Method, apparatus, electronic device and storage medium for upgrading a device to access the cloud

By deploying docking sensing devices in the device access channel for access authentication and cloud secondary verification, the problem of insufficient security in the existing technology of upgrading equipment access to the cloud is solved, and higher security and more stable OTA upgrade process is achieved.

CN117499918BActive Publication Date: 2025-06-27CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311258720.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-26
Publication Date
2025-06-27
Estimated Expiration
2043-09-26

AI Technical Summary

Technical Problem

The security of existing upgraded devices in the cloud is weak, and it is easy to become the target of attackers, threatening the security of the entire OTA upgrade process.

Method used

By deploying docking sensing devices in the device access channel, access authentication of upgraded devices to be accessed, and secondary verification is carried out through the cloud to ensure the security of upgraded devices accessing the cloud.

Benefits of technology

It realizes all-round and multi-angle access verification, effectively preventing attackers disguised as legal upgraded devices from accessing the cloud, improving the security of upgrading devices to access the cloud, and ensuring the security of the entire OTA upgrade process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117499918B_ABST
    Figure CN117499918B_ABST
Patent Text Reader

Abstract

This application relates to the field of intelligent networked vehicles, and provides a method, device, electronic device, and storage medium for upgrading device access to the cloud. The method includes: obtaining access status information sent by a docking perception device deployed in a device access channel; if it is determined according to the access status information that a to-be-accessed upgrade device meets a preset allowable access condition, sending access authentication information to the to-be-accessed upgrade device via the docking perception device, where the access authentication information includes a second device identification information, a second device location information, a second device reputation value, and a second communication secret order of the cloud; in the device access channel, if a confirmation information forwarded by the to-be-accessed upgrade device via the docking perception device is received, determining the to-be-accessed upgrade device as a target upgrade device, and allowing the target upgrade device to access the cloud. This application can achieve comprehensive access verification by multiple parties, thereby ensuring the security of upgrading device access to the cloud.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent connected vehicles, and in particular, to a method, device, electronic device, and storage medium for upgrading device access to the cloud. Background Art

[0002] In recent years, with the rapid development of intelligent connected vehicles, the intelligent level of automotive components has been continuously improved, and more and more ECUs (Electronic Control Units) are installed inside vehicles. From in-vehicle entertainment systems, mobile services to autonomous driving, OTA (Over the Air Technology) plays an extremely important role. Using OTA technology can help vehicle manufacturers remotely upgrade vehicle functions, optimize performance, and repair defects, bringing better services and a more intelligent and convenient driving experience to users. As an important way for vehicle manufacturers to repair software and firmware vulnerabilities of intelligent connected vehicles and iteratively improve software functions, OTA has also become a key target for hackers.

[0003] The entire OTA system mainly includes the cloud and the vehicle side, and the security work of OTA is a systematic project. Any security problem at either end will threaten the security of the entire OTA system. Therefore, the security of both the cloud and the vehicle side needs to be emphasized. The cloud is mainly responsible for cloud docking with the upgrade device, managing model / vehicle / ECU version information, managing upgrade software, approval, and releasing upgrade software, etc.

[0004] In related technologies, for the link of cloud docking between the cloud and the upgrade device, usually the upgrade device directly accesses the cloud, or can access the cloud after simple authentication. This enables attackers to easily disguise as "legitimate upgrade devices", achieve docking with the cloud, obtain the upgrade file package, and then replace / tamper with the upgrade file package to achieve the purpose of malicious upgrade.

[0005] It can be seen that the security of the existing link for the upgrade device to access the cloud is weak, and it is easy to become the target of attackers, thus threatening the security of the entire OTA upgrade process. Summary of the Invention

[0006] In view of this, embodiments of this application provide a method, device, electronic device, and storage medium for upgrading device access to the cloud, so as to solve the problem that the security of the existing link for the upgrade device to access the cloud is weak, and it is easy to become the target of attackers, thus threatening the security of the entire OTA upgrade process.

[0007] In the first aspect of the embodiments of this application, a method for upgrading device access to the cloud is provided, including:

[0008] Obtain the access status information sent by the docking perception device deployed in the device access channel. The access status information includes the first device identification information, the first device location information, the first device reputation value, and the first communication token of the device to be accessed for upgrade;

[0009] If it is determined according to the access status information that the device to be accessed for upgrade meets the preset allowable access conditions, then send access authentication information to the device to be accessed for upgrade via the docking perception device. The access authentication information includes the second device identification information, the second device location information, the second device reputation value, and the second communication token of the cloud;

[0010] In the device access channel, if the confirmation information forwarded by the device to be accessed for upgrade via the docking perception device is received, then determine the device to be accessed for upgrade as the target upgrade device and allow the target upgrade device to access the cloud.

[0011] In the second aspect of the embodiments of the present application, a device for a upgrade device to access the cloud is provided, including:

[0012] An information acquisition module, configured to obtain the access status information sent by the docking perception device deployed in the device access channel. The access status information includes the first device identification information, the first device location information, the first device reputation value, and the first communication token of the device to be accessed for upgrade;

[0013] An information sending module, configured to, if it is determined according to the access status information that the device to be accessed for upgrade meets the preset allowable access conditions, then send access authentication information to the device to be accessed for upgrade via the docking perception device. The access authentication information includes the second device identification information, the second device location information, the second device reputation value, and the second communication token of the cloud;

[0014] A device access module, configured to, in the device access channel, if the confirmation information forwarded by the device to be accessed for upgrade via the docking perception device is received, then determine the device to be accessed for upgrade as the target upgrade device and allow the target upgrade device to access the cloud.

[0015] In the third aspect of the embodiments of the present application, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above method are implemented.

[0016] In the fourth aspect of the embodiments of the present application, a readable storage medium is provided. The readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0017] Compared with the prior art, the beneficial effects of the embodiments of the present application at least include: In the stage when the device to be upgraded is connected to the cloud, by designing a special device access channel and deploying a docking perception device in the device access channel to act as a "messenger" for docking between the device to be upgraded and the cloud, the device to be upgraded is subjected to a primary access authentication by the docking perception device, and then the access status information of the device to be upgraded after the primary authentication is sent to the cloud for secondary verification. After the secondary verification is passed, the access authentication information fed back by the cloud is returned to the device to be upgraded, and then the device to be upgraded confirms the access authentication information. After the confirmation is completed, the access docking between the cloud and the device to be upgraded is completed. The entire access process includes the access authentication of both the cloud and the device to be upgraded, and at the same time, the device to be upgraded is also subjected to intermediate authentication by the docking perception device deployed in the device access channel, which can realize comprehensive access verification by multiple parties, thereby ensuring the security of the upgraded device accessing the cloud. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0019] Figure 1 is a schematic diagram of an application scenario of an embodiment of the present application;

[0020] Figure 2 is a schematic flowchart of a method for an upgraded device to access the cloud provided by an embodiment of the present application;

[0021] Figure 3 is a schematic diagram of a position relationship change method in the method for an upgraded device to access the cloud provided by an embodiment of the present application;

[0022] Figure 4 is a schematic diagram of a device for an upgraded device to access the cloud provided by an embodiment of the present application;

[0023] Figure 5 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] In the following description, specific details such as specific system architectures and technologies are presented for the purpose of illustration rather than limitation, in order to provide a thorough understanding of the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from obstructing the description of the present application.

[0025] A method and apparatus for an upgrade device to access the cloud according to an embodiment of the present application will be described in detail below with reference to the accompanying drawings.

[0026] Figure 1 It is a schematic diagram of an application scenario of an embodiment of the present application. This application scenario may include a cloud 101 and an upgrade device to be accessed 102; there is a device access channel 103 between the cloud 101 and the upgrade device to be accessed 102; and a docking sensing device 104 is deployed in the device access channel 103.

[0027] The cloud 101 can be a TSP (Telematics Service Provider) platform. The TSP platform plays a core role in the entire OTA upgrade system, connecting automobile manufacturers, in-vehicle device manufacturers, mobile communication operators, content service providers, etc. The main functions of the cloud 101 include cloud docking with the upgrade device, vehicle model / vehicle / ECU version information management, upgrade software management, major version management and policy creation, ECU associated upgrade configuration, upgrade mode configuration, policy testing, approval, release, etc.

[0028] The upgrade device to be accessed 102 can be a vehicle end or an automobile functional software developer. When the upgrade device to be accessed 102 is a vehicle end, it can specifically be an in-vehicle VBOX.

[0029] The device access channel 103 can be a 4G / 5G / WiFi network channel, etc.

[0030] The docking sensing device 104 can be a device that can directly communicate with the cloud 101 and the upgrade device to be accessed 102. For example, it can be a device that supports the MQTT (Message Queuing Telemetry Transport) protocol.

[0031] The cloud 101, the upgrade device to be accessed 102, and the docking sensing device 104 are all provided with a Bluetooth positioning module, for example, an iBeacon Bluetooth positioning module.

[0032] In an implementation scenario, the cloud 101 obtains the access status information sent by the docking perception device 104 deployed in the device access channel 103. The access status information includes the first device identification information, the first device location information, the first device reputation value, and the first communication token of the device to be accessed and upgraded 102. If it is determined according to the access status information that the device to be accessed and upgraded 102 meets the preset allowable access conditions, the access authentication information is sent to the device to be accessed and upgraded 102 via the docking perception device 104. The access authentication information includes the second device identification information, the second device location information, the second device reputation value, and the second communication token of the cloud 101. In the device access channel 103, if the confirmation information forwarded by the device to be accessed and upgraded 102 via the docking perception device 104 is received, the device to be accessed and upgraded 102 is determined as the target upgrade device, and the target upgrade device is allowed to access the cloud 101. The above entire access process not only includes the two-way access authentication of the cloud and the device to be accessed and upgraded, but also performs intermediate authentication on the device to be accessed and upgraded through the docking perception device, which can achieve all-round and multi-angle access verification, effectively prevent attackers pretending to be "legitimate upgrade devices" from accessing the cloud and disturbing the OTA upgrade process, greatly improve the security of the upgrade device accessing the cloud, and ensure the security of the entire OTA upgrade process.

[0033] Figure 2 It is a schematic flowchart of a method for an upgrade device to access the cloud provided by an embodiment of the present application. Figure 2 The method for the upgrade device to access the cloud can be performed by Figure 1 the cloud 101 as shown in Figure 2 the following. The method for the upgrade device to access the cloud includes:

[0034] Step S201: Obtain the access status information sent by the docking perception device deployed in the device access channel. The access status information includes the first device identification information, the first device location information, the first device reputation value, and the first communication token of the device to be accessed and upgraded.

[0035] The first device identification information may be the device ID, device name, or device coding information of the device to be accessed and upgraded, etc.

[0036] The first device reputation value is a characteristic value used to characterize the reliability of the device to be accessed and upgraded. Generally, the higher the first device reputation value, the higher the reliability of the device to be accessed and upgraded. Conversely, the lower the first device reputation value, the lower the reliability of the device to be accessed and upgraded. The reputation degree of the device to be accessed can be determined according to two dimensions of the first device identification information and the first device location information of the device to be accessed.

[0037] The first communication secret order can be the identification information for cloud docking used for OTA upgrade that has been negotiated in advance between the device to be connected and the cloud. This identification information can be a specific string, a specific random number, etc.

[0038] As an example, a correspondence table of device identification - device location - device reputation value can be preset, as shown in Table 1.

[0039] Table 1 Correspondence table of device identification - device location - device reputation value

[0040]

[0041] Exemplarily, assume that the first device identification information of the device to be connected for upgrade is identification Y1, and the first device location information is within the range of location area X1. Then, by querying Table 1, the first device reputation value of the device to be connected for upgrade can be obtained as "reputation value P1".

[0042] Step S202, if it is determined according to the access status information that the device to be connected for upgrade meets the preset allowable access conditions, then send access authentication information to the device to be connected for upgrade via the docking sensing device. The access authentication information includes the second device identification information, the second device location information, the second device reputation value, and the second communication secret order of the cloud.

[0043] The preset allowable access conditions can be that the first device reputation value is greater than or equal to the preset reputation threshold, and the first communication secret order is correct.

[0044] The second device identification information can be the device ID, device name, device coding information, etc. of the cloud.

[0045] The second device reputation value is a characteristic value used to represent the reliability degree of the cloud. Generally, the higher the second device reputation value, the higher the reliability degree of the cloud. On the contrary, the lower the second device reputation value, the lower the reliability degree of the cloud. The reputation degree of the cloud can be determined according to two dimensions of the second device identification information and the second device location information of the cloud.

[0046] The second communication secret order can be the identification information for cloud docking used for OTA upgrade that has been negotiated in advance between the device to be connected and the cloud. This identification information can be a specific string, a specific random number, etc.

[0047] The first communication secret order and the second communication secret order can be the same identification information, or a preset pair of combined pairing contents. For example, the first communication secret order is the random number "1", and the second communication secret order is the random number "-1".

[0048] Step S203, in the device access channel, if the confirmation information forwarded by the docking sensing device from the device to be upgraded is received, the device to be upgraded is determined as the target upgrade device, and the target upgrade device is allowed to access the cloud.

[0049] The confirmation information refers to the indication message for the device to be connected to confirm access to the cloud.

[0050] The technical solution provided by the embodiments of the present application, in the stage of the device to be upgraded accessing the cloud, by designing a special device access channel and deploying a docking sensing device in the device access channel to act as a "messenger" for docking between the device to be upgraded and the cloud, the device to be upgraded is authenticated once through the docking sensing device, and then the access status information of the device to be upgraded after passing the first verification is sent to the cloud for secondary verification. After the secondary verification passes, the access authentication information feedback by the cloud is returned to the device to be upgraded, and then the device to be upgraded confirms the access authentication information. After the confirmation is completed, the access docking between the cloud and the device to be upgraded is completed. The entire access process not only includes the two-way access authentication of the cloud and the device to be upgraded, but also conducts intermediate authentication on the device to be upgraded through the docking sensing device, which can achieve all-round and multi-angle access verification, effectively prevent attackers pretending to be "legitimate upgrade devices" from accessing the cloud and disrupting the OTA upgrade process, and at the same time can also effectively prevent attackers from pretending to be "legitimate clouds" to dock with legitimate upgrade devices to intercept sensitive information of legitimate upgrade devices, or replace / tamper with the upgrade file package, greatly improving the security of the upgrade device accessing the cloud and ensuring the security of the entire OTA upgrade process.

[0051] In some embodiments, before the step of obtaining the access status information sent by the docking sensing device deployed in the device access channel, it further includes:

[0052] Obtain the third device identification information and the third device location information broadcast by at least one candidate sensing device;

[0053] Based on the third device identification information and the third device location information, determine the third device reputation value of each candidate sensing device;

[0054] According to the third device reputation value, select one from at least one candidate sensing device as the docking sensing device;

[0055] Deploy the docking sensing device in the device access channel for docking between the cloud and the device to be upgraded.

[0056] As an example, the cloud 101 can obtain the third device identification information and the third device location information broadcast by at least one candidate sensing device within its signal coverage through Bluetooth scanning. Then, based on the third device identification information and the third device location information of each candidate sensing device, the corresponding third device reputation value is determined. Among them, the determination method of the third device reputation value can refer to the above-mentioned determination method of the first device reputation value, which will not be elaborated here. Next, sort the third device reputation values of each candidate sensing device, and determine the candidate sensing device with the highest reputation value as the docking sensing device. After that, deploy the docking sensing device in the device docking channel.

[0057] In some embodiments, the above access status information is generated by the docking sensing device according to the following steps:

[0058] Start Bluetooth scanning to obtain the first device identification information and the first device location information of the device to be accessed and upgraded within the signal coverage of its current device location;

[0059] If the first device reputation value of the device to be accessed and upgraded is greater than or equal to the preset reputation threshold according to the first device identification information and the first device location information, generate access status information according to the first device identification information, the first device location information, the first device reputation value, and the first communication command.

[0060] As an example, the docking sensing device turns on the Bluetooth positioning module (such as the iBeacon Bluetooth positioning module) for Bluetooth scanning to obtain the first device identification information and the first device location information broadcast by the device to be accessed and upgraded within the signal coverage (generally 1 to 10 meters) centered on its current device location. If the first device reputation value of the device to be accessed and upgraded is greater than or equal to the preset reputation threshold (for example, it can be 80 points, 90 points, etc.) according to the first device identification information and the first device location information, it can be determined that the device to be accessed and upgraded is a reliable access device.

[0061] In some embodiments, the step of generating access status information according to the first device identification information, the first device location information, the first device reputation value, and the first communication command specifically includes:

[0062] Use the preset encryption key to encrypt the access status information to obtain the encrypted ciphertext;

[0063] Generate a digital signature according to the encryption key and the encrypted ciphertext;

[0064] Assemble the encryption key, the encrypted ciphertext, the digital signature, and the first communication command into the access status information and send it to the cloud;

[0065] When access authentication information returned by the cloud for access status information is received, a first location association relationship is established between the current device location and the first device location information of the device to be accessed and upgraded.

[0066] As an example, the format of access status information is defined as: (α, β, γ, δ) = (e k ,E(m),S(e k +E(m)),e t ), where Table e k indicates the encryption key, and E(m) indicates the encryption key e k The encrypted ciphertext obtained by encrypting the access status information is S(e k +E(m)) means e k and the digital signature of E(m), e t According to the access status information assembly format defined above, the encryption key, the encrypted ciphertext, the digital signature and the first communication password are assembled into access status information, and the access status information is sent to the cloud.

[0067] Access authentication information refers to the confirmation message returned by the cloud after verifying the access status information and confirming that the access status information meets the preset access permission conditions.

[0068] After obtaining the first device identification information, the first device location information, the first device reputation value and the first communication password of the device to be accessed and upgraded, the docking perception device performs an access verification on this information. After determining that the device to be accessed and upgraded is a reliable access device, it assembles the access status information according to the defined assembly format of the access status information and sends it to the cloud for a secondary access verification. In this way, some suspicious access devices disguised / impersonated by hackers can be identified layer by layer, effectively blocking the suspicious access devices from accessing the cloud, and preventing the suspicious access devices from disrupting or destroying the security of the entire OTA upgrade process.

[0069] By deploying docking sensing devices in the device access channel to perform access verification on the devices to be upgraded, suspicious access devices can be effectively intercepted to prevent suspicious access devices from directly docking with the cloud and increasing the docking access volume of the cloud, which is conducive to improving the response efficiency of the cloud to reliable access devices.

[0070] In some embodiments, after the step of establishing a first location association relationship between the current device location and the first device location information of the device to be accessed for upgrading, the step further includes:

[0071] If the location information of the first device of the device to be connected and upgraded changes, and the changed location information of the first device is not within the signal coverage of the current device location, search whether there are other docking sensing devices near the changed location of the first device of the device to be connected and upgraded;

[0072] If there are other docking sensing devices, and the signal coverage range of the current positions of the other docking sensing devices covers the changed first device location information, the location association relationship between the current device location and the first device location information of the device to be connected and upgraded is released, and the changed first device location information is sent to the other docking sensing devices, so that the other docking sensing devices establish a second location association relationship between the current position and the changed first device location information.

[0073] Combination Figure 3 , assuming that the device to be connected and upgraded is vehicle A, at time t, the first device position of vehicle A is Figure 3 The current device position of the docking sensing device B is shown as point a in Figure 3 At the position shown by point b in , docking sensing device B establishes a first position association relationship between its current device position and the first device position of vehicle A as [a, b], where a represents the first device position of vehicle A and b represents the current device position of docking sensing device B. At time t+Δt, vehicle A moves from point a to point a′. At point a′, the signal coverage range of docking sensing device B does not cover point a′. At this time, docking sensing device B can search whether there are other docking sensing devices with signal coverage covering point a′ near point a′. If there is another docking sensing device C with signal coverage covering point a′, docking sensing device B cancels the association relationship between point a and point b, and sends the position information of point a′ (i.e., the changed first device position information) to the other docking sensing device C. The other docking sensing device C establishes a second position association relationship [a′, c] between its current position (point c) and point a′ based on the received position information of point a′.

[0074] In a scenario where the location of the device to be upgraded is changing dynamically, the location association relationship between the docking perception device and the device to be upgraded can be changed dynamically and timely. The "dynamic" docking perception device can be used to provide better and more efficient cloud access services for the mobile device to be upgraded, thereby improving the security of the upgrade device's access to the cloud.

[0075] In some embodiments, after the step of obtaining the first device identification information and the first device location information of the device to be upgraded within the signal coverage range of the current device location, the method further includes:

[0076] If the first device reputation value of the device to be upgraded determined according to the first device identification information and the first device location information is less than the preset reputation threshold, the device to be upgraded is marked as a suspicious device to be connected;

[0077] Transfer the first device identification information and the first device location information of the suspicious device to be connected to the interception device list, and report a suspicious access warning message to the cloud.

[0078] The suspicious access warning message includes the first device identification information and the first device location information of the suspicious device to be connected.

[0079] After receiving the suspicious access warning message sent by the docking perception device, the cloud can include the suspicious device to be connected in the access blacklist. When a device to be upgraded attempts to connect to the cloud through other means, the cloud can retrieve the blacklist for verification to lock the suspicious device to be connected and prevent the suspicious device from accessing the cloud without authorization through other means, thereby improving the security of the upgraded device accessing the cloud.

[0080] In some embodiments, the above method further includes the following steps:

[0081] Determine the access permission of the target upgraded device;

[0082] Open a data transmission channel or a data upload channel for the target upgraded device according to the access permission, so that the target upgraded device can download the upgrade data packet through the data transmission channel or upload the upgrade data packet through the data upload channel; wherein, the data transmission channel, the data upload channel, and the device access channel are isolated from each other.

[0083] The access permission refers to whether the target upgraded device has the right to access the cloud and the corresponding operation permissions.

[0084] As an example, if the target upgraded device is a vehicle-mounted VBOX, then it has the operation permission to download the upgrade data packet from the cloud, but does not have the operation permission to upload the upgrade data packet to the cloud. If the target upgraded device is a software developer, then it has the operation permission to upload the upgrade data packet to the cloud, but does not have the operation permission to download the upgrade data packet from the cloud.

[0085] In the embodiments of the present application, by adopting the setting method of isolating the data transmission channel, the data upload channel, and the device access channel from each other, the security of the upgraded device accessing the cloud can be controlled in a targeted manner, preventing unauthorized access devices from accessing the cloud and disturbing the docking between the normal authorized access devices and the cloud, thereby reducing the docking efficiency and security between them; at the same time, it can ensure that the transmission and upload of the upgrade data packet between other normal authorized access devices and the cloud are not disturbed by the unauthorized access devices accessing the cloud, which is beneficial to improving the OTA upgrade efficiency.

[0086] Any of the above optional technical solutions can be combined arbitrarily to form optional embodiments of the present application, which will not be elaborated one by one here.

[0087] The following is an apparatus embodiment of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the apparatus embodiment of the present application, please refer to the method embodiment of the present application.

[0088] Figure 4 It is a schematic diagram of a device for an upgraded device to access the cloud provided by an embodiment of the present application. As Figure 4 shown, the device for the upgraded device to access the cloud includes:

[0089] An information acquisition module 401, configured to acquire access status information sent by a docking perception device deployed in a device access channel, where the access status information includes first device identification information, first device location information, first device reputation value, and first communication secret order of a to-be-accessed upgraded device;

[0090] An information sending module 402, configured to, if it is determined according to the access status information that the to-be-accessed upgraded device meets a preset allowable access condition, send access authentication information to the to-be-accessed upgraded device via the docking perception device, where the access authentication information includes second device identification information, second device location information, second device reputation value, and second communication secret order of the cloud;

[0091] A device access module 403, configured to, in the device access channel, if a confirmation message forwarded by the docking perception device from the to-be-accessed upgraded device is received, determine the to-be-accessed upgraded device as a target upgraded device and allow the target upgraded device to access the cloud.

[0092] The technical solution provided by the embodiments of the present application, at the stage when the device to be upgraded is connected to the cloud, by designing a special device access channel and deploying a docking perception device in the device access channel to act as a "messenger" for docking between the device to be upgraded and the cloud, the device to be upgraded is subjected to a primary access authentication through the docking perception device, and then the access status information of the device to be upgraded after passing the primary verification is sent to the cloud for secondary verification. After the secondary verification is passed, the access authentication information feedback by the cloud is returned to the device to be upgraded, and then the device to be upgraded confirms the access authentication information. After the confirmation is completed, the access docking between the cloud and the device to be upgraded is completed. The entire access process not only includes the two-way access authentication of the cloud and the device to be upgraded, but also conducts an intermediate authentication of the device to be upgraded through the docking perception device, which can achieve all-round and multi-angle access verification, effectively prevent attackers pretending to be "legitimate upgrade devices" from accessing the cloud and disrupting the OTA upgrade process, and at the same time can also effectively prevent attackers from pretending to be "legitimate clouds" to dock with legitimate upgrade devices to intercept sensitive information of legitimate upgrade devices, or replace / tamper with the upgrade file package, greatly improving the security of the upgrade device accessing the cloud and ensuring the security of the entire OTA upgrade process.

[0093] In some embodiments, the above device further includes:

[0094] An acquisition module, configured to acquire the third device identification information and the third device location information broadcast by at least one candidate perception device;

[0095] A determination module, configured to determine the third device reputation value of each candidate perception device based on the third device identification information and the third device location information;

[0096] A screening module, configured to screen out one from at least one candidate perception device as the docking perception device according to the third device reputation value;

[0097] A deployment module, configured to deploy the docking perception device in the device access channel for docking between the cloud and the device to be upgraded.

[0098] In some embodiments, the docking perception device includes a generation module, and the generation module is configured to generate access status information.

[0099] The generation module specifically includes:

[0100] A scanning unit, configured to start Bluetooth scanning and acquire the first device identification information and the first device location information of the device to be upgraded within the signal coverage range of its current device location;

[0101] The generating unit is configured to generate access status information according to the first device identification information, the first device location information, the first device reputation value and the first communication password if it is determined that the first device reputation value of the device to be accessed and upgraded is greater than or equal to a preset reputation threshold according to the first device identification information and the first device location information.

[0102] In some embodiments, the generating unit includes:

[0103] The encryption component is configured to encrypt the access state information using a preset encryption key to obtain an encrypted ciphertext;

[0104] A generating component is configured to generate a digital signature based on the encryption key and the encrypted ciphertext;

[0105] An assembly component, configured to assemble the encryption key, the encrypted ciphertext, and the digital signature into access status information, and send the information to the cloud;

[0106] An establishing component is configured to establish a first location association relationship between a current device location and first device location information of a device to be accessed and upgraded when access authentication information returned by the cloud for access status information is received.

[0107] In some embodiments, the generating unit further includes:

[0108] A search component is configured to search for other docking sensing devices near the changed first device location of the to-be-connected upgraded device if the first device location information of the to-be-connected upgraded device changes and the changed first device location information is not within the signal coverage range of the current device location;

[0109] The change component is configured to release the position association relationship between the current device position and the first device position information of the device to be connected and upgraded if there are other docking sensing devices and the signal coverage range of the current position of the other docking sensing devices covers the changed first device position information, and send the changed first device position information to the other docking sensing devices, so that the other docking sensing devices establish a second position association relationship between the current position and the changed first device position information.

[0110] In some embodiments, the generation module further includes:

[0111] a marking unit configured to mark the device to be upgraded as a suspicious device to be connected if it is determined according to the first device identification information and the first device location information that the first device reputation value of the device to be upgraded is less than a preset reputation threshold;

[0112] A reporting unit, configured to transfer the first device identification information and the first device location information of a suspicious device to be connected to a list of intercepted devices, and report a suspicious access warning message to the cloud.

[0113] In some embodiments, the above device further includes:

[0114] A permission determination module, configured to determine the access permission of a target device to be upgraded;

[0115] A channel opening module, configured to open a data transmission channel or a data upload channel to the target device to be upgraded according to the access permission, so that the target device to be upgraded downloads an upgrade data packet through the data transmission channel or uploads an upgrade data packet through the data upload channel; wherein, the data transmission channel, the data upload channel, and the device access channel are isolated from each other.

[0116] It should be understood that the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0117] Figure 5 It is a schematic diagram of an electronic device 5 provided by an embodiment of the present application. As Figure 5 shown, the electronic device 5 in this embodiment includes: a processor 501, a memory 502, and a computer program 503 stored in the memory 502 and executable on the processor 501. When the processor 501 executes the computer program 503, the steps in the above method embodiments are implemented. Alternatively, when the processor 501 executes the computer program 503, the functions of each module / unit in the above device embodiments are implemented.

[0118] The electronic device 5 may be a desktop computer, a notebook, a palm computer, a cloud server, or other electronic devices. The electronic device 5 may include, but is not limited to, the processor 501 and the memory 502. Those skilled in the art can understand that Figure 5 merely examples of the electronic device 5, and do not constitute a limitation to the electronic device 5. It may include more or fewer components than shown in the figure, or different components.

[0119] The processor 501 may be a Central Processing Unit (CPU), or may be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0120] The memory 502 may be an internal storage unit of the electronic device 5. For example, the hard disk or memory of the electronic device 5. The memory 502 may also be an external storage device of the electronic device 5. For example, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc., equipped on the electronic device 5. The memory 502 may also include both an internal storage unit and an external storage device of the electronic device 5. The memory 502 is used to store computer programs and other programs and data required by the electronic device.

[0121] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In practical applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0122] When an integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium (such as a computer-readable storage medium). Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of this application, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-described various method embodiments can be implemented. The computer program can include computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable storage medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0123] The above embodiments are only used to illustrate the technical solutions of this application, rather than to limit it; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of this application, and should all be included in the protection scope of this application.

Claims

1. A method for an upgrade device to access the cloud, characterized in that, Including: Obtaining access status information sent by a docking perception device deployed in a device access channel, where the access status information includes first device identification information, first device location information, first device reputation value, and first communication secret order of a device to be accessed for upgrade; If it is determined according to the access status information that the device to be accessed for upgrade meets a preset allowable access condition, then sending access authentication information to the device to be accessed for upgrade via the docking perception device, where the access authentication information includes second device identification information, second device location information, second device reputation value, and second communication secret order of the cloud; In the device access channel, if a confirmation message forwarded by the device to be accessed for upgrade via the docking perception device is received, then determining the device to be accessed for upgrade as a target upgrade device and allowing the target upgrade device to access the cloud; Before obtaining the access status information sent by the docking perception device deployed in the device access channel, further including: Obtaining third device identification information and third device location information broadcast by at least one candidate perception device; Based on the third device identification information and third device location information, determining the third device reputation value of each candidate perception device; According to the third device reputation value, screening out one from the at least one candidate perception device as the docking perception device; Deploying the docking perception device in a device access channel for docking between the cloud and a device to be upgraded.

2. The method according to claim 1, wherein The access status information is generated by the docking perception device according to the following steps: Starting Bluetooth scanning to obtain first device identification information and first device location information of a device to be accessed for upgrade within the signal coverage range of its current device location; If it is determined according to the first device identification information and first device location information that the first device reputation value of the device to be accessed for upgrade is greater than or equal to a preset reputation threshold, then generating access status information according to the first device identification information, first device location information, first device reputation value, and first communication secret order.

3. The method according to claim 2, wherein Generating access status information according to the first device identification information, first device location information, first device reputation value, and first communication secret order, including: Using a preset encryption key to encrypt the access status information to obtain an encrypted ciphertext; Generating a digital signature according to the encryption key and the encrypted ciphertext; Assembling the encryption key, the encrypted ciphertext, and the digital signature into access status information and sending it to the cloud; When receiving the access authentication information returned by the cloud for the access status information, establishing a first location association relationship between the current device location and the first device location information of the device to be accessed for upgrade.

4. The method according to claim 3, wherein After establishing the first location association relationship between the current device location and the first device location information of the device to be accessed for upgrade, further including: If the first device location information of the device to be accessed for upgrade changes and the changed first device location information is not within the signal coverage range of its current device location, then searching whether there is any other docking perception device near the changed first device location of the device to be accessed for upgrade; If there are other docking sensing devices, and the signal coverage range of the current position of the other docking sensing devices covers the changed first device position information, the position association relationship between the current device position and the first device position information of the device to be accessed and upgraded is released, and the changed first device position information is sent to the other docking sensing devices, so that the other docking sensing devices establish a second position association relationship between the current position and the changed first device position information.

5. The method according to claim 2, wherein After obtaining the first device identification information and the first device position information of the device to be upgraded within the signal coverage range of its current device position, it further includes: If it is determined according to the first device identification information and the first device position information that the first device reputation value of the device to be upgraded is less than a preset reputation threshold, the device to be upgraded is marked as a suspicious device to be accessed. The first device identification information and the first device position information of the suspicious device to be accessed are transferred to the interception device list, and a suspicious access warning message is reported to the cloud.

6. The method according to claim 1, wherein The method further includes: Determine the access permission of the target upgrade device; Open a data transmission channel or a data upload channel for the target upgrade device according to the access permission, so that the target upgrade device can download the upgrade data packet through the data transmission channel or upload the upgrade data packet through the data upload channel; wherein, the data transmission channel, the data upload channel and the device access channel are isolated from each other.

7. A device for upgrading equipment to access the cloud, characterized in that, It includes: An information acquisition module, configured to acquire the access status information sent by a docking sensing device deployed in the device access channel, where the access status information includes the first device identification information, the first device position information, the first device reputation value, and the first communication secret order of the device to be accessed and upgraded; An information sending module, configured to send access authentication information to the device to be accessed and upgraded via the docking sensing device if it is determined according to the access status information that the device to be accessed and upgraded meets the preset allowable access conditions, where the access authentication information includes the second device identification information, the second device position information, the second device reputation value, and the second communication secret order of the cloud; A device access module, configured to determine the device to be accessed and upgraded as the target upgrade device and allow the target upgrade device to access the cloud if an acknowledgement message forwarded by the docking sensing device from the device to be accessed and upgraded is received in the device access channel; The device further includes: An acquisition module, configured to acquire the third device identification information and the third device position information broadcast by at least one candidate sensing device; A determination module, configured to determine the third device reputation value of each of the candidate sensing devices based on the third device identification information and the third device position information; A screening module, configured to screen out one of the at least one candidate sensing device as the docking sensing device according to the third device reputation value; A deployment module, configured to deploy the docking sensing device in the device access channel for docking between the cloud and the device to be upgraded.

8. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Vehicle OTA upgrading method and system, electronic equipment and storage medium

    CN116506840A