Vehicle control methods, devices, electronic equipment, storage media, and vehicles
Through multi-level security authentication, including encrypted authentication between the keyless entry and start device and the vehicle controller, the drive motor controller and the body controller, and the engine controller and the body controller, the problem of low security in traditional vehicle security authentication is solved, achieving a higher level of security and anti-theft effect.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-12
- Publication Date
- 2026-03-13
AI Technical Summary
Traditional vehicles lack anti-theft authentication between the key and the vehicle controller and drive motor controller, resulting in low security of vehicle security authentication.
Multi-level security authentication is implemented, including the first level of security authentication between the keyless entry and start device and the vehicle controller, and the second level of security authentication between the drive motor controller and the body controller, and between the engine controller and the body controller. The vehicle is only allowed to start after successful authentication through encryption algorithms and challenge signals.
It improves vehicle security certification, enhances anti-theft functions, reduces drivers' concerns about theft, and improves vehicle security and anti-theft effectiveness.
Smart Images

Figure CN118810678B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicles, and more specifically, to a vehicle control method, apparatus, electronic device, storage medium, and vehicle. Background Technology
[0002] Currently, anti-theft control methods for powertrain systems in traditional vehicles typically involve authentication between the key and the Engine Management System (EMS). Since traditional vehicles do not involve anti-theft authentication between the key and the Hybrid Control Unit (HCU) or the key and the Motor Control Unit (MCU), the security of vehicle authentication remains low.
[0003] There is currently no effective solution to the problem of low security in vehicle safety certification. Summary of the Invention
[0004] This invention provides a vehicle control method, apparatus, electronic device, storage medium, and vehicle to at least address the technical problem of low security in vehicle security authentication.
[0005] According to one aspect of the present invention, a vehicle control method is provided. The method may include: in response to a vehicle controller being in an initialization state, performing a first-level security authentication on the vehicle to obtain a first authentication result, wherein the first-level security authentication represents the security authentication between a keyless entry and start device and the vehicle controller; in response to the first authentication result being successful, performing a second-level security authentication on the vehicle to obtain a second authentication result, wherein the second-level security authentication represents the security authentication between a drive motor controller and a body controller, and between an engine controller and a body controller; and in response to the second authentication result being successful, controlling the vehicle to start under normal conditions.
[0006] Optionally, in response to the vehicle controller being in an initialization state, a first-level security authentication is performed on the vehicle to obtain a first authentication result, including: obtaining the vehicle's key information; in response to the key information indicating that the vehicle's key is in the start state and the key is located inside the vehicle, controlling the low-voltage power supply of the vehicle's power system and the unlocking of the electronic steering column; in response to the failure of the low-voltage power supply of the power system or the failure of the electronic steering column to unlock, controlling the vehicle to output a warning message; in response to the successful low-voltage power supply of the power system, the successful unlocking of the electronic steering column, and the vehicle controller being in an initialization state, performing a first-level security authentication on the keyless entry and start device and the vehicle controller to obtain a first authentication result.
[0007] Optionally, a first-level security authentication is performed on the keyless entry and start device and the vehicle controller to obtain a first authentication result, including: controlling the vehicle controller to send a challenge code signal to the keyless entry and start device; in response to the keyless entry and start device successfully receiving the challenge code signal, controlling the keyless entry and start device to decrypt the challenge code signal to obtain an identification code signal; in response to the identification code signal successfully matching a first target identification code signal stored internally in the keyless entry and start device, controlling the keyless entry and start device to send the identification code signal to the vehicle controller; in response to the vehicle controller successfully receiving the identification code signal and the identification code signal being a normal signal, controlling the vehicle controller to decrypt the identification code signal to obtain a decrypted identification code signal; in response to the decrypted identification code signal successfully matching a second target identification code signal stored internally in the vehicle controller, determining the first authentication result as successful authentication.
[0008] Optionally, the method further includes: in response to the vehicle controller not receiving the identification code signal, controlling the vehicle controller to send a challenge code signal to the keyless entry and start device according to a first time period within a first time period until the vehicle controller successfully receives the identification code signal, or the vehicle controller still does not receive the identification code signal, and determining the first authentication result as authentication failure.
[0009] Optionally, the method further includes: in response to the failure of the identification code signal to match the first target identification code signal, controlling the keyless entry and start device to send the identification code signal to the vehicle controller; in response to the vehicle controller successfully receiving the identification code signal and the identification code signal being an abnormal signal, determining that the first authentication result is an authentication failure.
[0010] Optionally, the method further includes: in response to the failure of the decrypted identification code signal to match the second target identification code signal, determining the first authentication result as authentication failure.
[0011] Optionally, in response to the first authentication result being successful, a second level of safety authentication is performed on the vehicle to obtain a second authentication result, including: in response to the first authentication result being successful and the vehicle's gear being in the target gear, performing a second level of safety authentication on the drive motor controller and the body controller, and performing a second level of safety authentication on the engine controller and the body controller to obtain a second authentication result.
[0012] Optionally, a second-level security authentication is performed on the drive motor controller and the body controller, and a second-level security authentication is also performed on the engine controller and the body controller to obtain a second authentication result. This includes: controlling the drive motor controller to send a first challenge signal to the body controller within a second time period, and controlling the engine controller to send a second challenge signal to the body controller within a second time period; in response to the body controller successfully receiving the first challenge signal and the second challenge signal, controlling the body controller to decrypt the first challenge signal to obtain a first response signal, and controlling the body controller to decrypt the second challenge signal to obtain a second response signal; controlling the body controller to send the first response signal to the drive motor controller, and controlling the body controller to send the second response signal to the engine controller; in response to the drive motor controller successfully receiving the first response signal, and the first response signal successfully matching the first target response signal stored internally by the drive motor controller, determining the second authentication result as successful authentication; in response to the engine controller successfully receiving the second response signal, and the second response signal successfully matching the second target response signal stored internally by the engine controller, determining the second authentication result as successful authentication.
[0013] Optionally, the method further includes: in response to the second authentication result being successful, prohibiting the second-level security authentication of the drive motor controller and the body controller, and prohibiting the second-level security authentication of the engine controller and the body controller within a third time period.
[0014] Optionally, the method further includes: in response to a successful second authentication result, acquiring a powertrain status signal and a drive motor status signal; in response to a powertrain status signal being a first target value and a drive motor status signal being in speed response mode, controlling the drive motor controller to send a first challenge signal to the body controller according to a second time period, and controlling the engine controller to send a second challenge signal to the body controller according to a second time period; in response to a powertrain status signal being a second target value and a drive motor status signal being in torque response mode, prohibiting the drive motor controller from sending the first challenge signal to the body controller, and prohibiting the engine controller from sending the second challenge signal to the body controller.
[0015] Optionally, the method further includes: in response to the first challenge signal being an invalid challenge signal, the second challenge signal being an invalid challenge signal, and the number of times the invalid challenge signal is received reaching a first threshold, prohibiting the body controller from sending a first response signal to the drive motor controller, and prohibiting the body controller from sending a second response signal to the engine controller; in response to the first response signal being an invalid response signal, the second response signal being an invalid response signal, and the number of times the invalid response signal is received reaching a second threshold, prohibiting the drive motor controller from sending a first challenge signal to the body controller, and prohibiting the engine controller from sending a second challenge signal to the body controller.
[0016] According to another aspect of the present invention, a vehicle control device is also provided. The device may include: a first authentication unit, configured to perform a first-level security authentication on the vehicle in response to the vehicle controller being in an initialization state, and obtain a first authentication result, wherein the first-level security authentication represents the security authentication between the keyless entry and start device and the vehicle controller; a second authentication unit, configured to perform a second-level security authentication on the vehicle in response to the first authentication result being successful, and obtain a second authentication result, wherein the second-level security authentication represents the security authentication between the drive motor controller and the body controller, and the security authentication between the engine controller and the body controller; and a control unit, configured to control the vehicle to start under normal conditions in response to the second authentication result being successful.
[0017] According to another aspect of the present invention, a computer-readable storage medium is also provided. The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to perform the vehicle control method of the present invention.
[0018] According to another aspect of the present invention, a vehicle is also provided. This vehicle is used to execute the vehicle control method of the present invention.
[0019] According to another aspect of the present invention, a computer program product is also provided. This computer program product may include a computer program configured to execute any of the vehicle control methods described above when running.
[0020] According to another aspect of the present invention, a computer program product is also provided. This computer program product may include a non-volatile computer-readable storage medium storing a computer program configured to execute any of the vehicle control methods described above when run.
[0021] According to another aspect of the present invention, a computer program is also provided. This computer program is configured to execute any of the above-described vehicle control methods when run.
[0022] In this embodiment of the invention, in response to the vehicle controller being in an initialization state, a first-level security authentication is performed on the vehicle to obtain a first authentication result. This first-level security authentication represents the security authentication between the keyless entry and start device and the vehicle controller. In response to the first authentication result being successful, a second-level security authentication is performed on the vehicle to obtain a second authentication result. This second-level security authentication represents the security authentication between the drive motor controller and the vehicle body controller, and between the engine controller and the body controller. In response to the second authentication result being successful, the vehicle is controlled to start under normal conditions. In other words, this embodiment of the invention performs a first-level security authentication between the keyless entry and start device and the vehicle controller. After the first-level security authentication is successful, a second-level security authentication is performed between the drive motor controller and the engine controller and the body controller, respectively. Only after the second-level security authentication is successful is the vehicle controlled to start under normal conditions. This achieves the technical effect of improving the security of vehicle security authentication and solves the technical problem of low security in vehicle security authentication. Attached Figure Description
[0023] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this invention, illustrate exemplary embodiments of the invention and are used to explain the invention, but do not constitute an undue limitation of the invention. In the drawings:
[0024] Figure 1 This is a flowchart of a vehicle control method according to an embodiment of the present invention;
[0025] Figure 2 This is a schematic diagram of a hybrid vehicle powertrain configuration according to an embodiment of the present invention;
[0026] Figure 3 This is a flowchart of a vehicle anti-theft authentication method according to an embodiment of the present invention;
[0027] Figure 4 This is a flowchart of a two-way anti-theft authentication method for vehicles according to an embodiment of the present invention;
[0028] Figure 5 This is a flowchart of a motor or engine starting process according to an embodiment of the present invention;
[0029] Figure 6 This is a schematic diagram of an anti-theft authentication sequence according to an embodiment of the present invention;
[0030] Figure 7 This is a schematic diagram of a vehicle control device according to an embodiment of the present invention. Detailed Implementation
[0031] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0032] It should be noted that the terms "first," "second," etc., in the specification and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0033] According to an embodiment of the present invention, an embodiment of a vehicle control method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0034] Figure 1 This is a flowchart of a vehicle control method according to an embodiment of the present invention, such as... Figure 1 As shown, the method may include the following steps:
[0035] Step S102: In response to the vehicle controller being in the initialization state, the vehicle is subjected to first-level security authentication to obtain a first authentication result. The first-level security authentication is used to represent the security authentication between the keyless entry and start device and the vehicle controller.
[0036] In the technical solution provided in step S102 of the present invention, in response to the vehicle controller being in an initialization state, a first-level security authentication can be performed on the vehicle to obtain a first authentication result. The vehicle controller (HCU), as the core controller of the vehicle, can be used to coordinate and control other subsystems, realizing power-on / power-off control of the power system and driving control, etc. The Passive Entry Passive Start (PEPS) device can be used to control keyless entry into the vehicle and start the engine. The PEPS is composed of a controller, a vehicle-side receiver, and a radio frequency transmitter in the vehicle key. This first-level security authentication can be referred to as the first-level anti-theft authentication.
[0037] It should be noted that the various controllers mentioned above communicate with each other via a Controller Area Network (CAN).
[0038] It should be noted that the HCU and PEPS in the anti-theft control system have two states: the anti-theft system is disabled and the anti-theft system is armed. When the PEPS is in the anti-theft armed state, it does not receive information sent by the HCU. The PEPS only triggers the anti-theft disabled state when the vehicle key is inside the vehicle. When the HCU is powered on and initialized, the HCU is in the anti-theft armed state. When the anti-theft authentication between the HCU and PEPS fails, the HCU is also in the anti-theft armed state. When the anti-theft authentication between the HCU and PEPS succeeds, the HCU is in the anti-theft disabled state.
[0039] Step S104: In response to the first authentication result being successful, perform a second-level safety authentication on the vehicle to obtain a second authentication result. The second-level safety authentication is used to represent the safety authentication between the drive motor controller and the body controller in the vehicle, and the safety authentication between the engine controller and the body controller in the vehicle.
[0040] In the technical solution provided in step S104 of the present invention, after performing a first-level security authentication on the vehicle and obtaining a first authentication result, when the obtained first authentication result is successful, in response to the successful first authentication result, a second-level security authentication can be performed on the vehicle to obtain a second authentication result. The drive motor controller (MCU) can be used to control the drive motor. The engine controller (EMS) can control the engine. The body control unit (BCM) can be used to control the vehicle's internal electrical system. The second-level security authentication can be referred to as the second-level anti-theft authentication.
[0041] Optionally, the second-level anti-theft control of the vehicle's powertrain system can determine whether the high-voltage starter motor and engine can be accessed through anti-theft authentication between the MCU, EMS, and BCM. The second-level anti-theft control may include motor authentication between the MCU and BCM, and engine authentication between the EMS and BCM, with each controller transmitting information to the others via a CAN bus.
[0042] Optionally, during the powertrain anti-theft control process, the anti-theft control algorithm is integrated into the internal memory of the MCU and EMS. When the motor and engine anti-theft authentication is successful, the vehicle anti-theft system is deactivated, and the vehicle can then use the high-voltage electric starter motor and engine. Otherwise, the vehicle anti-theft system remains armed, and the vehicle cannot use the high-voltage electric starter motor and engine.
[0043] In step S106, in response to the second authentication result being successful, the vehicle is controlled to start under normal conditions.
[0044] In the technical solution provided by step S106 of the present invention, after performing a second-level security authentication on the vehicle and obtaining a second authentication result, when the obtained second authentication result is successful, the vehicle can be controlled to start under normal conditions in response to the successful second authentication result.
[0045] Optionally, the high-voltage starter motor and engine can only be activated after the vehicle has completed the first and second levels of anti-theft authentication. Since vehicles have multiple power sources, this embodiment, through its multi-level anti-theft authentication design, makes vehicle anti-theft more secure and effective, reduces driver anxiety about theft, and improves vehicle security and anti-theft performance.
[0046] In steps S102 to S106 of the present invention, in response to the vehicle controller being in an initialization state, a first-level security authentication is performed on the vehicle to obtain a first authentication result. This first-level security authentication represents the security authentication between the keyless entry and start device and the vehicle controller. In response to a successful first authentication result, a second-level security authentication is performed on the vehicle to obtain a second authentication result. This second-level security authentication represents the security authentication between the drive motor controller and the vehicle body controller, and between the engine controller and the body controller. In response to a successful second authentication result, the vehicle is controlled to start under normal conditions. In other words, this embodiment of the present invention performs a first-level security authentication between the keyless entry and start device and the vehicle controller. After successful first-level security authentication, a second-level security authentication is performed between the drive motor controller and the engine controller and the body controller, respectively. Only after successful second-level security authentication is the vehicle controlled to start under normal conditions. This achieves the technical effect of improving the security of vehicle security authentication and solves the technical problem of low security in vehicle security authentication.
[0047] The method described in this embodiment will be further described below.
[0048] As an optional embodiment, step S102, in response to the vehicle controller being in an initialization state, performs a first-level security authentication on the vehicle to obtain a first authentication result, including: obtaining the vehicle's key information; in response to the key information indicating that the vehicle's key is in an ignition state and the key is located inside the vehicle, controlling the low-voltage power supply of the vehicle's power system and the unlocking of the electronic steering column; in response to the failure of the low-voltage power supply of the power system or the failure of the electronic steering column to unlock, controlling the vehicle to output a warning message; in response to the successful low-voltage power supply of the power system, the successful unlocking of the electronic steering column, and the vehicle controller being in an initialization state, performing a first-level security authentication on the keyless entry and start device and the vehicle controller to obtain a first authentication result.
[0049] In this embodiment, vehicle key information can be acquired. When the acquired key information indicates that the vehicle key is in the ignition state and located inside the vehicle, the system can control the low-voltage power-on of the vehicle's powertrain and the unlocking of the electronic steering column. If the low-voltage power-on of the powertrain fails or the electronic steering column unlocking fails, the system can control the vehicle to output a warning message. When the low-voltage power-on of the powertrain is successful, the electronic steering column unlocking is successful, and the vehicle controller is in the initialization state, the keyless entry and start device and the vehicle controller can undergo a first-level security authentication to obtain a first authentication result. The ignition state of the vehicle key can be used to indicate that the vehicle key has been inserted, and can be represented by Key-On. The warning message can be used to indicate that the low-voltage power-on of the powertrain and the unlocking of the electronic steering column failed to complete normally.
[0050] Optionally, when the vehicle key is in the Key-On state and the key is inside the vehicle, the powertrain can be controlled to trigger low-voltage power-on (Ignition On) and the electronic steering column can be unlocked. If the powertrain's low-voltage power-on trigger or the electronic steering column unlocking trigger fails to complete normally, authentication fails, and the vehicle's instrument panel displays relevant information. If the powertrain's low-voltage power-on trigger and the electronic steering column unlocking trigger complete normally, and the HCU controller's internal initialization is complete, then the HCU and PEPS undergo first-level security authentication, obtaining the first authentication result.
[0051] As an optional embodiment, a first-level security authentication is performed between the keyless entry and start device and the vehicle controller to obtain a first authentication result, including: controlling the vehicle controller to send a challenge code signal to the keyless entry and start device; in response to the keyless entry and start device successfully receiving the challenge code signal, controlling the keyless entry and start device to decrypt the challenge code signal to obtain an identification code signal; in response to the identification code signal successfully matching a first target identification code signal stored internally in the keyless entry and start device, controlling the keyless entry and start device to send the identification code signal to the vehicle controller; in response to the vehicle controller successfully receiving the identification code signal and the identification code signal being a normal signal, controlling the vehicle controller to decrypt the identification code signal to obtain a decrypted identification code signal; and in response to the decrypted identification code signal successfully matching a second target identification code signal stored internally in the vehicle controller, determining the first authentication result as successful authentication.
[0052] In this embodiment, the vehicle controller can be controlled to send a challenge code signal to the keyless entry and start device. After the keyless entry and start device successfully receives the challenge code signal, it can be controlled to decrypt the challenge code signal to obtain an identification code signal. When the obtained identification code signal successfully matches the first target identification code signal stored internally by the keyless entry and start device, the keyless entry and start device can be controlled to send the identification code signal to the vehicle controller. When the vehicle controller successfully receives the identification code signal, and the identification code signal is a normal signal, it can be controlled to decrypt the identification code signal to obtain a decrypted identification code signal. Further, when the decrypted identification code signal successfully matches the second target identification code signal stored internally by the vehicle controller, the first authentication result can be determined as successful authentication. The challenge code signal can be a string of encrypted data using a special encryption algorithm, and the challenge code can be eight bytes of data. The first target identification code signal can be an identification code signal stored in the internal module of the keyless entry and start device. The second target identification code can be an identification code signal stored in the internal module of the vehicle controller.
[0053] Optionally, after the HCU controller completes its internal initialization, it can send a challenge code signal to PEPS. Upon receiving the challenge code signal from the HCU, PEPS can decrypt it using a decryption algorithm to obtain an identification code signal. The decrypted identification code signal is then compared with the first target identification code signal stored in the PEPS internal module. If they match, PEPS sends a response code signal indicating successful anti-theft authentication to the HCU. This response code signal is a normal eight-byte data. When the HCU receives the response code signal from PEPS and determines that it is a normal signal (i.e., normal byte data), it uses an encryption algorithm to decode the response code signal. The decrypted response code signal is then compared with the second target identification code signal stored in the internal module. If they match, two-way authentication is successful.
[0054] As an optional embodiment, the method further includes: in response to the vehicle controller not receiving the identification code signal, controlling the vehicle controller to send a challenge code signal to the keyless entry and start device according to a first time period within a first time period, until the vehicle controller successfully receives the identification code signal, or the vehicle controller still does not receive the identification code signal, and determining the first authentication result as authentication failure.
[0055] In this embodiment, when the vehicle controller does not receive the identification code signal, it can be controlled to send a challenge code signal to the keyless entry and start device according to a first time period within a first time interval, until the vehicle controller successfully receives the identification code signal. If the vehicle controller still does not receive the identification code signal, the first authentication result can be determined as authentication failure. The first time interval can be a predetermined time set according to actual conditions, for example, 2 seconds (s). This is only an example and no specific limit is placed on the value of the first time interval. The first time period can be an interval set according to actual conditions, for example, 200 milliseconds (ms). This is only an example and no specific limit is placed on the value of the first time period.
[0056] Optionally, if the HCU does not receive the response code signal sent by PEPS, the HCU is controlled to continuously send a challenge code signal at regular intervals, such as 200ms, within a specified time, for example, 2 seconds. If the HCU still does not receive the response code signal sent by PEPS, the anti-theft authentication fails.
[0057] As an optional embodiment, the method further includes: in response to the failure of the identification code signal to match the first target identification code signal, controlling the keyless entry and start device to send the identification code signal to the vehicle controller; in response to the vehicle controller successfully receiving the identification code signal and the identification code signal being an abnormal signal, determining that the first authentication result is an authentication failure.
[0058] In this embodiment, when the identification code signal fails to match the first target identification code signal, the keyless entry and start device can be controlled to send the identification code signal to the vehicle controller. When the vehicle controller successfully receives the identification code signal, and the identification code signal is an abnormal signal, the first authentication result can be determined as authentication failure.
[0059] Optionally, after the PEPS controller matches the decrypted identification code signal with the first target identification code signal stored in the internal module, if the two fail to match, the PEPS controller sends a response code signal indicating that the anti-theft authentication has failed to pass to the HCU. This response code is an abnormal eight-byte data. When the vehicle controller receives an abnormal identification code signal, the two-way authentication fails.
[0060] As an optional embodiment, the method further includes: in response to the failure of the decrypted identification code signal to match the second target identification code signal, determining the first authentication result as authentication failure.
[0061] In this embodiment, when the decrypted identification code signal fails to match the second target identification code signal, the first authentication result can be determined as authentication failure. Optionally, when controlling the HCU to send a challenge code signal to PEPS, the HCU also calculates the second target identification code signal internally, that is, calculates an anti-theft identification code, which is used to verify the response code signal returned by PEPS. When the response code signal returned by PEPS received by the HCU fails to match the second target identification code signal stored in the HCU's internal module, the two-way authentication fails.
[0062] As an optional embodiment, step S104, in response to the first authentication result being successful, performs a second-level safety authentication on the vehicle to obtain a second authentication result, including: in response to the first authentication result being successful and the vehicle's gear being in the target gear, performing a second-level safety authentication on the drive motor controller and the body controller, and performing a second-level safety authentication on the engine controller and the body controller to obtain a second authentication result.
[0063] In this embodiment, when the first authentication result is successful and the vehicle is in the target gear, a second level of safety authentication can be performed on the drive motor controller and the body controller, as well as on the engine controller and the body controller, to obtain a second authentication result. The target gear can be either Park (P) or Neutral (N), but this is only an example and no specific limitation is made to the target gear.
[0064] Optionally, after the HCU and PEPS two-way authentication is successful, when the driver in the vehicle presses the brake pedal and the vehicle is in P or N gear, the power system is controlled to enter the second level of anti-theft authentication.
[0065] As an optional embodiment, a second-level security authentication is performed on the drive motor controller and the body controller, and a second-level security authentication is also performed on the engine controller and the body controller to obtain a second authentication result. This includes: controlling the drive motor controller to send a first challenge signal to the body controller within a second time period, and controlling the engine controller to send a second challenge signal to the body controller within the same time period; in response to the body controller successfully receiving the first and second challenge signals, controlling the body controller to decrypt the first challenge signal to obtain a first response signal, and controlling the body controller to decrypt the second challenge signal to obtain a second response signal; controlling the body controller to send the first response signal to the drive motor controller, and controlling the body controller to send the second response signal to the engine controller; in response to the drive motor controller successfully receiving the first response signal, and the first response signal successfully matching a first target response signal stored internally by the drive motor controller, determining the second authentication result as successful; in response to the engine controller successfully receiving the second response signal, and the second response signal successfully matching a second target response signal stored internally by the engine controller, determining the second authentication result as successful.
[0066] In this embodiment, the drive motor controller can be controlled to send a first challenge signal to the body controller within a second time period, and the engine controller can be controlled to send a second challenge signal to the body controller within the same second time period. When the body controller successfully receives the first and second challenge signals, it can decrypt the first challenge signal to obtain a first response signal, and decrypt the second challenge signal to obtain a second response signal. Further, the body controller can send the first response signal to the drive motor controller and the second response signal to the engine controller. When the drive motor controller successfully receives the first response signal and it matches the first target response signal stored internally by the drive motor controller, the second authentication result can be determined as successful. When the engine controller successfully receives the second response signal and it matches the second target response signal stored internally by the engine controller, the second authentication result can be determined as successful.
[0067] The second time can be a specified time set according to actual conditions, such as 1 second. The second time can be calibrated; this is only an example and no specific limit is placed on its value. The first challenge signal can be a challenge signal sent by the MCU to the BCM, which can be called the first anti-theft challenge CAN signal and can be represented by MotToBCMImoChlg. The second challenge signal can be a challenge signal sent by the EMS to the BCM, which can be called the second anti-theft challenge CAN signal and can be represented by EngToBCMImoChlg. The first response signal can be a response signal sent by the BCM to the MCU and can be represented by MotToBCMImoResp. The second response signal can be a response signal sent by the BCM to the EMS and can be represented by EngToBCMImoChlgResp.
[0068] Optionally, when the vehicle key changes from Key-Off to Key-On, the MCU and EMS can be controlled to send anti-theft challenge CAN signals to the BCM via the CAN bus within a specified time, such as 1 second. Specifically, the MCU sends `MotToBCMImoChlg` to the BCM, and the EMS sends `EngToBCMImoChlg`. When the BCM receives the corresponding signal, it can calculate the corresponding signal value using an encryption algorithm and send this value to the MCU and EMS. It should be noted that the MCU and EMS use the same encryption algorithm as the BCM to calculate the response signal value and send it to their respective controller's anti-theft module. They then verify whether this signal value matches the signal value received from the BCM controller. Specifically, the BCM sends `MotToBCMImoResp` to the MCU and `EngToBCMImoChlgResp` to the EMS. When the verification shows consistency, the vehicle anti-theft system is deactivated, the MCU unlocks the drive motor, and the EMS unlocks the engine.
[0069] It should be noted that the BCM can only trigger the anti-theft response function, i.e., send the above response signal, when the vehicle key signal is valid, the motor and engine are not running, and the MCU and EMS are in polling state.
[0070] It should be noted that the anti-theft authentication control for the motor and engine is performed through encryption, with the MCU, EMS, and BCM employing a specified encryption algorithm. For anti-theft authentication control, the challenge and response signals are generated using encryption, consisting of a random number (multi-byte bits) and a key. When anti-theft authentication signals from both the MCU and EMS occur simultaneously, the BCM will respond to the MCU's anti-theft authentication signal first.
[0071] As an optional embodiment, the method further includes: in response to a successful second authentication result, prohibiting second-level security authentication of the drive motor controller and the body controller, and prohibiting second-level security authentication of the engine controller and the body controller within a third time period.
[0072] In this embodiment, when the second authentication result is successful, second-level security authentication for the drive motor controller and body controller, as well as for the engine controller and body controller, can be prohibited within a third time period. The third time period can be a predetermined time set according to actual conditions; for example, it can be 5 seconds. The third time period can be calibrated; this is only an example and no specific limit is placed on its value.
[0073] Optionally, once the motor and engine immobilizer authentication is successful and the vehicle key changes from Key-Start or Key-On to Key-OFF via the ignition switch, a fixed immobilizer timer (K_SftyMobiTime) can be set and gradually reduced. If the driver needs to restart the motor or engine within this time, re-authentication is not required.
[0074] It should be noted that the preconditions for triggering the anti-theft timer are that both the motor and engine are unlocked (i.e., anti-theft authentication has been passed) and the vehicle body controls are unlocked (i.e., anti-theft authentication has been passed). After the timer expires, when the key is switched from Key-OFF to Key-On, the powertrain can be controlled to enter the motor and engine anti-theft authentication control. When the powertrain is ready, the anti-theft function cannot be used to lock the motor and engine. During the anti-theft authentication control process, when the key is Key-OFF, the powertrain anti-theft system will be armed, meaning the anti-theft function is effective. When the key is switched back to Key-On at this time, the powertrain anti-theft function will resume authentication control.
[0075] As an optional embodiment, the method further includes: in response to a successful second authentication result, acquiring a powertrain status signal and a drive motor status signal; in response to a powertrain status signal being a first target value and the drive motor status signal being in speed response mode, controlling the drive motor controller to send a first challenge signal to the body controller according to a second time period, and controlling the engine controller to send a second challenge signal to the body controller according to a second time period; in response to a powertrain status signal being a second target value and the drive motor status signal being in torque response mode, prohibiting the drive motor controller from sending the first challenge signal to the body controller, and prohibiting the engine controller from sending the second challenge signal to the body controller.
[0076] In this embodiment, when the second authentication result is successful, the powertrain status signal and the drive motor status signal can be acquired. When the powertrain status signal is the first target value and the drive motor status signal is in speed response mode, the drive motor controller can be controlled to send a first challenge signal to the body controller according to a second time period, and the engine controller can be controlled to send a second challenge signal to the body controller according to a second time period. When the powertrain status signal is the second target value and the drive motor status signal is in torque response mode, the drive motor controller can be prevented from sending the first challenge signal to the body controller, and the engine controller can be prevented from sending the second challenge signal to the body controller.
[0077] The power system status signal can be a power system readiness signal sent by the HCU, represented by EPTRdy. The drive motor status signal can be represented by TMSta, the torque response mode by TrqCtlMd, and the speed response mode by SpdMd. When the drive motor starts, its state is in torque response mode, sent by the HCU. The first target value can be 0, indicating not ready. The second target value can be 1, indicating ready. The second time period can be the polling period, represented by K_ImmPollingPrd. The second time period can be calibrated; the default is 3 seconds. This is only an example and no specific limit is placed on the value of the second time period.
[0078] It should be noted that polling mode refers to the controller periodically sending challenge signals to interact with other controllers, such as inquiring about services or responses. This is a continuous signal sending and querying action by the controller.
[0079] Optionally, after the motor and engine anti-theft authentication is successful and after Key-Start, if EPTRdy = 0 and TMSta is not equal to TrqCtlMd, meaning the vehicle did not attempt to start the motor and engine, the vehicle anti-theft system will enter the anti-theft polling management state. During the anti-theft polling management process, the MCU and EMS can be controlled to periodically send challenge signals to the BCM; the period is the polling cycle. When EPTRdy = 1 or TMSta = TrqCtlMd, the MCU and EMS can be controlled to stop sending challenge signals and exit the anti-theft polling management state.
[0080] It should be noted that during the polling period of the anti-theft system controller, the powertrain's anti-theft function will remain unlocked. If the anti-theft authentication remains normal during the polling period, the drive motor and engine will remain unlocked until the next authentication period. If an anti-theft authentication anomaly occurs during the polling period, the drive motor and engine will remain armed until the next authentication period. During the polling period, when the HCU sends the signal TMSta = TrqCtlMd, it indicates the drive motor is in torque mode, and the MCU stops polling. During the polling period, when the HCU sends the signal EPTRdy = 1, it indicates the engine is in a starting state. When the EMS receives EPTRdy = 1, it can control the EMS to stop polling.
[0081] As an optional embodiment, the method further includes: in response to the first challenge signal being an invalid challenge signal, the second challenge signal being an invalid challenge signal, and the number of times the invalid challenge signal is received reaching a first threshold, prohibiting the body controller from sending a first response signal to the drive motor controller, and prohibiting the body controller from sending a second response signal to the engine controller; in response to the first response signal being an invalid response signal, the second response signal being an invalid response signal, and the number of times the invalid response signal is received reaching a second threshold, prohibiting the drive motor controller from sending a first challenge signal to the body controller, and prohibiting the engine controller from sending a second challenge signal to the body controller.
[0082] In this embodiment, when both the first and second challenge signals are invalid, and the number of times the invalid challenge signals are received reaches the first threshold, the body controller can be prohibited from sending the first response signal to the drive motor controller, and the body controller can be prohibited from sending the second response signal to the engine controller. When both the first and second response signals are invalid, and the number of times the invalid response signals are received reaches the second threshold, the drive motor controller can be prohibited from sending the first challenge signal to the body controller, and the engine controller can be prohibited from sending the second challenge signal to the body controller. The first threshold can be a threshold set according to actual conditions. The first threshold can be calibrated and can be represented by K_InvdChalNum. For example, the first threshold can be three times; this is only an example, and no specific limit is placed on the value of the first threshold. The second threshold can also be a threshold set according to actual conditions. The second threshold can be calibrated and can be represented by K_InvdRespNum. For example, the second threshold can be three times; this is only an example, and no specific limit is placed on the value of the second threshold.
[0083] Optionally, when the BCM receives invalid challenge signals (i.e., abnormal data format) from the MCU and EMS, it can be controlled to exit invalid response mode. This embodiment has a certain requirement regarding the number of invalid challenges, setting a calibrated value K_InvdChalNum. When the BCM detects receiving three abnormal challenges, it can be controlled to stop sending responses to the MCU and EMS, i.e., the BCM is locked until the delay time expires. When a Key-On event occurs again, the BCM will receive challenge signals from the MCU and EMS again as normal anti-theft authentication. The delay time can be represented by K_AttDelayTime, which can be calibrated, with a default value of 10 seconds.
[0084] Optionally, when the MCU and EMS receive an invalid response signal (i.e., abnormal data format) from the BCM, they can be controlled to exit invalid challenge. This embodiment has a certain requirement for the number of invalid responses, setting a calibrated value K_InvdRespNum. When the MCU and EMS detect receiving three abnormal responses, they can be controlled to stop sending challenges to the BCM, i.e., the MCU and EMS are locked until the delay time expires. When a key-on occurs again, the MCU and EMS will start sending challenges again as normal anti-theft authentication.
[0085] It should be noted that if the BCM does not receive a challenge from the MCU within the first timeout period, it can be controlled to record a first fault code, which can be represented by DTC1. The first timeout period can be represented by K_NoChalTime, which can be calibrated and defaults to 2 seconds. If the BCM does not receive a challenge from the EMS within the first timeout period, it can be controlled to record a second fault code, which can be represented by DTC2. If the MCU does not receive a response from the BCM within the second timeout period, it can be controlled to record a third fault code, which can be represented by DTC3. The second timeout period can be represented by K_NoRespTime, which can be calibrated and defaults to 2 seconds. If the EMS does not receive a response from the BCM within the second timeout period, it can be controlled to record a fourth fault code, which can be represented by DTC4.
[0086] In this embodiment, in response to the vehicle controller being in an initialization state, a first-level security authentication is performed on the vehicle, resulting in a first authentication result. This first-level security authentication represents the security authentication between the keyless entry and start device and the vehicle controller. In response to a successful first authentication result, a second-level security authentication is performed on the vehicle, resulting in a second authentication result. This second-level security authentication represents the security authentication between the drive motor controller and the vehicle body controller, and between the engine controller and the body controller. In response to a successful second authentication result, the vehicle is controlled to start under normal conditions. In other words, this embodiment performs a first-level security authentication between the keyless entry and start device and the vehicle controller. After successful first-level security authentication, a second-level security authentication is performed between the drive motor controller and the engine controller and the body controller, respectively. Only after successful second-level security authentication is the vehicle controlled to start under normal conditions. This achieves the technical effect of improving the security of vehicle security authentication and solves the technical problem of low security in vehicle security authentication.
[0087] The technical solutions of the embodiments of the present invention will be illustrated below with reference to preferred embodiments.
[0088] Currently, hybrid vehicles have gained widespread adoption and acceptance. Unlike traditional vehicles, new energy hybrid vehicles can obtain power from at least two sources: an engine and an electric motor. The engine consumes fuel, while the motor consumes electricity. Traditional vehicles, with only one power source—the engine—primarily rely on authentication between the key and the engine control system (EMS). Hybrid vehicles, however, with the added power of a drive motor, allow users to start the vehicle even when the engine is not running. This makes traditional anti-theft methods less secure, resulting in lower security for vehicle authentication.
[0089] As an alternative example, a vehicle anti-theft method is proposed. This method determines if there are any abnormalities around the vehicle. If an abnormality is found, the vehicle enters a warning mode, activating the vehicle's network and starting the in-vehicle infotainment system. Further, it determines if there are any abnormal door openings. If so, the vehicle enters an alarm mode, powering on the entire vehicle, maintaining the electronic steering lock in a locked state, displaying information on the in-vehicle screen, and sending a reminder message to the owner. However, because this method does not involve anti-theft control of the hybrid vehicle's powertrain system, it suffers from low security in terms of vehicle security authentication.
[0090] As another alternative example, a vehicle anti-theft system and method are also proposed. The system includes: a transmission control module for transmitting a low-frequency signal with a preset signal strength; a feedback module for analyzing the signal strength of the low-frequency signal and transmitting a high-frequency signal containing that signal strength; a time recording module for controlling a clock unit to record the time difference between transmitting the low-frequency signal and receiving the high-frequency signal; a distance calculation module for calculating the propagation distance of the low-frequency signal based on the time difference; and a signal strength judgment module for reading a preset signal strength range corresponding to the propagation distance from a first storage unit and determining whether the signal strength falls within the preset signal strength range. That is, this anti-theft control method is implemented through the above multiple modules; however, this method does not involve anti-theft control of the hybrid vehicle powertrain system, thus resulting in low security for vehicle security authentication.
[0091] As another alternative example, a system and method for vehicle anti-theft control are also proposed. The system includes an anti-theft controller, a communication system, an anti-theft monitoring system, and an alarm. The anti-theft controller communicates with both the anti-theft monitoring system and the alarm via the communication system. When the monitoring information sent by the anti-theft monitoring system meets the warning conditions, it sends an anti-theft alarm command to the alarm. Furthermore, when the anti-theft monitoring system receives an auxiliary anti-theft shutdown signal before entering the armed state, it prevents the sending of anti-theft alarm commands from the corresponding auxiliary anti-theft monitoring subsystem, thus meeting users' personalized needs for anti-theft alarm functions in different scenarios. However, since this method does not involve anti-theft control of the hybrid vehicle powertrain system, it suffers from low security in vehicle security authentication.
[0092] In summary, traditional vehicle powertrain anti-theft control methods primarily focus on the anti-theft authentication between the key and the engine control system (EMS). However, hybrid vehicles require not only anti-theft authentication between the key and EMS, but also between the key and the vehicle control unit (HCU) due to the presence of the HCU, and further anti-theft authentication of the drive motor. Therefore, a more secure powertrain anti-theft control scheme and method need to be redesigned; specifically, a new anti-theft authentication system between the key and the motor is required for hybrid vehicles.
[0093] To address the aforementioned issues, this embodiment proposes an anti-theft control method for hybrid vehicles. This method, specifically for hybrid vehicles, ensures vehicle safety by designing a multi-level powertrain anti-theft control system. The method includes two levels of security and anti-theft control: an anti-theft authentication control method between the HCU and PEPS (first-level anti-theft), and an anti-theft authentication control method between the MCU, EMS, and BCM (second-level anti-theft). Only after passing these two levels of anti-theft authentication control is the high-voltage electric starter motor and engine allowed to be connected to the vehicle.
[0094] In the development of the anti-theft control method, this embodiment also proposes an anti-theft system control and fixed-time management method, an anti-theft system polling and challenge management method, and an anti-theft system anomaly handling method. Compared with the traditional single-level anti-theft system, the vehicle powertrain anti-theft control method of this embodiment increases vehicle security, ensuring safe and risk-free vehicle use for users. Through a two-level security anti-theft design, the safety and risk-free operation of the hybrid vehicle powertrain system are ensured, meeting users' vehicle security and driving needs.
[0095] Figure 2 This is a schematic diagram of a hybrid vehicle powertrain configuration according to an embodiment of the present invention, as shown below. Figure 2 As shown in the schematic diagram, the hybrid vehicle powertrain configuration may include at least the following components: engine 201, starter 202, drive motor 203, power battery 204, transmission 205, clutch 206, battery 207, wheels 208, and transmission mechanism, as well as controllers corresponding to each powertrain component. Each controller may include at least the following: engine controller 209, vehicle controller 210, drive motor controller 211, battery management system (BMS) 212, transmission control unit (TCU) 213, direct current converter (DCDC) 214, instrument cluster (IC) 215, body controller 216, and keyless entry and start 217. The controllers communicate with each other via a CAN network.
[0096] The battery can be 12 volts (V). The HCU, as the core controller of the vehicle, can coordinate and control other subsystems, enabling power-on / off control of the power system and driving control. The EMS can control the engine, the MCU can control the drive motor, the BMS can control the power battery, the TCU can control the transmission, and the IC can display various system information. PEPS can control keyless entry and engine start; as a keyless entry and start device, PEPS can be composed of a controller, a receiver at the vehicle end, and a radio frequency transmitter in the vehicle key.
[0097] As a key function in vehicle control, the anti-theft feature of hybrid vehicles plays a crucial role in preventing theft and ensuring vehicle security through key encryption and adaptation. Traditional vehicles primarily rely on security authentication between the key and the EMS (Electronic Management System). For hybrid vehicles, to make the anti-theft system more effective and secure, a multi-layered security anti-theft system is designed, including anti-theft control between the HCU and PEPS (Power Control System and Power Savings Panel), between the EMS and BCM (Building Management System), and between the MCU and BCM. This significantly enhances the vehicle's security and anti-theft capabilities. When the vehicle's anti-theft system is engaged, i.e., the vehicle is in anti-theft mode, the engine cannot be started using high-voltage electricity. In this state, the power source cannot output torque to drive the vehicle, thus achieving the desired anti-theft effect.
[0098] Figure 3 This is a flowchart of a vehicle anti-theft authentication method according to an embodiment of the present invention, such as... Figure 3 As shown, PEPS and HCU communicate via two-way authentication, which constitutes the first level of vehicle security and anti-theft control. The vehicle anti-theft authentication process can include at least the following steps:
[0099] Step S301, HCU initialization.
[0100] In the above steps, the driver operates the Key-On key, and the HCU is initialized.
[0101] In step S302, the HCU sends the challenge code signal to PEPS.
[0102] In the above steps, after HCU initialization, HCU sends an encrypted Challenge Code signal to PEPS.
[0103] In step S303, PEPS uses its internal algorithm to decrypt the anti-theft identification code signal.
[0104] In the above steps, PEPS uses its internal algorithm to identify the encrypted data in the challenge code signal and decrypt the anti-theft identification code signal.
[0105] In step S304, PEPS verifies the identification code signal against the internally stored identification code signal.
[0106] In the above steps, PEPS verifies the decrypted identification code signal against the identification code signal stored in the internal module. If the encrypted data is correct, the verification passes; if the encrypted data is incorrect, the verification fails.
[0107] In step S305, PEPS sends the response code signal obtained after verification to HCU.
[0108] In the above steps, if the encrypted data is correct, PEPS sends a valid encryption response code signal to HCU before allowing other operations, such as entering the second level of security and anti-theft control. If the encrypted data is incorrect, PEPS sends an invalid encryption response code signal to HCU and issues a warning on the instrument panel. At the same time, BCM can control the vehicle to activate the hazard lights and sound the horn.
[0109] In step S306, the HCU performs judgment and authentication based on the response code signal.
[0110] In an anti-theft control system, the HCU and PEPS have two states: armed and disabled. When the PEPS is armed, it does not receive information from the HCU; it only disarms when the vehicle key is inside the vehicle. When the HCU powers on and initializes, it is in armed mode. If anti-theft authentication between the HCU and PEPS fails, the HCU is also in armed mode. When anti-theft authentication between the HCU and PEPS is successful, the HCU is in disabled mode.
[0111] Figure 4 This is a flowchart of a two-way anti-theft authentication method for vehicles according to an embodiment of the present invention, such as... Figure 4 As shown, the process of two-way anti-theft authentication for this vehicle can include at least the following steps:
[0112] Step S401: Is the vehicle key inside the vehicle?
[0113] In the above steps, when the vehicle key is in the Key-On state and the key is inside the vehicle, you can proceed to steps S402 and S411; otherwise, proceed to step S403.
[0114] Step S402: Power on the power system.
[0115] In the above steps, when the vehicle key is in the Key-On state and the key is inside the vehicle, the power system triggers low-voltage power-on (Ignition On).
[0116] Step S403: Authentication fails and the instrument displays a warning message.
[0117] In the above steps, if the vehicle key is not in the Key-On state and the key is not inside the vehicle, the authentication will fail and the instrument panel will display relevant information.
[0118] Step S404: Has HCU initialization been completed?
[0119] In the above steps, after the power system is powered on, it is determined whether the HCU initialization is complete. If the HCU initialization is complete, proceed to steps S405 and S406; otherwise, proceed to step S407.
[0120] In step S405, the HCU sends a challenge code signal to PEPS.
[0121] In the above steps, after the HCU controller has completed its internal initialization, the HCU sends a challenge code signal to PEPS.
[0122] Step S406: The HCU internally calculates the identification code signal.
[0123] In the above steps, while the HCU sends the challenge code signal to PEPS, the HCU internally calculates the anti-theft identification code, which is used for verification when it receives the response code signal returned by PEPS.
[0124] Step S407: Continue initialization. If initialization is not completed within the specified time, exit.
[0125] In the above steps, if HCU initialization is not completed, the HCU initialization will continue. If HCU initialization is not completed within the specified time, the process will exit.
[0126] In step S408, PEPS calculates the identification code signal, matches it with the internally stored data code, and sends the signal to HCU.
[0127] In the above steps, after the HCU sends a challenge code signal to PEPS and PEPS receives the challenge code signal from the HCU, PEPS decrypts the challenge code signal using a decryption algorithm and compares the decrypted data with the identification code data stored in the internal module. If the match is successful, PEPS will send a response code signal indicating that the anti-theft authentication has passed to the HCU. At this time, the response code is a normal eight-byte data.
[0128] Optionally, when PEPS matches the decrypted data with the identification code data stored in the internal module, if the match fails, PEPS will send a response code signal indicating that the anti-theft authentication has failed to pass to the HCU. At this time, the response code is an abnormal eight-byte data.
[0129] In step S409, the HCU decodes the received PEPS signal and matches it with the internal identification code signal.
[0130] In the above steps, after PEPS sends a signal to HCU, HCU determines whether the received response code signal sent by PEPS is a normal signal. If it is normal byte data, HCU uses an encryption algorithm to decode the message and matches the decrypted data with the identification code data stored in the internal module.
[0131] Optionally, if the HCU does not receive the response code signal from PEPS, the HCU should continuously send a challenge code signal at regular intervals, such as 200ms, within a specified time, such as 2 seconds. If it still does not receive the response code signal from PEPS, the anti-theft authentication fails. The challenge code signal is a string of encrypted data using a special encryption algorithm; the challenge code is eight bytes of data.
[0132] Step S410: Check if the signal matches the identification code signal.
[0133] In the above steps, after the HCU matches the received signal with the internal identification code signal, if the match is successful, the two-way authentication is successful; otherwise, the two-way authentication fails. If the data is abnormal byte data, the two-way authentication also fails.
[0134] Step S411: Unlock the electronic steering column.
[0135] In the above steps, when the vehicle key is in the Key-On state and the key is inside the vehicle, the electronic steering column is triggered to unlock.
[0136] Step S412: Is the electronic steering column unlocking successful?
[0137] In the above steps, it is determined whether the electronic steering column is successfully unlocked. If the electronic steering column is successfully unlocked, proceed to step S413; otherwise, proceed to step S414.
[0138] Step S413: Is the gear in P or N?
[0139] In the above steps, when the electronic steering column is successfully unlocked and the driver presses the brake pedal, it is further determined whether the gear is in P or N. If the gear is in P or N, proceed to step S415; otherwise, proceed to step S417.
[0140] Step S414: Authentication fails and the instrument displays a warning message.
[0141] In the above steps, if the electronic steering column is not unlocked, authentication fails and the instrument panel displays a warning message.
[0142] Step S415: Are all the above conditions satisfied?
[0143] In the above steps, when the gear is in P or N gear, and the HCU determines that the signal sent by the received PEPS is consistent with the internal identification code signal, then proceed to step S417.
[0144] Step S416: Retain the low voltage of the traction gear.
[0145] In the above steps, when the gear is not in P or N, the traction (CN) gear low voltage is retained.
[0146] Step S417: The power system enters the second level of anti-theft authentication.
[0147] In the above steps, when the gear is in P or N gear and the HCU determines that the signal sent by PEPS is consistent with the internal identification code signal, the power system enters the second level of anti-theft authentication.
[0148] In step S418, the HCU decodes the received PEPS signal and matches it with the internal identification code signal.
[0149] In the above steps, if the gear is not in P or N, or if the HCU determines that the received PEPS signal is inconsistent with the internal identification code signal, the HCU decodes the received PEPS signal and matches it with the internal identification code signal.
[0150] In this embodiment, the second-level anti-theft control of the vehicle powertrain system can determine whether the high-voltage starter motor and engine can be started through anti-theft authentication between the MCU, EMS, and BCM. The second-level anti-theft control includes motor authentication between the MCU and BCM, and engine authentication between the EMS and BCM, with each controller transmitting information to each other via a CAN bus.
[0151] During the vehicle powertrain anti-theft control process, the anti-theft control algorithm is integrated into the internal memory of the MCU and EMS. When the motor and engine anti-theft authentication is successful, the vehicle anti-theft system is deactivated, and the vehicle can then use the high-voltage electric starter motor and engine. Otherwise, the vehicle anti-theft system remains armed, and the vehicle cannot use the high-voltage electric starter motor and engine.
[0152] When the vehicle key changes from Key-Off to Key-On, the MCU and EMS should send anti-theft challenge CAN signals to the BCM via the CAN bus within a specified time, such as 1 second. Specifically, the MCU sends MotToBCMImoChlg to the BCM, and the EMS sends EngToBCMImoChlg to the BCM. The BCM will then calculate the corresponding signal value using an encryption algorithm and send the signal value to the MCU and EMS.
[0153] The MCU and EMS use the same encryption algorithm as the BCM to calculate a response signal value and send it to the anti-theft module of their respective controllers. They then verify that this signal value matches the signal value received from the BCM controller. Specifically, the BCM sends MotToBCMImoResp to the MCU and EngToBCMImoChlgResp to the EMS. If the signals match, the vehicle anti-theft system is deactivated, the MCU unlocks the drive motor, and the EMS unlocks the engine.
[0154] The BCM can only trigger the anti-theft response function, i.e., send the aforementioned response signal, when the vehicle key signal is valid, the motor and engine are not running, and the MCU and EMS are in polling mode. The anti-theft authentication control of the motor and engine is encrypted; the MCU, EMS, and BCM use a specified encryption algorithm. For anti-theft authentication control, both the challenge and response signals are generated using encryption, consisting of a random number (multi-byte bits) and a key. If anti-theft authentication signals from both the MCU and EMS occur simultaneously, the BCM will respond to the MCU's anti-theft authentication signal first.
[0155] If the motor and engine immobilizer authentication has been successful, and the vehicle key changes from Key-Start or Key-On to Key-OFF, a fixed security immobilizer timer (K_SftyMobiTime, calibrable, default 5s) should be set and gradually decremented. If the driver needs to restart the motor or engine within this time, re-authentication is not required. The fixed security immobilizer timer triggers only if both the motor and engine are unlocked (i.e., immobilizer authentication has been successful) and the vehicle body controls are unlocked (i.e., immobilizer authentication has been successful).
[0156] If the key is switched from Key-OFF to Key-On after the expiration time, the powertrain will enter the motor and engine immobilizer authentication control. When the powertrain is Ready, the immobilizer function is not allowed to lock the motor and engine. During the security immobilizer authentication control process, if the key is switched to Key-OFF, the powertrain immobilizer will be armed, meaning the immobilizer function is triggered and effective. If the key is switched back to Key-On at this time, the powertrain immobilizer function will resume authentication control.
[0157] Polling mode refers to the controller periodically sending challenge signals to interact with other controllers, such as inquiring about services or responses. It is a continuous signal sending and querying action by the controller.
[0158] If the motor and engine anti-theft authentication has passed, and after Key-Start, EPTRdy = 0 and TMSta is not equal to TrqCtlMd (meaning the vehicle did not attempt to start the motor and engine), the vehicle anti-theft system will enter anti-theft polling management mode. Here, EPTRdy is the powertrain readiness signal, where 0 indicates Not Ready and 1 indicates Ready, sent by the HCU. TMSta is the drive motor status signal, where TrqCtlMd indicates torque response mode and SpdMd indicates speed response mode. At startup, the drive motor must be in torque response mode, and this signal is sent by the HCU.
[0159] During the anti-theft polling management process, the MCU and EMS periodically send challenge signals to the BCM. The period can be understood as the polling cycle (K_ImmPollingPrd, which can be calibrated, default 3s). When EPTRdy=1 or TMSta=TrqCtlMd, the MCU and EMS will stop sending challenge signals and exit the anti-theft polling management state.
[0160] During the polling period of the anti-theft system controller, the power system's anti-theft function will remain in an unarmed (disarmed) state. If the anti-theft authentication remains normal during the polling period, the motor and engine will remain disarmed until the next anti-theft authentication period. If an anomaly occurs during the polling period, the drive motor and engine will remain armed until the next anti-theft authentication period.
[0161] During the anti-theft system controller polling period, if the HCU sends the signal TMSta = TrqCtlMd, the MCU determines that the drive motor is in torque mode, and the MCU should stop polling at this time. During the anti-theft system polling period, if the HCU sends the signal EPTRdy = 1, the EMS determines that the engine will be in a starting state. When the EMS receives the EPTRdy = 1 signal (1 indicates Ready, 0 indicates NotReady), the EMS should stop polling.
[0162] When the BCM receives invalid challenge signals from the MCU and EMS, such as when the data format is abnormal, the BCM will exit the invalid response phase. There is a limit to the number of invalid challenges; a calibrated value K_InvdChalNum (can be calibrated, default is 3) can be set. When the BCM detects three invalid challenges, it will stop sending responses to the MCU and EMS. The BCM will then be locked until a delay time expires (K_AttDelayTime, calibrated, default is 10 seconds). Upon a renewed Key-On event, the BCM will again receive challenge signals from the MCU and EMS as normal anti-theft authentication.
[0163] When the MCU and EMS receive an invalid response signal from the BCM, such as an abnormal data format, they will exit the invalid challenge. There is a requirement for the number of invalid responses; a calibrated value K_InvdRespNum (can be calibrated, default is 3) is set. When the MCU and EMS detect three abnormal responses, they will stop sending challenges to the BCM. Afterwards, the MCU and EMS will be locked until the delay time expires (K_AttDelayTime, calibrated, default is 10s). When a key-on occurs again, the MCU and EMS will start sending challenges again as normal anti-theft authentication.
[0164] If the BCM does not receive a challenge from the MCU within the timeout period (K_NoChalTime, configurable, default 2s), the BCM will log fault code DTC1. If the BCM does not receive a challenge from the EMS within the timeout period (K_NoChalTime, configurable, default 2s), the BCM will log fault code DTC2. If the MCU does not receive a response from the BCM within the timeout period (K_NoRespTime, configurable, default 2s), the MCU will log fault code DTC3. If the EMS does not receive a response from the BCM within the timeout period (K_NoRespTime, configurable, default 2s), the EMS will log fault code DTC4.
[0165] In this embodiment, the anti-theft system module configuration mainly includes controllers such as HCU and PEPS, MCU, EMS, and BCM. Relevant anti-theft information is written using external diagnostic tools, and the configuration includes learning keys for HCU and PEPS, as well as learning keys for MCU, EMS, and BCM. When HCU, MCU, EMS, and BCM are in an unconfigured state, the anti-theft system function can use external diagnostic tools to write the HCU_configuration, MCU_configuration, EMS_configuration, and BCM_configuration into the corresponding controller memory.
[0166] If the MCU or EMS is replaced during after-sales service, the MCU or EMS can use a program launched by a diagnostic tool to learn the key from the BCM. After learning the key, the MCU or EMS can store the data in the controller memory. If the BCM is replaced during after-sales service, the BCM can use a program launched by a diagnostic tool to learn the key from the MCU or EMS. After learning the key, the BCM should store the data in the controller memory.
[0167] In this embodiment, the high-voltage starter motor and engine can only be activated after the hybrid vehicle has completed the first and second levels of anti-theft authentication control. Since hybrid vehicles have multiple power sources, designing multi-level anti-theft authentication makes anti-theft measures for hybrid vehicles safer and more effective, reducing driver anxiety and improving vehicle security.
[0168] Figure 5 This is a flowchart of a motor or engine starting process according to an embodiment of the present invention, such as... Figure 5 As shown, the process of starting the motor or engine may include at least the following steps:
[0169] Step S501: Operate the vehicle key Key-Start.
[0170] In the above steps, after vehicle anti-theft authentication, the high-voltage starter motor or engine of the vehicle's power system can be triggered. That is, after the vehicle's power system passes the second level of anti-theft authentication control, the driver operates the vehicle key from Key-on to Key-Start.
[0171] Step S502: Is the high-voltage power supply to the power system successful?
[0172] In the above steps, it is determined whether the high voltage power-on of the power system is successful. If it is unsuccessful, the fault handling is initiated. If it is successful, the process proceeds to step S503; otherwise, the process proceeds to step S504.
[0173] Step S503: The vehicle enters the powertrain ready state.
[0174] In the above steps, when the high voltage of the power system is successfully energized, the vehicle enters the power system ready state. Once the vehicle is in the power system ready state, if the driver shifts to drive (D) or reverse (R) and releases the brake pedal, the vehicle can move.
[0175] Step S504: Handle the fault.
[0176] In the above steps, if the high voltage of the power system fails to be energized, the fault handling process will begin.
[0177] Step S505: Has the vehicle started its engine?
[0178] In the above steps, it is determined whether the vehicle needs to start the engine. If there is no need to start the engine, proceed to step S506; otherwise, proceed to step S507.
[0179] Step S506: The vehicle enters pure electric mode.
[0180] In the above steps, if there is no need to start the engine, the engine will not be started, and the vehicle will be driven by the electric motor to enter pure electric mode.
[0181] Step S507: Does the starter motor start the engine?
[0182] In the above steps, if the vehicle needs to start the engine, the engine can be started using a starter motor or a drive motor. Further, it needs to be determined whether the starter motor can start the engine. If the starter motor starts the engine, proceed to step S508; otherwise, proceed to step S509.
[0183] Step S508: Start the engine using the starter motor.
[0184] In the above steps, if the vehicle starts the engine for the first time in a driving cycle, the starter motor is used first to start the engine, and the control program for starting the engine using the starter motor is entered.
[0185] Step S509: Start the engine using the drive motor.
[0186] In the above steps, if the vehicle is not starting the engine for the first time in a driving cycle, the drive motor can be used to start the engine, and the control program for starting the engine using the drive motor can be entered.
[0187] Figure 6 This is a schematic diagram of an anti-theft authentication sequence according to an embodiment of the present invention, such as... Figure 6 As shown, the anti-theft authentication pass and powertrain readiness sequence diagram can include anti-theft authentication status, vehicle key status, brake pedal status, and powertrain status. Anti-theft authentication status includes pass and fail. Vehicle key status includes Key-On and Key-Start. Brake pedal status includes depressed and released. Powertrain status includes Not Ready, Ready, and Drive.
[0188] In this embodiment, in response to the vehicle controller being in an initialization state, a first-level security authentication is performed on the vehicle, resulting in a first authentication result. This first-level security authentication represents the security authentication between the keyless entry and start device and the vehicle controller. In response to a successful first authentication result, a second-level security authentication is performed on the vehicle, resulting in a second authentication result. This second-level security authentication represents the security authentication between the drive motor controller and the vehicle body controller, and between the engine controller and the body controller. In response to a successful second authentication result, the vehicle is controlled to start under normal conditions. In other words, this embodiment performs a first-level security authentication between the keyless entry and start device and the vehicle controller. After successful first-level security authentication, a second-level security authentication is performed between the drive motor controller and the engine controller and the body controller, respectively. Only after successful second-level security authentication is the vehicle controlled to start under normal conditions. This achieves the technical effect of improving the security of vehicle security authentication and solves the technical problem of low security in vehicle security authentication.
[0189] According to an embodiment of the present invention, a vehicle control device is also provided. It should be noted that this vehicle control device can be used to execute the vehicle control method of Embodiment 1.
[0190] Figure 7 This is a schematic diagram of a vehicle control device according to an embodiment of the present invention, such as... Figure 7 As shown, the vehicle control device 700 may include: a first authentication unit 702, a second authentication unit 704, and a control unit 706.
[0191] The first authentication unit 702 is used to perform first-level security authentication on the vehicle in response to the vehicle controller being in the initialization state, and obtain a first authentication result. The first-level security authentication is used to represent the security authentication between the keyless entry and start device and the vehicle controller.
[0192] The second authentication unit 704 is used to perform a second-level safety authentication on the vehicle in response to the first authentication result being successful, and to obtain a second authentication result. The second-level safety authentication is used to represent the safety authentication between the drive motor controller and the body controller in the vehicle, and the safety authentication between the engine controller and the body controller in the vehicle.
[0193] Control unit 706 is used to control the vehicle to start under normal conditions in response to a successful second authentication result.
[0194] Optionally, the first authentication unit 702 includes: an acquisition module for acquiring vehicle key information; in response to the key information indicating that the vehicle key is in the ignition state and the key is located inside the vehicle, controlling the low-voltage power supply of the vehicle's power system and the unlocking of the electronic steering column; a control module for controlling the vehicle to output warning information in response to the failure of the low-voltage power supply of the power system or the failure of the electronic steering column to unlock; and a first authentication module for performing first-level security authentication on the keyless entry and start device and the vehicle controller in response to the successful low-voltage power supply of the power system, the successful unlocking of the electronic steering column, and the vehicle controller being in the initialization state, to obtain a first authentication result.
[0195] Optionally, the first authentication module includes: a first sending submodule, used to control the vehicle controller to send a challenge code signal to the keyless entry and start device; a first decryption submodule, used to control the keyless entry and start device to decrypt the challenge code signal to obtain an identification code signal in response to the keyless entry and start device successfully receiving the challenge code signal; a second sending submodule, used to control the keyless entry and start device to send the identification code signal to the vehicle controller in response to the identification code signal successfully matching with a first target identification code signal stored internally in the keyless entry and start device; a second decryption submodule, used to control the vehicle controller to decrypt the identification code signal to obtain a decrypted identification code signal in response to the vehicle controller successfully receiving the identification code signal and the identification code signal being a normal signal; and a first determining submodule, used to determine the first authentication result as successful in response to the decrypted identification code signal successfully matching with a second target identification code signal stored internally in the vehicle controller.
[0196] Optionally, the device further includes: a first determining unit, configured to, in response to the vehicle controller not receiving the identification code signal, control the vehicle controller to send a challenge code signal to the keyless entry and start device within a first time period according to a first time cycle, until the vehicle controller successfully receives the identification code signal, or the vehicle controller still does not receive the identification code signal, and determine the first authentication result as authentication failure.
[0197] Optionally, the device further includes: a first sending unit, configured to control the keyless entry and start device to send the identification code signal to the vehicle controller in response to the failure of the identification code signal to match the first target identification code signal; and a second determining unit, configured to determine the first authentication result as authentication failure in response to the vehicle controller successfully receiving the identification code signal and the identification code signal being an abnormal signal.
[0198] Optionally, the device further includes a third determining unit, configured to determine the first authentication result as authentication failure in response to the failure to match the decrypted identification code signal with the second target identification code signal.
[0199] Optionally, the second authentication unit 704 includes: a second authentication module, configured to perform second-level safety authentication on the drive motor controller and the body controller, and perform second-level safety authentication on the engine controller and the body controller, in response to the first authentication result being successful and the vehicle being in the target gear, to obtain a second authentication result.
[0200] Optionally, the second authentication module includes: a third sending submodule, configured to control the drive motor controller to send a first challenge signal to the body controller within a second time period, and to control the engine controller to send a second challenge signal to the body controller within a second time period; a third decryption submodule, configured to, in response to the body controller successfully receiving the first challenge signal and the second challenge signal, control the body controller to decrypt the first challenge signal to obtain a first response signal, and control the body controller to decrypt the second challenge signal to obtain a second response signal; a fourth sending submodule, configured to control the body controller to send the first response signal to the drive motor controller, and control the body controller to send the second response signal to the engine controller; a second determining submodule, configured to, in response to the drive motor controller successfully receiving the first response signal and the first response signal successfully matching the first target response signal stored internally by the drive motor controller, determine the second authentication result as successful authentication; and a third determining submodule, configured to, in response to the engine controller successfully receiving the second response signal and the second response signal successfully matching the second target response signal stored internally by the engine controller, determine the second authentication result as successful authentication.
[0201] Optionally, the device further includes: a first prohibition unit, configured to prohibit second-level safety authentication of the drive motor controller and the body controller, and prohibit second-level safety authentication of the engine controller and the body controller, within a third time period, in response to a successful second authentication result.
[0202] Optionally, the device further includes: an acquisition unit, configured to acquire a powertrain status signal and a drive motor status signal in response to a successful second authentication result; a second transmission unit, configured to control the drive motor controller to send a first interrogation signal to the body controller according to a second time period and control the engine controller to send a second interrogation signal to the body controller according to a second time period in response to a powertrain status signal being a first target value and the drive motor status signal being in a speed response mode; and a third prohibition unit, configured to prohibit the drive motor controller from sending the first interrogation signal to the body controller and prohibit the engine controller from sending the second interrogation signal to the body controller in response to a powertrain status signal being a second target value and the drive motor status signal being in a torque response mode.
[0203] Optionally, the device further includes: a fourth prohibition unit, configured to prohibit the body controller from sending a first response signal to the drive motor controller and prohibit the body controller from sending a second response signal to the engine controller in response to the first challenge signal being an invalid challenge signal, the second challenge signal being an invalid challenge signal, and the number of times the invalid challenge signal is received reaching a first threshold; and a fifth prohibition unit, configured to prohibit the drive motor controller from sending a first challenge signal to the body controller and prohibit the engine controller from sending a second challenge signal to the body controller in response to the first response signal being an invalid response signal, the second response signal being an invalid response signal, and the number of times the invalid response signal is received reaching a second threshold.
[0204] In this embodiment of the invention, the first authentication unit 702, in response to the vehicle controller being in an initialization state, performs a first-level security authentication on the vehicle, obtaining a first authentication result. This first-level security authentication represents the security authentication between the keyless entry and start device and the vehicle controller. The second authentication unit 704, in response to the successful first authentication result, performs a second-level security authentication on the vehicle, obtaining a second authentication result. This second-level security authentication represents the security authentication between the drive motor controller and the vehicle body controller, and between the engine controller and the body controller. The control unit 706, in response to the successful second authentication result, controls the vehicle to start under normal conditions. In other words, this embodiment of the invention performs a first-level security authentication between the keyless entry and start device and the vehicle controller. After successful first-level security authentication, it performs second-level security authentication between the drive motor controller and the engine controller and the body controller, respectively. Only after successful second-level security authentication is the vehicle controlled to start under normal conditions. This achieves the technical effect of improving the security of vehicle security authentication and solves the technical problem of low security in vehicle security authentication.
[0205] According to an embodiment of the present invention, a computer-readable storage medium is also provided, the storage medium including a stored program, wherein the program executes the vehicle control method of Embodiment 1.
[0206] According to an embodiment of the present invention, a vehicle is also provided for performing any of the vehicle control methods in Embodiment 1.
[0207] According to an embodiment of the present invention, a computer program product is also provided, which may include a computer program, wherein the computer program is configured to execute any of the vehicle control methods in Embodiment 1 above when running.
[0208] According to another aspect of the present invention, a computer program product is also provided. This computer program product may include a non-volatile computer-readable storage medium storing a computer program configured to execute the vehicle control method of any one of Embodiment 1 above when run.
[0209] According to another aspect of the present invention, a computer program is also provided. This computer program is configured to execute any of the vehicle control methods described in Embodiment 1 above when it is run.
[0210] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0211] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0212] In the several embodiments provided by this invention, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of the units described above can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection of units or modules, and may be electrical or other forms.
[0213] The units described above as separate components may or may not be physically separate. Similarly, the components shown as units may or may not be physical units; they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.
[0214] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0215] If the aforementioned integrated units are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0216] The above are merely preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A control method of a vehicle, characterized by, The method comprises the following steps: In response to the vehicle controller being in an initialization state, performing first-level security authentication on the vehicle to obtain a first authentication result, wherein the first-level security authentication is used to represent security authentication between a keyless entry and start device and the vehicle controller in the vehicle; In response to the first authentication result being authentication success, performing second-level security authentication on the vehicle to obtain a second authentication result, wherein the second-level security authentication is used to represent security authentication between a drive motor controller and a vehicle body controller in the vehicle, and security authentication between an engine controller and the vehicle body controller in the vehicle; In response to the second authentication result being authentication success, controlling the vehicle to start in a normal state; In response to the first authentication result being authentication success, performing second-level security authentication on the vehicle to obtain a second authentication result, comprising: in response to the first authentication result being authentication success and the gear of the vehicle being a target gear, controlling the drive motor controller to send a first challenge signal to the vehicle body controller within a second time, and controlling the engine controller to send a second challenge signal to the vehicle body controller within the second time; In response to the vehicle body controller successfully receiving the first challenge signal and the second challenge signal, controlling the vehicle body controller to decrypt the first challenge signal to obtain a first response signal, and controlling the vehicle body controller to decrypt the second challenge signal to obtain a second response signal; Controlling the vehicle body controller to send the first response signal to the drive motor controller, and controlling the vehicle body controller to send the second response signal to the engine controller; In response to the drive motor controller successfully receiving the first response signal and the first response signal matching a first target response signal stored in the drive motor controller successfully, and in response to the engine controller successfully receiving the second response signal and the second response signal matching a second target response signal stored in the engine controller successfully, determining that the second authentication result is authentication success.
2. The method of claim 1, wherein, In response to the vehicle controller being in an initialization state, performing first-level security authentication on the vehicle to obtain a first authentication result, comprising: Obtaining key information of the vehicle; In response to the key information being that the key of the vehicle is in a start state and the key is located in the vehicle, controlling power system low voltage power-on in the vehicle and electronic steering column unlocking in the vehicle; In response to the power system low voltage power-on failing or the electronic steering column unlocking failing, controlling the vehicle to output a warning information; In response to the power system low voltage power-on being successful, the electronic steering column unlocking being successful, and the vehicle controller being in the initialization state, performing first-level security authentication on the keyless entry and start device and the vehicle controller to obtain the first authentication result.
3. The method of claim 2, wherein, The first level security authentication is performed between the keyless entry and start device and the vehicle controller to obtain a first authentication result, including: controlling the vehicle controller to send a challenge code signal to the keyless entry and start device; in response to the keyless entry and start device successfully receiving the challenge code signal, controlling the keyless entry and start device to decrypt the challenge code signal to obtain an identification code signal; in response to the identification code signal matching a first target identification code signal stored in the keyless entry and start device, controlling the keyless entry and start device to send the identification code signal to the vehicle controller; in response to the vehicle controller successfully receiving the identification code signal and the identification code signal being a normal signal, controlling the vehicle controller to decrypt the identification code signal to obtain a decrypted identification code signal; in response to the decrypted identification code signal matching a second target identification code signal stored in the vehicle controller, determining that the first authentication result is authentication success.
4. The method of claim 3, wherein, The method further includes: in response to the vehicle controller not receiving the identification code signal, controlling the vehicle controller to send the challenge code signal to the keyless entry and start device within a first time until the vehicle controller successfully receives the identification code signal or the vehicle controller still does not receive the identification code signal, determining that the first authentication result is authentication failure.
5. The method of claim 3, wherein, The method further includes: in response to the identification code signal failing to match the first target identification code signal, controlling the keyless entry and start device to send the identification code signal to the vehicle controller; in response to the vehicle controller successfully receiving the identification code signal and the identification code signal being an abnormal signal, determining that the first authentication result is authentication failure.
6. The method of claim 3, wherein, The method further includes: in response to the decrypted identification code signal failing to match the second target identification code signal, determining that the first authentication result is authentication failure.
7. The method of claim 1, wherein, The method further includes: in response to the second authentication result being authentication success, within a third time, prohibiting the second level security authentication between the drive motor controller and the body controller again and prohibiting the second level security authentication between the engine controller and the body controller again.
8. The method of claim 1, wherein, The method further includes: in response to the second authentication result being authentication success, obtaining a power system state signal and a drive motor state signal; in response to the power system state signal being a first target value and the drive motor state signal being a speed response mode, controlling the drive motor controller to send the first challenge signal to the body controller according to a second time, and controlling the engine controller to send the second challenge signal to the body controller according to the second time; inhibit the drive motor controller from sending the first challenge signal to the body controller and inhibit the engine controller from sending the second challenge signal to the body controller in response to the powertrain status signal being a second target value and the drive motor status signal being in a torque response mode.
9. The method of claim 1, wherein, The method further comprises: in response to the first challenge signal being an invalid challenge signal, the second challenge signal being the invalid challenge signal, and a number of times of receiving the invalid challenge signal reaching a first number threshold, inhibiting the body controller from sending the first response signal to the drive motor controller and inhibiting the body controller from sending the second response signal to the engine controller; in response to the first response signal being an invalid response signal, the second response signal being the invalid response signal, and a number of times of receiving the invalid response signal reaching a second number threshold, inhibiting the drive motor controller from sending the first challenge signal to the body controller and inhibiting the engine controller from sending the second challenge signal to the body controller.
10. A control device of a vehicle characterized by comprising: The apparatus performs the method of any one of claims 1 to 9 when the apparatus is in operation, and the apparatus comprises: a first authentication unit, configured to perform a first level security authentication on the vehicle in response to a vehicle controller in the vehicle being in an initialization state, to obtain a first authentication result, wherein the first level security authentication is used to represent a security authentication between a keyless entry and start device and the vehicle controller in the vehicle; a second authentication unit, configured to perform a second level security authentication on the vehicle in response to the first authentication result being authentication success, to obtain a second authentication result, wherein the second level security authentication is used to represent a security authentication between a drive motor controller and a body controller in the vehicle, and a security authentication between an engine controller and the body controller in the vehicle; a control unit, configured to control the vehicle to start in a normal state in response to the second authentication result being authentication success. The second authentication unit is further configured to perform the following steps: in response to the first authentication result being authentication success and a gear position of the vehicle being a target gear position, control the drive motor controller to send a first challenge signal to the body controller within a second time, and control the engine controller to send a second challenge signal to the body controller within the second time; in response to the body controller successfully receiving the first challenge signal and the second challenge signal, control the body controller to decrypt the first challenge signal to obtain a first response signal, and control the body controller to decrypt the second challenge signal to obtain a second response signal; control the body controller to send the first response signal to the drive motor controller, and control the body controller to send the second response signal to the engine controller. In response to the drive motor controller successfully receiving the first response signal and the first response signal matching a first target response signal stored internally in the drive motor controller, and in response to the engine controller successfully receiving the second response signal and the second response signal matching a second target response signal stored internally in the engine controller, the second authentication result is determined to be an authentication success.
11. An electronic device, comprising: Comprising: a memory storing an executable program; a processor configured to execute the program, wherein the program, when executed, performs the method of any one of claims 1-9.
12. A computer-readable storage medium, characterized in that, The computer readable storage medium comprises a stored program, wherein the program, when executed by a processor, controls a device in which the storage medium is located to perform the method of any one of claims 1-9.
13. A computer program product, characterised in that, The computer program product comprises a computer program configured to be executed by a processor to perform the method of any one of claims 1-9.
14. A vehicle characterized by comprising: A computer program product configured to perform the method of any one of claims 1-9.
Citation Information
Patent Citations
Keyless entry and staring system of automobile and application method
CN102733675A
Anti-theft system for vehicles having remote-controlled engine starting function
EP1170181A2