steps in the above method embodiments.
[0195] The above embodiments are only used to illustrate the technical solutions of the present application, rather than limit them. Although the present application has been described in detail with reference to the foregoing embodiments, it should be understood by those skilled in the art that the technical solutions recorded in the foregoing embodiments can be modified, or some technical features can be replaced by equivalent features. Such modifications or replacements do not change the essence of the corresponding technical solutions, and should be included in the protection scope of the present application.
Claims
1. A parameter update method based on secure vehicle communication, characterized in that, The method is applied to a target component of a target vehicle, the target component refers to a component that needs to be repaired and replaced in the target vehicle, the parameters include a key of the target component and a freshness value of the target component, and the method comprises: obtaining a first encrypted key sent by an electrical inspection instrument, wherein the first encrypted key is generated by encrypting an original key of the target vehicle, and the encrypted key of the original key of the target vehicle is determined according to a type of the target component; decrypting the first encrypted key by using an initial key of the target component to determine the original key of the target vehicle; updating the key of the target component from the initial key to the original key of the target vehicle; obtaining an initial freshness value between the target component and a counterpart part sent by the electrical inspection instrument, wherein the counterpart part refers to a component that has data communication with the target component in the target vehicle, and the initial freshness value refers to a freshness value used when the target component sends a message to the counterpart part; increasing the initial freshness value by a preset value to generate a target freshness value; updating the freshness value of the target component to the target freshness value; when the target vehicle is powered on, sending a freshness value synchronization message to the counterpart part, and attaching the target freshness value in the freshness value synchronization message, so that the counterpart part updates a freshness value of the counterpart part from the initial freshness value to the target freshness value when it is determined that the target freshness value is greater than the initial freshness value, wherein the freshness value synchronization message is encrypted by using the original key of the target vehicle.
2. The method of claim 1, wherein, After the key of the target component is updated from the initial key to the original key of the target vehicle, the method further comprises: obtaining a second encrypted key sent by the electrical inspection instrument, wherein the second encrypted key is generated by encrypting a new key of the target vehicle generated in advance by using the original key of the target vehicle; decrypting the second encrypted key by using the original key of the target vehicle to determine the new key of the target vehicle; updating the key of the target component from the original key of the target vehicle to the new key of the target vehicle, so as to clear the freshness value of the target component when the keys of all components in the target vehicle are updated from the original key of the target vehicle to the new key of the target vehicle.
3. The method of any of claims 1-2, wherein, When the type of the target component includes a new component, the initial key includes a pre-prepared key of the target component; when the type of the target component includes an old component, the initial key includes a key of a vehicle where the target component originally locates.
4. A parameter update method based on secure in-vehicle communication, characterized by The method is applied to an electrical inspection instrument, the parameters include a key of a target component of a target vehicle and a freshness value of the target component, the target component refers to a component that needs to be repaired and replaced in the target vehicle, and the method comprises: obtaining a vehicle identification code of the target vehicle and obtaining an initial key of the target component; sending a vehicle key query request to the cloud, wherein the vehicle key query request includes the vehicle identification code of the target vehicle; obtaining a first encryption key issued by the cloud, wherein the first encryption key is generated by encrypting an original key of the target vehicle, and the encryption key of the original key of the target vehicle is determined according to the type of the target component; sending the first encryption key to the target component, so that the target component decrypts the first encryption key by using an initial key of the target component, to determine the original key of the target vehicle, and update the key of the target component from the initial key to the original key of the target vehicle; reading an initial freshness value between the target component and a counterpart, wherein the counterpart refers to a component in the target vehicle that has data communication with the target component, and the initial freshness value refers to a freshness value used by the target component when sending a message to the counterpart; sending the initial freshness value to the target component, so that the target component increases the initial freshness value by a preset value to generate a target freshness value, updates the freshness value of the target component to the target freshness value, and sends a freshness value synchronization message to the counterpart when the target vehicle is powered on, and the target freshness value is attached to the freshness value synchronization message, so that the counterpart updates the freshness value of the counterpart from the initial freshness value to the target freshness value when it is determined that the target freshness value is greater than the initial freshness value, wherein the freshness value synchronization message is encrypted by using the original key of the target vehicle.
5. The method of claim 4, wherein, After the first encryption key is sent to the target component, the method further includes: obtaining a second encryption key, wherein the second encryption key is generated by encrypting a new key of the target vehicle generated in advance by using the original key of the target vehicle; sending the second encryption key to the target component, so that the target component decrypts the second encryption key by using the original key of the target vehicle, to determine the new key of the target vehicle, and update the key of the target component from the original key of the target vehicle to the new key of the target vehicle, so that the freshness value of the target component is cleared when the keys of all components in the target vehicle are updated from the original key of the target vehicle to the new key of the target vehicle.
6. The method of any one of claims 4-5, wherein, The type of the target component is an old component, and the initial key of the target component is obtained by: obtaining a vehicle identification code of a vehicle where the target component is originally located, and sending the vehicle identification code to the cloud to obtain a key of the vehicle where the target component is originally located from the cloud as the initial key.
7. A parameter updating system based on secure in-vehicle communication, characterized by The system includes an electrical detector, a cloud, and a target component of a target vehicle, the parameters include a key of the target component and a freshness value of the target component, the target component refers to a component that needs to be repaired or replaced in the target vehicle, and the system includes: The electric detector is used to acquire a vehicle identification code of the target vehicle, acquire an initial key of the target component, send a vehicle key query request to the cloud, acquire a first encrypted key issued by the cloud, and send the first encrypted key to the target component, wherein the vehicle key query request comprises the vehicle identification code of the target vehicle; The cloud is used to receive the vehicle key query request sent by the electric detector, encrypt the original key of the target vehicle by using an encrypted key, generate the first encrypted key, and issue the first encrypted key to the electric detector, wherein the encrypted key is determined according to the type of the target component; The target component is used to acquire the first encrypted key sent by the electric detector, decrypt the first encrypted key by using the initial key of the target component to determine the original key of the target vehicle, and update the key of the target component from the initial key to the original key of the target vehicle; The electric detector is also used to read an initial freshness value between the target component and a counterpart, and send the initial freshness value to the target component, wherein the counterpart refers to a component in the target vehicle that has data communication with the target component, and the initial freshness value refers to a freshness value used by the target component when sending a message to the counterpart; The target component is also used to acquire the initial freshness value sent by the electric detector, increase the initial freshness value by a preset value to generate a target freshness value, update the freshness value of the target component to the target freshness value, and then send a freshness value synchronization message to the counterpart when the target vehicle is powered on, and attach the target freshness value in the freshness value synchronization message, so that the counterpart updates the freshness value of the counterpart from the initial freshness value to the target freshness value when it is determined that the target freshness value is greater than the initial freshness value, wherein the freshness value synchronization message is encrypted by using the original key of the target vehicle.
8. A parameter updating apparatus based on secure in-vehicle communication, characterized by comprising: The device is applied to a target component of a target vehicle, the target component refers to a component that needs to be repaired or replaced in the target vehicle, the parameters comprise a key of the target component and a freshness value of the target component, and the device comprises: A first acquisition module is configured to acquire a first encrypted key sent by an electric detector, wherein the first encrypted key is generated by encrypting an original key of a target vehicle, and an encrypted key of the original key of the target vehicle is determined according to a type of the target component; A first decryption module is configured to decrypt the first encrypted key by using an initial key of the target component to determine the original key of the target vehicle; A first update module is configured to update a key of the target component from the initial key to the original key of the target vehicle. The fourth acquisition module is configured to acquire an initial freshness value between the target component and a counterpart of the electric detection instrument, wherein the counterpart refers to a component in the target vehicle that has data communication with the target component, and the initial freshness value refers to a freshness value used by the target component when sending a message to the counterpart; The first generation module is configured to increase the initial freshness value by a preset value to generate a target freshness value; The second update module is configured to update the freshness value of the target component to the target freshness value; The fourth sending module is configured to send a freshness value synchronization message to the counterpart when the target vehicle is powered on, and attach the target freshness value in the freshness value synchronization message, so that the counterpart updates the freshness value of the counterpart from the initial freshness value to the target freshness value when determining that the target freshness value is greater than the initial freshness value, wherein the freshness value synchronization message is encrypted by using the original key of the target vehicle.
9. A parameter updating apparatus based on secure in-vehicle communication, characterized by, The device is applied to an electric detection instrument, and the parameters include a key of a target component and a freshness value of the target component, wherein the target component refers to a component that needs to be repaired or replaced in a target vehicle. The device comprises: The second acquisition module is configured to acquire a vehicle identification code of the target vehicle and an initial key of the target component; The first sending module is configured to send a vehicle key query request to the cloud, wherein the vehicle key query request includes the vehicle identification code of the target vehicle; The third acquisition module is configured to acquire a first encryption key issued by the cloud, wherein the first encryption key is generated by encrypting the original key of the target vehicle, and the encryption key of the original key of the target vehicle is determined according to the type of the target component; The second sending module is configured to send the first encryption key to the target component, so that the target component decrypts the first encryption key by using the initial key of the target component to determine the original key of the target vehicle, and updates the key of the target component from the initial key to the original key of the target vehicle; The reading module is configured to read an initial freshness value between the target component and a counterpart, wherein the counterpart refers to a component in the target vehicle that has data communication with the target component, and the initial freshness value refers to a freshness value used by the target component when sending a message to the counterpart; A fifth sending module is configured to send the initial freshness value to the target component, so that the target component increases the initial freshness value by a preset value to generate a target freshness value, updates the freshness value of the target component to the target freshness value, and when the target vehicle is powered on, sends a freshness value synchronization message to the counterpart, and the target freshness value is attached in the freshness value synchronization message, so that when the target freshness value is greater than the initial freshness value, the freshness value of the counterpart is updated from the initial freshness value to the target freshness value, and the freshness value synchronization message is encrypted by using the original key of the target vehicle.
10. A terminal device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, The computer program is executed by the processor to implement the method of any one of claims 1 to 3, or to implement the method of any one of claims 4 to 6.
11. A computer-readable storage medium storing a computer program, wherein the computer program comprises the following steps of: The computer program is executed by the processor to implement the method of any one of claims 1 to 3, or to implement the method of any one of claims 4 to 6.
Citation Information
Patent Citations
Key writing method and device
CN112740212A
Key updating method and related device thereof
WO2022227057A1